> Markdown version of [/jobs/ext/1745935-director-global-cybersecurity-governance-risk](https://www.wearedevelopers.com/jobs/ext/1745935-director-global-cybersecurity-governance-risk). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, Global Cybersecurity - Governance, Risk,... - **Company:** Donaldson Company - **Location:** Bloomington, MN, United States - **Experience:** Expert - **Salary:** $158,000.0 - $211,300.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Identity and Access Management, PCI Data Security Standards, Zero Trust Network Access, Tisax, Information Technology, Operational Systems, Servicenow - **Published:** July 8, 2026 - **Apply:** https://www.juju.com/job/00000000geyews ## About the Role Bachelor's degree in Cybersecurity, Computer Science, Engineering, Risk Management, or related field 10+ years of progressive experience in cybersecurity, GRC, or identity management Experience managing budgets and vendors, building multi-year roadmaps, and delivering measurable outcomes through program and portfolio management Proven experience leading enterprise GRC functions Strong working knowledge of NIST CSF, NIST 800-53, ISO 27001, and SOC frameworks Experience with global regulatory and compliance programs (such as SOX, GDPR, PCI DSS, CMMC, TISAX) Experience collaborating with IAM and/or OT security leadership in large-scale environments Professional certifications (such as CISSP, CISM, CRISC, or CISA) Demonstrated experience operating in complex, global organizations This role is on-site at our world headquarters in Bloomington, MN Preferred Qualifications Experience in global manufacturing, lab environment, or OT-intensive environments Familiarity with Zero Trust, cloud security, and AI governance frameworks Strong communication and board-level presentation capabilities Proven ability to influence across matrixed IT, security, and business teams, Bachelor Degree ## Description Donaldson is committed to solving the world's most complex filtration challenges. Together, we make cool things. As an established technology and innovation leader, we are continuously evolving to meet the filtration needs of our changing world. Join a culture of collaboration and innovation that matters and a chance to learn, effect change, and make meaningful contributions at work and in communities. The Director, Global Cybersecurity Governance, Risk, Compliance & Identity is accountable for defining and executing Donaldson's enterprise cybersecurity governance and risk management strategy, while ensuring a consistent, integrated control environment across IT, OT, and product ecosystems. Provide direct leadership of the global Governance Risk Compliance (GRC) function and responsibility for Identity & Access Management (IAM/ICAM) and Operational Technology (OT) Security programs, ensuring alignment to regulatory requirements, risk, and business objectives. Build and maintain strong partnerships across the enterprise to embed security operations & compliance requirements into platforms and processes; serve as an escalation point for high-impact events and customer/security assurance needs. As an advisor to executive leadership, this role drives decision-making across global manufacturing, digital transformation, and product innovation, strengthening Donaldson's security while enabling the business. Key Responsibilities Integrate GRC, IAM, and OT security into a unified cybersecurity risk model Support M&A due diligence and integration from a cybersecurity and compliance perspective Develop, mentor, and retain a high-performing security operations organization, including hiring strategy, succession planning, performance management, and a culture of accountability and learning Establish and maintain cybersecurity KPIs, KRIs, and dashboards Advise leadership on risk, investment priorities, and regulatory exposure Drive continuous improvement of the enterprise control environment Governance, Risk & Compliance Direct leadership of the global GRC organization, including governance, risk management, compliance, and audit functions Define and mature enterprise cybersecurity governance frameworks, policies, and standards Establish an integrated risk management program spanning IT, OT, cloud, and third parties Own regulatory, legal, and customer-driven compliance programs (e.g., SOX, GDPR, CMMC, and TISAX) Oversee audits, regulatory engagements, and customer security assessments Deliver cyber risk reporting and board-facing materials Identity & Access Management Provide strategic oversight of the IAM/ICAM function, including identity lifecycle, access governance, and privileged access usingSailPointISC as the core platform, powered by ServiceNow and other technologies. Align IAM capabilities with Zero Trust architecture and security strategy Drive identity risk through metrics, reporting, and control effectiveness Partner with IAM leadership to ensure scalable, compliant identity services across global operations Define, implement, and operate the use and impact of GenAI within IAM landscape along with use of GenAI in the ecosystem Operational Technology (OT) Security Provide strategic oversight of OT cybersecurity strategy and governance across manufacturing, labs, and ICS environments Appy consistent security controls and risk management practices across plants and, lab environments Partner with OT and manufacturing & technical leaders to embed security into system lifecycle and operations Align OT security with regulatory, safety, and business continuity requirements ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)