Cybersecurity GRC Manager (Hybrid)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Koch Engineered Solutions (KES) is looking for a Cybersecurity GRC Manager to join our global IT capability. This is a unique opportunity to build and scale a global cybersecurity GRC program in a complex industrial environment with direct exposure to executive leadership. Reporting to the KES CISO, this role will help strengthen how KES manages cybersecurity risk, compliance obligations, and governance practices to support operational resilience, customer trust, and business decision-making.
Enjoy the flexibility of a hybrid work schedule (3 days in office) while working from one of our locations in Wichita, KS; Tulsa, OK; Houston, TX; or Scottsdale, AZ.
Please note: This position is not eligible for visa sponsorship.
Our Team
The KES IT capability partners with the KES businesses to apply technology in ways that improve performance, manage risk, and support long-term business objectives. Within IT, the KES cybersecurity capability works in close partnership with other IT functions, the Koch cybersecurity organization, and business leaders across legal, compliance, commercial, and operations to meet customer, regulatory, and contractual security expectations while embedding security considerations into business and technology processes.
As a member of this team, you will operate in a diverse, cross-functional environment with a high degree of autonomy, driving outcomes across organizational boundaries.
What You Will Do
- Own and mature the KES cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across KES businesses.
- Represent KES cybersecurity in internal meetings, review boards, and cross-functional forums, including coordination with the Koch cybersecurity organization.
- Build and manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance.
- Manage cybersecurity compliance obligations across regulatory, contractual, and customer requirements, including NIS2, China MLPS, NERC CIP, and other applicable cybersecurity standards and frameworks.
- Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders.
- Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services.
- Coordinate the KES cybersecurity awareness program in partnership with the Koch cybersecurity organization, tailoring content, driving participation, and tracking effectiveness.
- Monitor emerging cybersecurity risks, regulatory changes, technology trends, and program metrics to improve visibility, inform risk decisions, support executive reporting, and strengthen program effectiveness.
- Travel as needed - approximately 10%
Requirements
- Experience in cybersecurity governance, risk, and compliance program management, including risk registers, remediation tracking, and compliance obligations.
- Experience interpreting regulatory, contractual, and customer cybersecurity requirements and translating them into practical business actions.
- Experience partnering with cross-functional stakeholders and leaders.
- Demonstrated ability to influence in a matrixed environment.
What Will Put You Ahead
- Experience with GRC platforms such as ZenGRC, ServiceNow GRC, or similar tools to manage risk, compliance, and audit activities.
- Experience with cybersecurity requirements or frameworks such as NIS2, China MLPS, NERC CIP, ISO 27001, NIST CSF, CIS Controls, or other commonly used cybersecurity maturity frameworks.
- Experience supporting customer cybersecurity questionnaires, contract security reviews, evidence requests, or external security assessments.
- Experience applying cybersecurity governance and compliance practices, in a practical, risk-based manner that supports business objectives and enables informed decision-making.
- Experience supporting cybersecurity governance in industrial, engineering, energy, manufacturing, or operational technology environments.
- Experience supporting cybersecurity governance for emerging technologies, including AI-enabled tools or platforms.
- Experience using AI tools to create efficiencies in business processes and role responsibilities., Artificial Intelligence (AI), Business Processes, Business Support, Computer Security, Contract Analysis, Contract Requirements, Cross-Functional, Diversity, Ecosystems, Emerging Technology, Energy Engineering, Entrepreneurship, ISO (International Organization for Standardization), Improvement Metrics, Industrial Engineering, Internet Security, Interpret Regulations, Leadership, Legal, Maintain Compliance, Manufacturing Operations, NIS (Network Information Service), Operational Improvement, Operational Strategy, Operational Support, Performance Management, Philosophy, Process Management, Program Evaluation, Project/Program Management, Regulations, Regulatory Compliance, Risk, Risk Management, ServiceNow, U.S. National Institute of Standards and Technology (NIST), Willing to Travel
About the company
All Koch companies value diversity of thought, perspectives, aptitudes, experiences, and backgrounds. We are Military Ready and Second Chance employers. Learn more about our hiring philosophy here ., As a Koch company, Koch Engineered Solutions (KES) is a dynamic network of businesses that work together to create an ecosystem of domain expertise to increase operational efficiency, improve safety, reduce waste, and reduce emissions.
At Koch, employees are empowered to do what they do best to make life better. Learn how our business philosophy helps employees unleash their potential while creating value for themselves and the company.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
9 Ways to Make Money Hacking
Now is the time for industrialized software development
Is Software Engineering Over-Saturated?