Global Security Governance, Risk & Compliance Manager
Posted 5hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Global Security GRC Manager leading CMMC, vendor risk, data protection, and resilience programs. Driving security governance across engineering, manufacturing, and corporate environments.
Responsibilities:
- Drive and sustain governance, risk, and compliance across engineering, manufacturing, and corporate environments
- Report to the CISO and lead a team of GRC professionals
- Lead enterprise-wide IT execution of CMMC and other compliance program lifecycles
- Define scope, SSP/POA&M, evidence quality and refresh cadence, assessor coordination, corrective-action closure, and site-level readiness
- Coordinate control owners through a global matrix model
- Translate policies and strategic objectives into standardized processes across plants, engineering teams, and corporate functions
- Drive remediation programs and provide transparency into readiness, progress, and risk
- Mentor team members, prioritize workload, develop capability, and foster global collaboration
- Own preparation for and participation in customer and third-party audits and security questionnaires
- Leverage AI technologies to reduce manual GRC effort
- Maintain a business-impact view of risk, track remediation commitments, and escalate gaps to leadership
- Coordinate evidence, close findings, and establish sustainable corrective-action plans
- Champion a global security culture and promote accountability and risk ownership
- Translate regulatory topics into clear employee expectations
- Partner with HR and stakeholders to deliver targeted training, awareness, and role-based education
- Manage the end-to-end vendor security risk lifecycle, including assessments, treatment, remediation, and monitoring
- Operate supplier security expectations with key stakeholders and escalate systemic vendor-risk trends
- Govern data protection for intellectual property, manufacturing processes, export-controlled data, and cloud workloads
- Validate classification, DLP, access-control, and retention standards
- Govern security and compliance aspects of business continuity and disaster recovery readiness
- Define resilience-control requirements and validate recovery playbooks, exercises, and evidence
- Partner with technology and business service owners to close identified gaps
Requirements:
- Minimum of 7 years of IT GRC, information security, or regulated compliance experience
- Preferably 2 years managing a geographically diverse team
- Demonstrated ability to use generative AI and automation responsibly to improve analysis, evidence operations, knowledge management, and workflow efficiency
- Experience evaluating AI risk and governance preferred
- Defense experience strongly preferred
- Demonstrated experience with CMMC, NIST SP 800-171, and/or DFARS readiness and audit execution
- Strong oral and written communication skills
- Ability to lead cultural changes, influence people, and provide technical strategic direction
- Demonstrated problem-solving and organizational skills
- Ability to work on multiple programs at one time
- Bachelor's degree from an accredited college/university or equivalent experience
- CISSP, CISM, CRISC, CGEIT, GRCP, CGRC, GSLC, PMP, or other relevant certification preferred
- Must meet applicable U.S. export-control requirements; controlled-information access may require U.S. Person status or an export-control license
Benefits:
- Reasonable accommodation for applicants with disabilities
- Full-time remote work arrangement


















