Cybersecurity GRC Manager
Koch · Scottsdale, AZ · 3 wk ago
On-siteInformation TechnologyFull-time
About the role
The role of Cybersecurity GRC Manager at Koch Engineered Solutions (KES) involves building and scaling a global cybersecurity GRC program in a complex industrial environment. This role reports directly to the KES CISO and plays a crucial part in strengthening how KES manages cybersecurity risk, compliance obligations, and governance practices.
Responsibilities
- Own and mature the KES cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across KES businesses.
- Represent KES cybersecurity in internal meetings, review boards, and cross-functional forums, including coordination with the Koch cybersecurity organization.
- Build and manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance.
- Manage cybersecurity compliance obligations across regulatory, contractual, and customer requirements, including NIS2, China MLPS, NERC CIP, and other applicable cybersecurity standards and frameworks.
- Cook cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders.
- Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services.
- Cook the KES cybersecurity awareness program in partnership with the Koch cybersecurity organization, tailoring content, driving participation, and tracking effectiveness.
- Monitor emerging cybersecurity risks, regulatory changes, technology trends, and program metrics to improve visibility, inform risk decisions, support executive reporting, and strengthen program effectiveness.
Requirements
- Experience in cybersecurity governance, risk, and compliance program management, including risk registers, remediation tracking, and compliance obligations.
- Experience interpreting regulatory, contractual, and customer cybersecurity requirements and translating them into practical business actions.
- Experience partnering with cross-functional stakeholders and leaders.
- Demonstrated ability to influence in a matrixed environment.
Qualifications
- Experience with GRC platforms such as ZenGRC, ServiceNow GRC, or similar tools to manage risk, compliance, and audit activities.
- Experience with cybersecurity requirements or frameworks such as NIS2, China MLPS, NERC CIP, ISO 27001, NIST CSF, CIS Controls, or other commonly used cybersecurity maturity frameworks.
- Experience supporting customer cybersecurity questionnaires, contract security reviews, evidence requests, or external security assessments.
- Experience applying cybersecurity governance and compliance practices, in a practical, risk-based manner that supports business objectives and enables informed decision-making.
- Experience supporting cybersecurity governance in industrial, engineering, energy, manufacturing, or operational technology environments.
- Experience supporting cybersecurity governance for emerging technologies, including AI-enabled tools or platforms.
- Experience using AI tools to create efficiencies in business processes and role responsibilities.
Skills
- Strong communication and interpersonal skills.
- Ability to work independently and collaboratively.
- Excellent problem-solving and analytical skills.
- Knowledge of relevant industry standards and regulations.
- Proficiency in Microsoft Office Suite.
Benefits
- Medical, dental, and vision insurance.
- Flexible spending and health savings accounts.
- Life insurance.
- Disability coverage.
- Retirement plans.
- Paid vacation/time off.
- Education assistance.
- Additional benefits may include infertility assistance, paid parental leave, and adoption assistance.
Pay
Compensation details are confidential and will be shared with candidates during the interview process.
Schedule
The role offers flexibility to sit in Wichita, KS, Tulsa, OK, Houston, TX, or Scottsdale, AZ, and may require domestic and international travel up to 10%.