Cybersecurity GRC Program Manager at EnerSys, leading cybersecurity compliance efforts. Collaborating with internal teams and auditors in a hybrid work environment.
Responsibilities
Provide GRC guidance and interpretation of rules, regulations, risks, and best practices.
Execute cybersecurity risk assessment and control attestation processes, including ongoing and annual assessments.
Collaborate with Internal and External Auditors on security assessments and audits.
Review control effectiveness evidence, collect, review, and upload evidence for compliance purposes.
Document emerging and residual risk, assist in risk analysis and evaluation, and identify potential areas of risk.
Engage with internal teams and consultants to ensure adherence to processes and troubleshoot, identify, analyze, and mitigate risks in existing processes, policies, and procedures.
Lead the information security compliance program, ensuring compliance with regulations, and develop and implement effective policies and practices to secure sensitive data.
Communicate operational metrics and trend analysis for IT Leadership, and collaborate with cross-functional teams to align GRC efforts with business objectives.
Stay up to date on regulatory developments and industry trends.
Expected to travel up to 10% each year.
Requirements
A degree in a technical field (Computer Science, Information Systems, or Cybersecurity) is preferred but not required.
5+ years of experience in Information Technology and client/customer management.
Strong understanding of cybersecurity principles, risk management frameworks, and compliance standards (e.g., CMMC, EU CRA, NIS2, TISAX, Essential Eight, IEC 62443, NIST CSF&RMF, ISO 27001).
Experience working with internal and external auditors.
Excellent communication and interpersonal skills: Oral, written and listening.
Strong analytical and problem-solving abilities.
Ability to work independently and collaboratively in a cross-functional environment.
Relevant IT certification (e.g., CISSP, CISM, CISA, CRISC) other relevant certifications are preferred.
Benefits
Hybrid Work Schedule Monday & Friday: Work from home
Tuesday, Wednesday, Thursday: Onsite at the Reading, PA office
Campus Security Officer ensuring safety at Bright Horizons early childcare centers in Seattle. Responsible for access control, surveillance, and emergency response.
Sounding and Security Watch responsible for Navy asset security at NSF Diego Garcia. Conducting checks and ensuring safety during designated watch hours with strong situational awareness.
Sales Enablement Manager creating technical content for Upwind Security. Collaborating across teams to translate cloud security concepts into clear narratives for engineers and security leaders.
Security Engineer designing and implementing security measures to protect Snap Inc.'s infrastructure. Collaborating across teams while focusing on threat detection and response strategies.
IT Security & Compliance Head at Lonza leading security strategy and managing global risk. Collaboration with senior leadership to enhance information security across Capsules & Health Ingredients business.
Senior Security Manager leading security for Sanofi meetings and events across North America. Ensuring compliance with global meeting policies and managing event security operations in high - stake environments.
Security Officer maintaining safety protocols at Aloft New Orleans. Responsible for patrolling, monitoring security systems, and assisting guests with safety - related concerns.
Security Detection Specialist responsible for detecting cybersecurity incidents using advanced security technologies. Analyzing data feeds and leveraging security tools for incident detection and reporting.
Senior Incident Response Engineer at Walmart focusing on security threat campaigns to enhance detection and response capabilities. Collaborating with SOC and engineering teams to improve security posture.
Head of Infrastructure & Security at Kinatico, a RegTech leader, focused on cloud infrastructure and security governance. Leading a technically deep team of cloud engineers and security specialists in a hybrid environment.