> Markdown version of [/jobs/ext/2383444-information-security-and-compliance-manager](https://www.wearedevelopers.com/jobs/ext/2383444-information-security-and-compliance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security and Compliance Manager - **Company:** Transhield, Inc. - **Location:** Elkhart, IN, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Cyber Security, Identity and Access Management, Network Segmentation, PCI Data Security Standards, Phishing, Security Information and Event Management, Simulation Software, Software Vulnerability Management, Tisax, Data Processing, Information Security Management System, IT General Controls (ITGC), RSA Archer Platform, Plan of Action and Milestones - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=923cdded1fdb7c83 ## About the Role Required * 5+ years in information security and/or IT compliance. * Experience as the primary security owner or sole practitioner - comfortable building, not just inheriting. * Experience as an auditor or managed third-party auditors directly (C3PAO, QSA, or external financial auditors). * Reviewed contracts for security/compliance obligations and translated them into actionable IT requirements. * Proficiency with vulnerability management, SIEM, IAM/MFA, and endpoint protection tooling. * Strong written communication: policy writing, SSPs, control narratives, and executive summaries. Preferred * Direct, hands-on experience managing preparation for at least two of: CMMC/NIST 800-171, TISAX, SOX ITGCs, PCI-DSS. * Background in defense manufacturing, automotive supply chain, or regulated SME manufacturing. * CISSP, CISM, CISA, or equivalent certification (or active pursuit within 12 months). * CMMC Registered Practitioner (RP) or Certified Professional (CP). * PCI-ISA or QSA credential. * Experience with Microsoft 365 / Entra ID in a compliance-scoped environment. * Familiarity with GRC platforms (Drata, Vanta, Archer, or similar). * Exposure to ITAR/EAR requirements as they intersect with information security. Who You Are * Ownership mentality - you build the program, not just maintain a checklist. * Practitioner first - comfortable writing the SSP and presenting to the CFO in the same week. * Multi-framework fluency - you hold CMMC, TISAX, SOX, and PCI context simultaneously. * Collaborative - you get compliance outcomes by working with operations, not around them. * Detail-oriented - audit-ready records are your professional standard, not a pre-audit sprint andyou read agreements for business obligations as a matter of routine. * Right-sized mindset - you know how to apply enterprise-grade thinking pragmatically in a SME. ## Description This is a founding security role - our first dedicated information security hire, functioning as a de facto individual-contributor CISO. Reporting to the Director of IT, you will design, implement, and own the company's information security program and serve as the hands-on accountable owner across a portfolio of regulatory frameworks for a modest-sized discrete manufacturer as an internationally operating Business Unit of a larger conglomerate. You will do the work directly: writing policy, managing audits, maintaining evidence, and tracking compliance obligations - while communicating clearly with leadership and external auditors., Security Program * Build and maintain the company ISMS: policies, standards, risk register, and control framework. * Own the vulnerability management program, security architecture reviews, and Incident Response plan. * Manage the vendor/third-party risk program, including security requirements in supplier contracts. * Administer annual security awareness training and phishing simulation program. * Report program status, open risks, and compliance calendar to the Director of IT. CMMC Level 2 (C3PAO) * Own the System Security Plan (SSP), POA&M, and CUI environment boundary documentation. * Serve as primary contact for C3PAO assessments; maintain audit-ready posture year-round. * Manage DFARS 252.204-7021 obligations and any subcontractor security flow-down requirements. TISAX Level 3 * Own the full TISAX assessment lifecycle: scoping, VDA ISA gap analysis, remediation, and ENX audit coordination. * Maintain the TISAX label and manage exchange requests; support OEM/Tier-1 customer verification requirements. SOX IT General Controls * Own ITGC design and evidence across logical access, change management, and computer operations. * Serve as primary liaison to external financial auditors for ITGC walkthroughs and evidence delivery. * Manage access certifications, privileged access reviews, and separation of duties controls. PCI-DSS * Own CDE scope, network segmentation documentation, and annual ROC/SAQ process with QSA. * Maintain ASV scanning and penetration testing schedules; drive remediation of findings. Contract Compliance Requirements Tracking (ISO 9001 Support) * Maintain a contract requirements register capturing security, data handling, and compliance obligations from customer and supplier contracts - supporting the company's ISO 9001 QMS. * Review incoming contracts for security and IT compliance obligations; communicate requirements to relevant teams and track fulfillment. * Partner with the Quality Manager on internal audits where contract requirements intersect with IT controls. ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Velocity with Guardrails: How Technical Teams Can Move Fast Without Losing Decision Integrity](https://www.wearedevelopers.com/magazine/747-velocity-with-guardrails-how-technical-teams-can-move-fast-without-losing-decision-integrity) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)