Back to jobs
New

Manager, IT Security and Compliance

New York City

Who We Are

Authentic Brands Group (Authentic) is a global brand and entertainment platform that owns and invests in iconic intellectual property and cultural assets. It accelerates brands through a set of specialized businesses that combine powerful storytelling, premium content, unforgettable live experiences and global commerce. Through a network of more than 1,700 best-in-class licensees and strategic partners across 150 countries and expansive distribution, Authentic’s brands drive more than $36 billion in annual systemwide retail sales worldwide.
 
Authentic’s diversified portfolio spans more than 50 brands and reaches nearly one billion social media followers. Its roster includes Reebok, Champion, Shaquille O’Neal, David Beckham, Kevin Hart, Sports Illustrated, Elvis Presley, Muhammad Ali, Marilyn Monroe, GUESS, Aéropostale, Nautica, Eddie Bauer, Lucky Brand, Nine West, Brooks Brothers, Juicy Couture, Vince Camuto, Izod, Van Heusen, Dockers, Ted Baker, Hart Schaffner Marx, Vince, Barneys New York, Judith Leiber, Quiksilver, Spyder, Billabong, Volcom, Roxy, RVCA, DC Shoes, Prince, Sperry and Hunter.

For more information, visit corporate.authentic.com. Follow Authentic on LinkedIn, Instagram and WeChat.

Why Authentic

You’ll be able to access the resources and scale, while leveraging innovative technology and nimble environment. What we’re saying is, this isn’t your average day job. If you’re hungry to drive ideas into action and own your career, let’s chat. Our team is rapidly innovating to evolve and define the future of our brands. With the help of some of the brightest minds in retail, marketing, licensing, legal and more, we are building the intersection of digital and experiential marketing to help achieve that mission. We reimagine, evolve and transform brands! At Authentic, we foster an inclusive workplace where diversity of thought and expertise drive competitive advantage. Our global teams are built by go-getters who contribute unique perspectives and push the boundaries of creativity and innovation. Headquartered in New York City, Authentic has offices in major metropolitan cities including Los Angeles and Miami, as well as Toronto, Mexico City, London, and Shanghai.

 

Position Justification

As the organization continues to grow and adopt new technologies, the security and compliance function must scale beyond reactive reviews and ad hoc guidance. Business teams are increasingly relying on SaaS platforms, APIs, cloud services, integrations, automation, and AI-enabled tools to support daily operations. Each of these areas can introduce risk if access, data protection, vendor oversight, logging, configuration, and control requirements are not consistently managed.

Establishing a Manager, Security & Compliance role will provide dedicated oversight for security risk management, application and integration reviews, control design, compliance support, and secure technology adoption. This role will help reduce regulatory, audit, operational, and reputational risk by ensuring that security and compliance requirements are built into new initiatives early, documented clearly, and tracked through remediation.

The role will also relieve existing teams of one-off security assessments, strengthen accountability across the control environment, and create a scalable function that supports the business while maintaining appropriate governance over sensitive data and critical systems.

Position Overview

We are seeking a Manager, Security & Compliance to help strengthen the organization’s cybersecurity, technology risk, and compliance programs. This role will be responsible for evaluating security risks, designing practical controls, supporting audit and compliance activities, and partnering with business and technology teams to ensure new systems, integrations, and processes are implemented securely.

This is a highly visible, cross-functional role suited for someone who can operate effectively in a fast-moving, lean environment. The successful candidate will work directly with application owners, business leaders, IT, legal, and technology teams to translate security and compliance expectations into clear, practical requirements without unnecessarily slowing down the business.

This role reports to the Director of Cyber Security & Compliance.

What You’ll Do

  • Lead security and compliance reviews for new and existing technologies, including SaaS platforms, applications, APIs, cloud services, integrations, automation tools, and AI-enabled solutions.
  • Assess risk across business and technology initiatives, with a focus on data protection, access controls, vendor risk, logging, auditability, and secure configuration.
  • Define and implement practical security controls that align with business needs, regulatory expectations, internal policies, and audit requirements.
  • Partner with application owners and business stakeholders to identify security and compliance requirements early in the project lifecycle.
  • Conduct security and architecture reviews for applications, APIs, integrations, data flows, and third-party platforms.
  • Support compliance activities, including evidence collection, control documentation, risk remediation tracking, user access reviews, and audit response.
  • Strengthen application and network security posture by contributing to secure design, vulnerability management, control improvements, and remediation planning.
  • Review third-party technology solutions and support vendor due diligence from a security and compliance perspective.
  • Establish and maintain guardrails for technology use, including acceptable use, data handling, access management, logging, monitoring, and approval standards.
  • Support incident response and investigations involving applications, integrations, vendor platforms, data exposure, or control failures.
  • Track risks, issues, remediation plans, and control maturity, and provide clear reporting to leadership.
  • Help develop lightweight, scalable processes for reviewing and approving new technologies in a growing organization.
  • Stay current on emerging threats, compliance expectations, cybersecurity frameworks, and industry best practices.
  • Implement and test CI/CD and secure development controls within internally developed applications.

What You Bring

  • Bachelor’s degree in Computer Science, Information Security, Information Systems, or a related field.
  • 7+ years of experience in cybersecurity, technology risk, IT audit, compliance, application security, or network security.
  • Strong understanding of security and compliance fundamentals, including access management, authentication, authorization, data protection, logging, vulnerability management, and secure configuration.
  • Experience reviewing applications, APIs, SaaS platforms, cloud environments, or integration-heavy technology ecosystems.
  • Familiarity with application security concepts, including OWASP risks, secure SDLC practices, API security, and data protection requirements.
  • Solid grounding in network security concepts and modern enterprise architectures.
  • Experience designing, documenting, or testing security controls in SaaS, cloud, or API-driven environments.
  • Ability to perform risk assessments and translate findings into practical, business-friendly recommendations.
  • Experience supporting audits, compliance programs, or security governance activities.
  • Strong communication skills and the ability to influence decisions across technical and non-technical teams.
  • Comfortable operating in a lean, fast-paced environment with evolving priorities.

Nice to Have

  • Familiarity with frameworks such as NIST CSF, CIS Controls, SOC 2, ISO 27001, or similar control frameworks.
  • Experience supporting SOC 2, internal audit, external audit, or regulatory compliance programs.
  • Experience with third-party risk management, user access reviews, policy governance, or control testing.
  • Exposure to AI governance, emerging technology risk, or responsible AI initiatives.
  • Experience in a mid-sized or growth-stage company environment.
  • Industry certifications such as CISSP, CISA, CCSP, GIAC, Security+, or similar.

Why This Role Is Unique

  • Direct impact on how the company manages cybersecurity, compliance, and technology risk as it grows.
  • High visibility with leadership, IT, legal, business stakeholders, and application owners.
  • Opportunity to build scalable security and compliance processes from the ground up.
  • Broad exposure across applications, infrastructure, cloud, SaaS platforms, integrations, and emerging technologies.
  • A chance to balance business enablement with real-world risk management, not just enforce policy.

Success in This Role Looks Like

  • New technologies are reviewed consistently, with clear security and compliance requirements defined early.
  • Security is seen as a practical business partner, not a blocker.
  • Risks are identified, documented, prioritized, and tracked through remediation.
  • Controls are practical, scalable, and aligned with audit and compliance expectations.
  • Application, integration, and third-party risks are reduced before they become issues.
  • Strong partnerships exist across security, IT, legal, compliance, and business teams.
  • AI-enabled technologies are governed as part of the broader security and compliance program, rather than managed as a standalone effort.

Primary Location Salary Range:

$140,000 - $150,000

Fraud Alert: Unauthorized Job Offers and Impersonations

We have been made aware of fraudulent job offers and interview requests being sent by individuals falsely claiming to represent Authentic. These scams are often initiated via email, employment websites and social media, and may include fake interview requests, offer letters or attempts to collect personal and financial information.

Please note:

  • All legitimate Authentic job postings can be found only on our official website (authentic.com) or through our verified LinkedIn page (https://www.linkedin.com/company/weareauthentic).
  • Authentic does not conduct interviews over Teams or Zoom without prior email correspondence from a verified @authentic.com email address.
  • We will never ask you for sensitive personal information, payment or banking details as part of the hiring process.

If you believe you've been contacted by someone impersonating an Authentic team member, please report it immediately by emailing peopleandculture@authentic.com.

Authentic is an equal-opportunity employer and we value and embrace the diversity and inclusion of all Team Members. We do not discriminate on the basis of gender, gender identity, sexual orientation, race, national origin, disability, age, marital status, protected veteran status, or other legally protected status.

For individuals with disabilities or religious obligations who would like to request an accommodation, please contact talent@authentic.com

To access Authentic' s Privacy Policy, which contains information regarding data collected from job applicants and how we use it, please click here: https://authentic.com/pages/privacy-policy 

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Authentic Brands Group ’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 07/31/2029

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.