National Manager, Information Security

Company:  Kia America, Inc.
Location: 

Irvine, CA, US, 92606

At Kia, we’re creating award-winning products and redefining what value means in the automotive industry. It takes a special group of individuals to do what we do, and we do it together. Our culture is fast-paced, collaborative, and innovative. Our people thrive on thinking differently and challenging the status quo. We are creating something special here, a culture of learning and opportunity, where you can help Kia achieve big things and most importantly, feel passionate and connected to your work every day.

Kia provides team members with competitive benefits including premium paid medical, dental and vision coverage for you and your dependents, 401(k) plan matching of 100% up to 6% of the salary deferral, and paid time off. Kia also offers company lease and purchase programs, company-wide holiday shutdown, paid volunteer hours, and premium lifestyle amenities at our corporate campus in Irvine, California.

Status

Exempt 

General Summary

The Manager, Information Security is responsible for leading the Governance, Risk, Compliance (GRC), Cyber Resilience, Security Awareness, and Security Program Management activities across Kia North America. 

This role serves as the operational leader for enterprise cybersecurity governance and security program execution, ensuring alignment with Kia Global Security standards, regulatory requirements, and business objectives. 

The position partners closely with information security teams, business leaders, internal audit, legal, compliance organizations, and external service providers to maintain a strong cybersecurity posture across Kia America, Kia Canada, Kia Georgia, and Kia Mexico. 

The role reports to the Head of Information Security and acts as a key leader in driving security maturity, risk reduction, compliance readiness, and cyber resilience initiatives across the region.

This position also provides leadership in information security governance including overseeing all responses to information security audits, managing the security risk management program, advising the Information Security Management Committee (ISMC), ensuring Kia America retains its ISO27001 certification, and representing Kia NA’s interests in global security policy discussions.

Essential Duties and Responsibilities

Priority 1 - 25%

  • Lead and manage the North America Information Security Governance Program.
  • Maintain Information Security policies, standards, procedures, and guidelines.
  • Manage the Information Security Management System (ISMS).
  • Coordinate Information Security Management Committee (ISMC) activities.
  • Ensure ongoing ISO27001 certification readiness.
  • Manage internal and external security audit activities.
  • Coordinate remediation of audit findings.
  • Monitor regulatory and compliance requirements impacting cybersecurity programs.

Priority 2 - 20%

  • Own and maintain the enterprise cybersecurity risk management program.
  • Facilitate periodic risk assessments and risk treatment planning.
  • Maintain and report on the enterprise Risk Register.
  • Manage security exception and risk acceptance processes.
  • Establish and oversee Third-Party Risk Management (TPRM) activities.
  • Assess cybersecurity risks associated with vendors, suppliers, and business partners.
  • Track remediation of identified third-party security risks.

Priority 3 - 25%

  • Develop and manage the Cyber Resilience Program.
  • Lead Executive Cyber Table Top Exercises.
  • Coordinate cyber incident response simulations and readiness assessments.
  • Support business continuity and disaster recovery testing.
  • Track lessons learned and remediation activities from exercises and incidents.
  • Partner with HAEA and business units to improve cyber readiness.

Priority 4 - 20%

  • Lead execution of strategic cybersecurity initiatives.
  • Coordinate North America Information Security Workshops.
  • Facilitate collaboration among KUS, KCA, KaGA, and KMX security teams.
  • Drive regional security maturity improvement initiatives.
  • Manage key cybersecurity program milestones, deliverables, and metrics.
  • Support annual cybersecurity planning and roadmap activities.

Priority 5 - 15%

  • Lead enterprise Security Awareness programs.
  • Manage new-hire security training and annual awareness campaigns.
  • Establish metrics to measure security culture and employee engagement.
  • Develop executive cybersecurity dashboards and KPI reporting.
  • Support board-level and executive-level reporting requirements.
  • Establish governance processes for emerging technologies, including Generative AI and Cloud Services.
  • Promote responsible and secure adoption of new technologies.

This list of essential responsibilities and duties is not exhaustive and may be supplemented and changed as necessary by management.

Qualifications/Education

  • Bachelor’s degree in Information Security, Information Technology, Computer Science, Business Administration, Risk Management, or a related field.
  • Master's degree preferred.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, ISO27001 Lead Implementer, ISO27001 Lead Auditor, or equivalent are strongly preferred.

Job Requirement

  • Minimum 10 years of experience in Information Security, Cybersecurity, IT Risk Management, Compliance, Audit, or related disciplines.
  • Minimum 5 years of experience leading Governance, Risk, and Compliance (GRC) programs within a large enterprise environment.
  • Experience working in a multinational organization. Automotive industry experience is preferred.
  • Demonstrated experience developing and maintaining Information Security Governance frameworks, policies, standards, and procedures.
  • Hands-on experience managing enterprise cybersecurity risk assessment, risk treatment, and risk reporting activities.
  • Experience maintaining ISO27001 certification and coordinating internal and external audits.
  • Experience leading security compliance initiatives and managing remediation activities.
  • Experience managing Third-Party Risk Management (TPRM) programs and supplier security assessments.
  • Experience conducting executive-level risk reporting and presenting cybersecurity risks and compliance status to senior leadership.
  • Experience coordinating cross-functional initiatives involving Information Security, Legal, Compliance, Internal Audit, Privacy, and business stakeholders.
  • Physical Requirements: Primarily office-based work performed in a corporate environment.
  • May need to work additional hours outside of normal business hours as required by the job.
  • Up to 10% domestic and/or international travel.

Specialized Skills and Knowledge Required

  • Strong knowledge of Information Security Governance, Risk Management, Compliance (GRC), and industry security frameworks.
  • Working knowledge of ISO 27001, NIST Cybersecurity Framework (CSF), CIS Controls, and cybersecurity best practices.
  • Strong understanding of cybersecurity risk assessment methodologies, control frameworks, and regulatory compliance requirements.
  • Demonstrated ability to balance business objectives, cybersecurity risks, and compliance obligations while supporting organizational goals.
  • Strong leadership and stakeholder management skills with the ability to influence decisions without direct authority.
  • Excellent written, verbal, presentation, and executive communication skills.
  • Ability to develop and present security metrics, dashboards, risk reports, and recommendations to senior leadership.
  • Experience facilitating audits, managing remediation programs, and driving continuous improvement initiatives.
  • Strong vendor management and Third-Party Risk Management (TPRM) capabilities.
  • Ability to build effective working relationships with business leaders, technical teams, auditors, regulators, and external partners.
  • Strong project and program management capabilities, including managing multiple concurrent initiatives and priorities.
  • Self-motivated, proactive, and adaptable, with the ability to operate effectively in a fast-paced and evolving cybersecurity environment.
  • Strong analytical, organizational, and problem-solving skills.
  • Proven ability to lead and manage a cybersecurity governance function, including setting departmental priorities, developing team capabilities, managing resources, and overseeing the work of direct reports.

Competencies

  • Care for People
  • Chase Excellence Every Day
  • Dare to Push Boundaries
  • Empower People to Act
  • Move Further Together

 

Pay Range

$139,566 - $225,000 

Pay will be based on several variables that are unique to each candidate, including but not limited to, job-related skills, experience, relevant education or training, etc.

 

Equal Employment Opportunities

KUS provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, ancestry, national origin, sex, including pregnancy and childbirth and related medical conditions, gender, gender identity, gender expression, age, legally protected physical disability or mental disability, legally protected medical condition, marital status, sexual orientation, family care or medical leave status, protected veteran or military status, genetic information or any other characteristic protected by applicable law.  KUS complies with applicable law governing non-discrimination in employment in every location in which KUS has offices.  The KUS EEO policy applies to all areas of employment, including recruitment, hiring, training, promotion, compensation, benefits, discipline, termination and all other privileges, terms and conditions of employment.

 

Disclaimer:  The above information on this job description has been designed to indicate the general nature and level of work performed by employees within this classification and for this position.  It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.


Nearest Major Market: Irvine California
Nearest Secondary Market: Los Angeles