À propos de ce poste Information Manager chez WME
POSITION SUMMARY
The Information Manager owns the organization’s information and data governance together with the security assurance program. On the information side, the role governs SharePoint and OneDrive content, retention and records, data classification and stewardship, and the Microsoft Purview control set. On the assurance side, it owns the risk register, control testing, compliance evidence, third-party risk, AI governance, and policy. A dotted line to Legal covers records, privacy, and disclosure obligations.
KEY RESPONSIBILITIES
- Own information governance across the M365 estate — SharePoint/OneDrive content lifecycle, retention and records management, sensitivity classification, and stewardship — operated through Microsoft Purview.
- Own data classification and stewardship across the estate, aligned to the data-tier security standard.
- Own the risk register, control testing, and compliance evidence; independently test and attest control effectiveness.
- Run third-party and supply-chain risk (TPRM) — assessments, tiering, and ongoing monitoring.
- Own AI governance and emerging-tech policy in coordination with the technology-governance function.
- Author and maintain cybersecurity and information policy; liaise with external auditors and Legal.
- Own and operate the enterprise GRC platform and the Purview toolset.
FUNCTIONS OWNED
GRC, Risk & Compliance · Third-Party & Supply-Chain Risk · AI Governance & Emerging Tech · Information & Data Governance (M365 / Purview) (supports Governance, Policy & Awareness and Data Protection & Data-Tier Security)
REQUIRED QUALIFICATIONS
- 8+ years spanning information governance and GRC / risk & compliance, including 3+ years at a lead or manager level.
- Hands-on Microsoft Purview (DLP, retention, sensitivity labels, records management) and M365 information governance.
- Data classification and stewardship across a Microsoft 365 estate.
- GRC and risk-management frameworks; risk treatment and independent control testing.
- Compliance literacy across GDPR, CCPA/CPRA, PIPL, and SOX ITGC.
- Third-party risk management, policy authoring, and audit liaison experience.
- Bachelor’s degree or equivalent experience; a relevant certification (CISA, CIPP, CRISC, IGP, or IAPP) required.
PREFERRED QUALIFICATIONS
- Prior ownership of a Purview or M365 information-governance rollout.
- Experience standing up or running a GRC platform.
- Collaboration with a legal, records-management, or privacy office.
Per local requirements and in the interest of transparency, the rate shown below reflects the prevalent current hiring range for this position. Hiring pay rates are based on a number of factors, including location and may vary depending on job-related qualifications, knowledge, skills and experience. The company strives to provide locally competitive rewards packages, which include base rate along with, as applicable, short- and long-term incentives, growth and developmental opportunities, and robust benefits, such as health care, retirement, vacation and other paid time off, and additional offerings.
Hiring Rate Minimum:
$131,250 annually (minimum will not fall below the applicable state/local minimum salary thresholds)Hiring Rate Maximum:
$175,000 annually