Governance, Risk & Compliance Manager (IT)
Carter's • Atlanta, Georgia • Full Time
Posted on Thu, Oct 1, 2026
Serving the needs of all families with young children, Carter’s Inc. is the largest North American apparel retailer exclusively for babies and young children, encompassing Carter’s, OshKosh B’gosh, Skip*Hop and Little Planet brands. Meaningful work, constant learning, genuine people, and a community guided by core values that promote inclusion and innovation is in everything we do. There are many reasons to build your career at Carter's.
How you’ll make an impact:
As Carter's accelerates its use of AI technologies — including generative AI assistants, AI-enabled SaaS applications, MCP (Model Context Protocol) connectors, and agentic workflows — this role will ensure that AI adoption is governed with the same rigor applied to any other enterprise technology risk. The Manager will balance traditional IT GRC fundamentals with forward-looking AI governance leadership, making this a uniquely strategic position within the IT organization.
AI Governance & Emerging Technology Risk (YR 1 – approx. 60%)
- Lead the development and implementation of Carter's AI Governance Framework, defining policies for acceptable use, data classification, model risk, vendor AI tools, and agentic workflows aligning with the company’s ERM program.
- Maintain a comprehensive inventory of AI tools and connectors deployed across the enterprise, including MCP servers, generative AI platforms, and AI-enabled SaaS integrations (e.g., Atlassian, Microsoft 365, Snowflake, Adobe Analytics).
- Conduct and oversee AI risk assessments covering data exposure (including PII), identify potential vulnerabilities, unauthenticated access risks, and potential risk exposure in MCP connector packages.
- Define and enforce controls for AI connector permissions, least-privilege access, credential management, and data loss prevention in AI workflows.
- Monitor the AI regulatory landscape (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001, state AI laws) and translate requirements into actionable controls and policy updates for Carter's.
- Ensure AI governance aligns with data privacy obligations (e.g., CCPA, COPPA, GDPR) applicable to Carter's customer base, which includes children's products.
- Provide support to the Carters AI COE team and assist with AI Governance across multiple departments.
Compliance & Regulatory Management (40%)
- Oversee compliance with applicable regulatory frameworks and standards including SOX ITGC, PCI DSS, NIST (Cybersecurity and AI), and CCPA etc.
- Manage the IT control testing calendar, coordinate evidence collection, and liaise with internal and external auditors throughout audit engagements.
- Track remediation of audit findings and control deficiencies, providing regular status reporting to the Director of IT GRC and leadership.
- Support enterprise IT privacy program activities in coordination with the Legal and IT teams, particularly where technology systems process personal data.
We’d Love to hear from you if: (Requirements section)
Must have:
- At Least a bachelor’s degree in a technical field of studies (Mathematics, Computer Science, Accounting, etc.)
- 7+ years of progressive experience in IT Governance Risk Compliance (GRC), information security, risk management, or a related discipline
- 7+ years of experience related to building and implementing IT Governance Risk Management programs
- 2+ years of direct involvement in AI governance, AI risk assessment, or significant responsibility for AI tool security and compliance.
- Professional certification (CISSP, CISA, CISM, CGEIT, CRISC, AAIA, AAIR or similar)
- Strong foundational knowledge of IT GRC frameworks: NIST CSF, NIST AI, ISO 27001, COBIT, SOX ITGC, PCI DSS, and SOC 2.
- Working knowledge of AI technologies, including generative AI tools, large language models, MCP (Model Context Protocol) server architectures, and agentic AI workflows.
- Experience assessing AI and SaaS vendor risk, including security questionnaire review, CVE management, and third-party audit evaluation.
- Understanding data privacy regulations applicable to Carter's: CCPA, CPRA, and GDPR.
- Proven ability to manage cross-functional programs and influence stakeholders across IT, Legal, Finance, and business without direct authority.
- Strong written and verbal communication skills; able to translate complex technical risk topics for executive and non-technical audiences.
Carters is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity, sexual orientation, national origin, genetics, disability, age, veteran status, or any other status protected by federal, state, or local law.
More live compliance_manager roles
- Compliance Manager, Customs & Trade at DSV — Lancaster, California, United States
- Procurement Compliance Manager at Global Ordnance — Tampa, Florida, United States
- Risk and Corporate Compliance Manager at Lifestream Behavioral Center — Leesburg, FL, United States
- Operational Compliance Manager at Darwin Homes (Remote)
- Grants Compliance Manager at The Arc of Prince George's County — Upper Marlboro, Maryland, United States
- Grants Compliance Manager (NCS) at City of Baltimore — United States
- Compliance Manager, Card at Affirm (Remote)
- Hr Compliance Manager at PlayStation — United Kingdom, London
- Compliance Manager / AML Officer - Transamerica Asset Management at Aegon Asset Management (Remote)
- Governance & Compliance Manager - 3 Month Contract at Delta Capita — Ireland
- Corporate Trade Compliance Manager - Export at KYOCERA AVX Corporation — Fountain Inn, South Carolina, United States
- Compliance Manager at Drucker and Falk — Newport News, VA, United States
- Senior Product Compliance Manager - Aml at Wise — London, GB
- Lead Environmental Compliance Manager (Owner's Advisor) (Field Based) at ERM — New Orleans, Louisiana, United States
- Regional Market Compliance Manager at Green Thumb (Remote)
- Invoicing Compliance Manager at Amazon — Arlington, Virginia, US
- Senior Compliance Analyst / Compliance Manager Anz at Global Payment Holding Company — SYDNEY, NEW SOUTH WALES, AUSTRALIA
- Global Trade Compliance Manager - Defense Division at Moog — Buffalo, NY
- Division Compliance Manager - Fluid Systems Division at Parker Hannifin — Irvine, California, United States
- Product Compliance Manager, Square at Block — Bay Area, CA, United States of America
- Senior Global Stock Compliance Manager at Microsoft — Redmond, Washington, United States
- Planning Compliance Manager at NBCUniversal — Bedford, GB
- Data Center Security Compliance Manager at Control Risks (Remote)
- Enterprise Risk & Compliance Manager - US Based Remote Opportunity at Common App (Remote)
- Senior Compliance Manager at Retell AI — Redwood City, California, United States
- Global Trade Compliance Manager at DRiV (Remote)
- Dot Compliance Manager at Wells — Valders, Wisconsin, United States
- Compliance Manager - Health Services at Choctaw Nation of Oklahoma (Remote)
- Compliance Manager at SmartBank — Knoxville, Tennessee, United States
- Regulatory Compliance Manager at Meharry Medical College — Not Specified
- Regulatory Compliance Manager at Healthy Kids Programs — Carmel, NY, United States
- Uk & International Trade Compliance Manager/Lead at CDW — London - GBR
- Cyber Assurance + Compliance Manager at Iberdrola — United Kingdom, Glasgow
- Divisional Programs Data and Compliance Manager at Salvation Army Careers — Carson, CA, United States
- Alcohol Compliance Manager - Part-Time - Music Festivals at Oak View Group — Oak Ridge, Texas, United States
- Alcohol Compliance Manager (Part-Time) at Oak View Group — Oak Ridge, Texas, United States
- Corporate Occupational Risk & Compliance Manager (North America) at Hydro — Houston, Texas, United States
- Alcohol Compliance Manager | Part-Time | Music Festivals at Oak View Group — Oak Ridge North, Texas, United States
- SOC Compliance Manager at CTDI Careers — West Chester, Pennsylvania, United States
- Program Enablement, Finance and Compliance Manager - Outland Youth Employment Program at Outland — Thunder Bay, Ontario, Canada
- Contracts & Compliance Manager at Ansible Government Solutions (Remote)
- Global Export Compliance Manager at Rochester Sensors — Coppell, Texas, US
- Senior Public Sector Compliance Manager at Menlo Security (Remote)
- Grants and Compliance Manager at MANNA FoodBank — Mills River, North Carolina, United States
What the data says about this job
- Advertised pay for Compliance Manager: a median of $113,044 across 918 priced postings. Explore the market
Measured from employers' own postings and public filings. How we measure