About Us:
Join us at WinCo Foods, where we're more than just a grocery retailer - we're a growing family of over 140 supermarkets in 10 states with over 22,000 employee owners. Our purpose is to make the lives of our customers and employee owners better by offering the lowest possible prices to feed their families. Currently, WinCo is the second largest Employee-Owned company in the United States. With more than 500 millionaire employee-owners in our Employee Stock Ownership Plan (ESOP). Our benefits, including top-tier medical plans and tuition support set us apart. In your role, you'll be instrumental in making a real impact in the communities we serve, embodying our purpose every day.
Overview:
Job Summary
The GRC Lead is a key member of the IT Security team, responsible for leading the strategy, development, and implementation of WinCo Foods’ cybersecurity Governance, Risk, and Compliance (GRC) program. This role owns the evolution of GRC to drive enterprise risk visibility, ensure regulatory alignment, and measure security maturity. This position blends governance leadership with technical depth, ensuring GRC platforms, processes, and controls deliver meaningful business value and support enterprise security objectives. The GRC Lead will support executive and business leadership with clear, practical risk insight that helps inform prioritization, investment decisions, and risk acceptance across the enterprise.
Typical Duties and Responsibilities
Governance and GRC Program Leadership
- Establish and maintain the enterprise GRC charter, scope, and overall operating model.
-
Develop and maintain security policies, standards, and procedures aligned with business objectives and regulatory requirements.
-
Establish governance processes to ensure security requirements are incorporated into new systems, projects, and technology deployments prior to go-live.
-
Promote a culture of compliance, risk awareness, and accountability across IT and business functions.
-
Provide regular updates on risk posture, compliance status, and program maturity to IT and Security leadership.
-
Integrate other cybersecurity areas into the GRC Program such as Vulnerability Management, Disaster Recover, Business Continuity, Penetration Testing, Third-Party Risk Management, etc.
GRC Platform and Engineering
-
Lead the design, configuration, and optimization of the organization’s GRC platform(s).
-
Develop scalable workflows for risk assessments, control management, audit tracking, and compliance reporting.
-
Integrate GRC tooling with security platforms and enterprise systems to automate evidence collection and improve efficiency.
-
Develop dashboards, analytics, and reporting capabilities to provide visibility into cybersecurity posture and risk trends.
-
Continuously evaluate and enhance the GRC architecture to align with evolving regulatory requirements and business needs.
-
Engage with vendors to improve platform capabilities and ensure solutions meet organizational requirements.
-
Ensure GRC tooling and reporting capabilities support executive decision-making, prioritization, and risk transparency across the enterprise
Compliance & Audit Management
-
Align controls with applicable frameworks and regulatory requirements (PCI-DSS, NIST CSF, CIS Controls, FAIR-CAM, etc.) and track compliance/maturity over time.
-
Lead coordination of internal and external audits, including evidence collection, control validation, and remediation tracking.
-
Monitor retail and adjacent industry risk trends to identify emerging threats and control gaps
-
Provide governance oversight to ensure audit findings and regulatory developments are reflected in enterprise
Enterprise and Cyber Risk Management
-
Build and maintain a centralized enterprise and cyber risk register
-
Define and apply a consistent risk taxonomy and assessment approach
-
Evolve risk assessments from basic qualitative scoring to scenario-based analysis
-
Support leadership in evaluating risk trade-offs, including investment decisions, operational impact, and defined risk tolerance
-
Translate risk information into something leadership can utilize in decision making, including clear trade-offs between risk reduction, operational impact, and cost
-
Provide structured risk insight to inform strategic planning and prioritization across the Security organization
-
Incorporate relevant industry breach patterns and threat developments into scenario-based risk discussions to ensure risk assessments reflect current conditions
Required Education/Experience/Skills
-
Bachelor’s degree in Information Technology, Cybersecurity, Risk Management, or a related field, or demonstrated equivalent experience.
-
At least 6 years Governance, Risk and Compliance and/or Cyber Security experience.
-
Experience leading or engineering enterprise GRC or Risk Quantification platforms.
-
Strong knowledge of cybersecurity frameworks, regulatory requirements, and risk management methodologies.
-
Ability to communicate risk clearly to both technical and non-technical audience.
-
Demonstrated leadership in cross-functional initiatives.
-
Strong communication and relationship skills, with the ability to articulate complex technical concepts to non-technical stakeholders.
-
Demonstrates a strong, well-rounded understanding of core IT Security domains, and the tools and technologies used within each area.
Preferred Qualifications
-
Retail grocery or PCI-regulated environment experience.
- GRC or Risk Quantification certifications.
-
Vendor certifications in GRC related solution.
-
Professional certifications such as CISSP, CISM, CISA, CRISC, or similar.
The above statements are intended to describe the general nature of work performed by the employee assigned to this job. All employees must comply with Company policies and applicable laws. The responsibilities, duties, and qualifications required of personnel may vary.
EEO/Inclusivity:
Applicants must be authorized to work for any employer in the U.S. on a full-time basis. We are unable to sponsor or take over sponsorship of an employment Visa at this time.
As WinCo Foods continues to grow, our diversity—from our variety of perspectives and wide range of experiences—is essential to our strategy and success. We are committed to continue to cultivate and celebrate an inclusive environment in which all employees are valued and respected regardless of their race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, or disability status.