Sr Manager - IT Governance, Risk, and Compliance
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Develop and maintain the Cybersecurity GRC framework, policies, standards, and procedures in alignment with regulatory requirements (e.g., ISO 27001, NIST CSF, Cyber Essentials +, SOC 2, GDPR, CMMC Level 2,3)
- Develop, maintain, and socialize IT and cybersecurity policies, standards, and procedures across the organization.
- Oversee risk mitigation and the IT risk register, lead risk assessments.
- Develop, and oversee IT control effectiveness. Experience with IT Control design review and validation.
- Coordinate internal and external cybersecurity audits and assessments, tracking findings through remediation.
- Oversee customer assessments and questionnaires.
- Build, coordinate and oversee Third-Party risk management
- Strategic Program Management and Continuous Improvement: Lead the execution of the multi-year GRC Program roadmap, tracking and reporting on key performance indicators (KPIs) and key risk indicators (KRIs) to executive leadership. Drive continuous improvement in security controls and GRC processes by implementing best practices and automating controls where feasible.
- Talent Management and Core Values: Responsible to exemplify and hold their team accountable to demonstrating the Plexus Core Values. Leader will focus on evaluating potential, driving succession planning, and ensuring their employees receive the development and coaching required to realize their full potential.
- All GT leaders are accountable for upholding the organization’s cybersecurity posture by adhering to security policies and procedures, actively participating in training, protecting data and systems, actively identifying and mitigating vulnerabilities, and promptly reporting any suspicious activity or potential security incidents.
Requirements
- Bachelor’s Degree with 8 or more years of related experience is preferred. An equivalent combination of education and/or experience will be considered., * Advanced leadership experience in dynamic, fast paced environments.
- Advanced decision making, problem solving, and prioritization skills.
- Advanced verbal and written communication skills.
- Good interpersonal, communication and leadership skills; ability to motivate people and manage resources effectively and work with business partners to achieve goals.
- Business acumen, knowledge and professionalism; understand how a business operates with the ability to develop and articulate the value proposition of a new process.
- Functional knowledge in project management skills.
- Must be self-motivated with the ability to work independently and in a team environment.
- Knowledge of industry-standard security frameworks (e.g., NIST CSF, ISO 27001, CIS Controls) and regulatory requirements (e.g., SOX, SEC, GDPR, HIPAA, CMMC).
Preferred Qualifications:
- Experience building an IT GRC function within a global organization.
- Experience building an IT Third-Party Risk function within a global organization.
- Industry recognized certifications such as the CRISC, CISA, CISSP, CISM, and/or CGEIT are preferred.
- Experience in the use and administrative setup of GRC software platforms (e.g., Vanta, ServiceNow GRC).
Physical Requirements:
- Professional office environment with suitable lighting, comfortable temperatures, and low noise level. May require prolonged periods of sitting at a desk, using a computer, and other office equipment. Minimal physical activity is generally involved, emphasizing the importance of good posture and ergonomic workplace arrangements.
Benefits & conditions
Pulled from the full job description Annual leave Employee assistance programme Company pension Private medical insurance Cycle to work scheme Car scheme, We believe in rewarding your contribution with a comprehensive package designed to support your life both inside and outside of work.
- Growth: Bespoke development plans and volunteer time off
- Health: Private medical insurance, Employee Assistance Program and vision care
- Wealth: Enhanced pension contributions, life assurance, and group income protection
- Lifestyle: Electric Vehicle and Cycle to Work schemes, plus 33 days of annual leave
About the company
At Plexus, our vision is to help create the products that build a better world. By embracing an innovative culture of excellence, we pride ourselves on designing, manufacturing and servicing some of the world’s most transformative products. From life-saving medical technology and mission-critical defense solutions to sophisticated industrial automation, we’re proud to partner with our customers to bring their complex ideas to market.
Visit Plexus.com to learn more about our unwavering commitment to our vision.
Living Our Values
With a vision rooted in the wellbeing and inclusive engagement of our team members, our customers, their end users and our communities, people are the heart of what we do and who we are. Our values unite and guide us in everything that we do.
Our values include: Growing our People, Building Belonging, Innovating Responsibly, Delivering Excellence and Creating Customer Success.
As part of our team, you’ll do impactful work within an inclusive environment where everyone works together to achieve extraordinary outcomes. You’ll be empowered to reach your full potential through managing your own personalised development plan and access to our learning and development programs. Purpose Statement: Lead and manage the IT Governance, Risk, and Compliance (GRC) team, driving the development, maintenance, and execution of the GRC framework, ensuring compliance with global regulations and industry standards, and maturing the organization’s overall cybersecurity posture.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…