Cybersecurity GRC Manager (Hybrid)

Koch Engineered Solutions
Houston, TX, United States
4 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cyber Security Internet Security Network Information Services RSA Archer Platform CIS Benchmarks Servicenow

Job description

Koch Engineered Solutions (KES) is looking for a Cybersecurity GRC Manager to join our global IT capability. This is a unique opportunity to build and scale a global cybersecurity GRC program in a complex industrial environment with direct exposure to executive leadership. Reporting to the KES CISO, this role will help strengthen how KES manages cybersecurity risk, compliance obligations, and governance practices to support operational resilience, customer trust, and business decision-making.

Enjoy the flexibility of a hybrid work schedule (3 days in office) while working from one of our locations in Wichita, KS; Tulsa, OK; Houston, TX; or Scottsdale, AZ.

Please note: This position is not eligible for visa sponsorship.

Our Team

The KES IT capability partners with the KES businesses to apply technology in ways that improve performance, manage risk, and support long-term business objectives. Within IT, the KES cybersecurity capability works in close partnership with other IT functions, the Koch cybersecurity organization, and business leaders across legal, compliance, commercial, and operations to meet customer, regulatory, and contractual security expectations while embedding security considerations into business and technology processes.

As a member of this team, you will operate in a diverse, cross-functional environment with a high degree of autonomy, driving outcomes across organizational boundaries.

What You Will Do

  • Own and mature the KES cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across KES businesses.
  • Represent KES cybersecurity in internal meetings, review boards, and cross-functional forums, including coordination with the Koch cybersecurity organization.
  • Build and manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance.
  • Manage cybersecurity compliance obligations across regulatory, contractual, and customer requirements, including NIS2, China MLPS, NERC CIP, and other applicable cybersecurity standards and frameworks.
  • Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders.
  • Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services.
  • Coordinate the KES cybersecurity awareness program in partnership with the Koch cybersecurity organization, tailoring content, driving participation, and tracking effectiveness.
  • Monitor emerging cybersecurity risks, regulatory changes, technology trends, and program metrics to improve visibility, inform risk decisions, support executive reporting, and strengthen program effectiveness.
  • Travel as needed - approximately 10%

Requirements

  • Experience in cybersecurity governance, risk, and compliance program management, including risk registers, remediation tracking, and compliance obligations.
  • Experience interpreting regulatory, contractual, and customer cybersecurity requirements and translating them into practical business actions.
  • Experience partnering with cross-functional stakeholders and leaders.
  • Demonstrated ability to influence in a matrixed environment.

What Will Put You Ahead

  • Experience with GRC platforms such as ZenGRC, ServiceNow GRC, or similar tools to manage risk, compliance, and audit activities.
  • Experience with cybersecurity requirements or frameworks such as NIS2, China MLPS, NERC CIP, ISO 27001, NIST CSF, CIS Controls, or other commonly used cybersecurity maturity frameworks.
  • Experience supporting customer cybersecurity questionnaires, contract security reviews, evidence requests, or external security assessments.
  • Experience applying cybersecurity governance and compliance practices, in a practical, risk-based manner that supports business objectives and enables informed decision-making.
  • Experience supporting cybersecurity governance in industrial, engineering, energy, manufacturing, or operational technology environments.
  • Experience supporting cybersecurity governance for emerging technologies, including AI-enabled tools or platforms.
  • Experience using AI tools to create efficiencies in business processes and role responsibilities., Artificial Intelligence (AI), Business Processes, Business Support, Computer Security, Contract Analysis, Contract Requirements, Cross-Functional, Diversity, Ecosystems, Emerging Technology, Energy Engineering, Entrepreneurship, ISO (International Organization for Standardization), Improvement Metrics, Industrial Engineering, Internet Security, Interpret Regulations, Leadership, Legal, Maintain Compliance, Manufacturing Operations, NIS (Network Information Service), Operational Improvement, Operational Strategy, Operational Support, Performance Management, Philosophy, Process Management, Program Evaluation, Project/Program Management, Regulations, Regulatory Compliance, Risk, Risk Management, ServiceNow, U.S. National Institute of Standards and Technology (NIST), Willing to Travel

About the company

All Koch companies value diversity of thought, perspectives, aptitudes, experiences, and backgrounds. We are Military Ready and Second Chance employers. Learn more about our hiring philosophy here ., As a Koch company, Koch Engineered Solutions (KES) is a dynamic network of businesses that work together to create an ecosystem of domain expertise to increase operational efficiency, improve safety, reduce waste, and reduce emissions.

At Koch, employees are empowered to do what they do best to make life better. Learn how our business philosophy helps employees unleash their potential while creating value for themselves and the company.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

Videos

See all

Related articles

See all