IT Program Manager - Cyber Compliance
Eaton · Menomonee Falls, WI · 1 mo ago
Hybrid$130k–$190k/yrFull-time
Key Responsibilities
- Own end-to-end delivery of Eaton’s Cyber Compliance Transformation Program, meeting defined objectives, timelines, scope, budget, and business outcomes across all in-scope frameworks, control and sites.
- Translate the CISO’s compliance strategy into an integrated program plan, roadmap, and roles-and-responsibilities matrix; maintain the program charter as the authoritative governing artifact.
- Operate a single program intake so framework demands are prioritized, sequenced, and paced through one coordinated model rather than competing efforts.
- CMMC 2.0 (critical path): lead Level 2 readiness across in-scope environments — self-assessment, POA&M remediation, CUI protection, C3PAO assessment scheduling and execution — aligned to NIST SP 800-171 and US Department of Defense / Department of War contract requirements.
- SOC 2: manage readiness and examination cycles against the Trust Services Criteria, coordinating control evidence and auditor engagement for shared services and customer-facing environments.
- ISO 27001: sustain ISMS certification and surveillance/re-assessment cycles across certified sites, including mandatory documentation, internal audits, and external (e.g., BSI) assessments.
- Cyber Essentials & CE+: drive certification and vulnerability-remediation readiness required for UK MOD and BAE contractual obligations, coordinating with assessors (e.g., URM / IASME) and site owners.
- TISAX & sector regulations: maintain TISAX and adjacent regulatory obligations (e.g., EASA Part-IS for aerospace sites), mapping shared controls to reduce duplicate effort.
- Advance the Unified Control Framework and “Test-Once / Apply-Many” evidence model so a single control set and reusable evidence satisfy many frameworks.
- Shift the program from point-in-time audits to continuous control testing and monitoring, ensuring controls operate effectively and assurance can be demonstrated at any time.
- Partner with Internal Audit to define what “great” looks like, validate control testing models, and reduce exceptions through standardized remediation and tracking.
- Actively manage budgets, forecasts, and resources to optimize delivery efficiency and program value.
Qualifications
- Bachelor’s degree from an accredited institution in Information Security, Risk Management, Information Technology, Business Administration, or a related field (or equivalent experience).
- 10+ years of experience in program/project management, with significant time leading cybersecurity compliance, GRC, audit, or assurance programs.
- Strong working knowledge of cybersecurity compliance frameworks — CMMC 2.0 / NIST SP 800-171, ISO 27001, SOC 2, Cyber Essentials / CE+, and TISAX.
- Proven ability to deliver large, multi-workstream programs end to end — scope, schedule, budget, risk, and dependencies — and meet delivery commitments.
- Strong leadership, analytical, problem-solving, documentation, and stakeholder-management skills.
- Excellent communication and presentation skills, including executive and steering-committee engagement.
- Ability to operate effectively and independently in a global, matrixed organization.