Jobs · Finance

IT Governance, Risk, and Compliance (GRC) Manager

Valvoline Global Operations · United States · 2 wk ago
RemoteRemoteFinanceFull-time

About the Company

At Valvoline Global Operations, we’re proud to be The Original Motor Oil, founded in 1866 as the world’s first branded motor oil. Today, as an affiliate of Aramco, one of the world’s largest integrated energy and chemicals companies, we drive innovation and create sustainable solutions for a better future. With a global presence, we develop future-ready products and provide best-in-class services for partners worldwide. Our corporate values—Care, Integrity, Passion, Unity, and Excellence—guide how we operate, treat one another, and engage with customers and communities. When you join Valvoline Global, you become part of a culture that celebrates creativity, innovation, and excellence, shaping the future of automotive and industrial solutions.

About the Role

The Manager, IT Governance, Risk, and Compliance (IT GRC) leads the organization’s information security governance, risk management, compliance, and assurance programs. This role provides strategic leadership for enterprise governance initiatives to strengthen security posture, ensure compliance with legal, regulatory, and contractual obligations, and support informed risk-based decision-making. The Manager oversees the Information Security Governance Framework, including policies, standards, procedures, compliance oversight, exception management, security awareness, privacy governance, third-party risk management, IT general controls, customer assurance activities, and continuous improvement initiatives. Additionally, this role serves as the primary leader for the IT/OT cybersecurity maturity program, driving cross-functional collaboration, executive reporting, and ongoing enhancement of security capabilities.

As a strategic partner to Information Technology, Legal, Internal Audit, Enterprise Architecture, Privacy, and business leadership, the Manager ensures governance processes are practical, measurable, and aligned with organizational objectives. The role also leads customer assurance activities, including responses to security questionnaires, contractual security requirements, customer attestations, security assessments, and external assurance programs, while serving as the primary liaison with internal and external auditors.

Responsibilities

  • Governance Leadership and Program Management (30%) – Provide strategic leadership for the IT GRC function, aligning governance activities with business objectives and the organization’s information security strategy. Lead the IT/OT cybersecurity maturity program, including executive reporting, Steering Committee governance, Aramco reporting, and cross-functional coordination to drive continuous improvement.
  • Compliance, Audit, and Risk Management (20%) – Direct information security compliance, enterprise IT risk management, privacy governance, and IT general controls programs. Serve as the primary liaison with Internal Audit and external auditors, coordinating audits, managing remediation activities, maintaining the cyber risk register, and ensuring regulatory, contractual, and internal control requirements are met.
  • Customer Assurance and Third-Party Risk (20%) – Lead customer assurance and third-party risk management activities, including customer security questionnaires, contractual security requirements, customer attestations, security assessments, and third-party security reviews. Partner with Legal, Procurement, Sales, Privacy, and business stakeholders to evaluate, communicate, and manage customer and supplier security requirements.
  • Information Security Governance Framework (20%) – Own the organization’s Information Security Governance Framework, including governance policies, standards, procedures, exception management, security awareness governance, compliance monitoring, and governance metrics. Ensure alignment with regulatory requirements, industry frameworks, and evolving business objectives while driving continuous improvement.
  • Team Leadership and Continuous Improvement (10%) – Lead, develop, and mentor the IT GRC team by establishing clear priorities, promoting professional growth, and fostering a culture of accountability, collaboration, and continuous improvement. Build strong relationships across Information Technology and business functions while driving operational excellence.

Requirements

  • Education: Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Computer Science, Information Systems, Business Administration, Accounting, Finance, Engineering, or a related field. Master’s degree in Business Administration (MBA), Information Security, Cybersecurity, Information Systems, or a related discipline is preferred.
  • Work Experience: Minimum of 8–10 years of progressively responsible experience in information security governance, risk management, compliance, information security, internal audit, enterprise risk management, or related disciplines. Minimum of 3–5 years of experience leading teams, large cross-functional programs, or enterprise governance initiatives with accountability for strategic planning, execution, and stakeholder management.
  • Demonstrated experience developing, implementing, and maintaining enterprise governance, risk, and compliance programs within a global organization.
  • Experience managing information security governance, regulatory compliance, internal and external audits, IT general controls (ITGCs), risk assessments, and third-party risk management activities.
  • Experience partnering with Legal, Internal Audit, Information Technology, Enterprise Architecture, and business stakeholders to implement governance and compliance initiatives.
  • Experience supporting customer security questionnaires, contractual security requirements, customer audits, or other customer assurance activities is preferred.
  • Experience working with governance, risk, and compliance platforms such as ServiceNow GRC, OneTrust, Archer, MetricStream, or similar solutions is preferred.

Qualifications

  • Professional certifications such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Data Privacy Solutions Engineer (CDPSE), or Certified Information Privacy Professional (CIPP) are preferred. Project Management Professional (PMP) or equivalent program management certification is also desirable.
  • Comprehensive knowledge of information security governance, risk management, compliance, and industry frameworks, including NIST Cybersecurity Framework (CSF), ISO 27001, COBIT, and related best practices.
  • Strong understanding of regulatory, contractual, and customer information security requirements, including privacy, third-party risk, IT general controls (ITGCs), and audit practices.
  • Demonstrated ability to develop, implement, and continuously improve enterprise governance programs, policies, standards, and procedures.
  • Exceptional written and verbal communication skills, including the ability to communicate complex information clearly and effectively to executive leadership, auditors, customers, and non-technical stakeholders.
  • Proven ability to influence cross-functional teams, build consensus, and lead enterprise initiatives without direct authority.
  • Strong program and project management skills, with the ability to coordinate multiple initiatives, manage competing priorities, and deliver results in a dynamic environment.
  • Excellent analytical, critical thinking, and risk-based decision-making skills, with the ability to identify dependencies, assess business impact, and develop practical, well-supported recommendations.
  • Demonstrated initiative, accountability, and ownership, with the ability to independently drive work to completion, proactively communicate risks and issues, and follow through on commitments.
  • Strong leadership and people development skills, including coaching, mentoring, performance management, and fostering a culture of continuous improvement.
  • Experience with governance, risk, and compliance technologies, workflow automation, and metrics-driven program management.
  • Ability to build and maintain effective working relationships with internal stakeholders, customers, auditors, regulators, vendors, and other external partners.
  • Ability to balance business objectives with sound information security governance and risk management practices while maintaining a customer-focused mindset.

Schedule

This role operates in a remote/office setting with travel requirements of up to 10%.

Similar jobs