IT Program Manager - Cyber Compliance
About the role
Eaton’s Corporate Sector division is seeking an IT Program Manager – Cyber Compliance to orchestrate and deliver Eaton’s multi-framework cybersecurity compliance program end to end. The role translates the CISO’s compliance vision into an executable, measurable plan, pivoting Eaton from reactive, event- and audit-driven activity to a continuous, assurance-based compliance capability. This is a delivery-accountable program management role with deep compliance expertise, running the full program lifecycle—scope, schedule, budget, risk, dependencies, and outcomes—across concurrent certification and assessment workstreams spanning CMMC 2.0, SOC 2, ISO 27001, and Cyber Essentials Plus (CE+). Success is the consistent, predictable achievement and sustainment of compliance assurance that protects revenue, contract eligibility, and customer preference with Eaton’s largest customers and regulators.
Responsibilities
- Compliance Program Leadership & Delivery – Own end-to-end delivery of Eaton’s Cyber Compliance Transformation Program, meeting defined objectives, timelines, scope, budget, and business outcomes across all in-scope frameworks, control sets, and sites; translate the CISO’s compliance strategy into an integrated program plan, roadmap, and roles-and-responsibilities matrix; maintain the program charter as the authoritative governing artifact; operate a single program intake to prioritize, sequence, and pace framework demands through one coordinated model.
- Framework-Specific Compliance Expertise
- CMMC 2.0 (critical path) – Lead Level 2 readiness across in-scope environments: self-assessment, POA&M remediation, CUI protection, and C3PAO assessment scheduling and execution aligned to NIST SP 800-171 and U.S. Department of Defense/Department of War contract requirements.
- SOC 2 – Manage readiness and examination cycles against the Trust Services Criteria, coordinating control evidence and auditor engagement for shared services and customer-facing environments.
- ISO 27001 – Sustain ISMS certification and surveillance/re-assessment cycles across certified sites, including mandatory documentation, internal audits, and external assessments (e.g., BSI).
- Cyber Essentials & CE+ – Drive certification and vulnerability-remediation readiness required for UK MOD and BAE contractual obligations, coordinating with assessors (e.g., URM/IASME) and site owners.
- TISAX & sector regulations – Maintain TISAX and adjacent regulatory obligations (e.g., EASA Part-IS for aerospace sites), mapping shared controls to reduce duplicate effort.
- Unified Control & Continuous Assurance – Advance the Unified Control Framework and “Test-Once / Apply-Many” evidence model so a single control set and reusable evidence satisfy multiple frameworks; shift the program from point-in-time audits to continuous control testing and monitoring, ensuring controls operate effectively and assurance can be demonstrated at any time; partner with Internal Audit to define “great,” validate control testing models, and reduce exceptions through standardized remediation and tracking.
- Stakeholder, Risk, Dependency & Financial Management – Serve as the face of the program, owning the plan, risks, executive presentations, and escalations; coordinate with control owners, regional security leads, IT, legal, and business stakeholders; proactively identify, mitigate, and resolve risks, issues, and cross-framework dependencies; manage budgets, forecasts, and resources to optimize delivery efficiency and program value.
- Audit Readiness & Assessment Execution – Lead assessment-ready posture via compliance preparation playbooks, mock assessments, and standardized audit responses; sequence concurrent certifications through a roadmap-based plan; oversee the quality, traceability, and reuse of compliance evidence in Eaton’s systems of record; coordinate post-assessment issue tracking and remediation validation.
- Governance, Reporting & Program Performance – Deliver decision-ready visibility into program health through status reporting, OKRs/KPIs/KRIs, leadership presentations, and steering-committee facilitation, with timely minutes, actions, and follow-ups; apply disciplined program governance and methodology to keep multi-workstream delivery on track and decision-making timely.
- Innovation, Automation & AI Enablement – Champion scaling compliance through automation and AI—improving evidence quality and reuse, accelerating customer and regulatory questionnaire responses, and surfacing trends, gaps, and emerging risks; pilot and embed continuous control monitoring and GRC tooling that reduces manual effort while improving predictability and quality.
- Continuous Improvement & Maturity Advancement – Advance Eaton’s Compliance Maturity Model from Reactive → Proactive → Optimized, applying lessons learned to streamline processes and strengthen integration across risk, controls, and compliance.
Requirements
- Bachelor’s degree from an accredited institution in Information Security, Risk Management, Information Technology, Business Administration, or a related field (or equivalent experience).
- 10+ years of experience in program/project management, with significant time leading cybersecurity compliance, GRC, audit, or assurance programs.
- Strong working knowledge of cybersecurity compliance frameworks—CMMC 2.0 / NIST SP 800-171, ISO 27001, SOC 2, Cyber Essentials / CE+, and TISAX.
- Proven ability to deliver large, multi-workstream programs end to end—scope, schedule, budget, risk, and dependencies—and meet delivery commitments.
- Strong leadership, analytical, problem-solving, documentation, and stakeholder-management skills.
- Excellent communication and presentation skills, including executive and steering-committee engagement.
- Ability to operate effectively and independently in a global, matrixed organization.
- This position requires access to export-controlled information. To conform to U.S. Government export regulations, applicant must be a U.S. person as defined by applicable law.
- All candidates must currently reside within 50 miles of Beachwood, OH; Moon Township, PA; Galesburg, MI; Houston, TX; Menomonee Falls, WI; or Raleigh, NC.
Preferred Qualifications
- Program/project management certification—e.g., PMP, PgMP, Scrum Master, or Product Owner.
- Compliance/security certifications—e.g., CMMC Registered Practitioner (RP)/Certified Professional (CCP), CISA, CISM, or ISO 27001 Lead Implementer/Lead Auditor.
- Experience with unified control frameworks and “Test-Once / Apply-Many” assurance models.
- Familiarity with continuous control monitoring, GRC automation platforms, and AI-enabled compliance, audit, or risk tooling.
- Experience partnering closely with Internal Audit and enterprise risk teams.
- Experience in regulated or defense/aerospace environments (e.g., U.S. DoD/DoW, UK MOD, EASA, C3PAO assessments, CUI/ITAR).
Pay
Expected annual salary range: $130,000 – $190,000. Salaries are based upon candidate skills, experience, and qualifications, as well as market and business considerations.