Senior Engineer, Global Cybersecurity Governance, Risk and Compliance
Donaldson · Bloomington, MN · Yesterday
Management$86k–$111k/yrFull-time
Key Responsibilities
- Lead and maintain the enterprise GRC risk tracking framework
- Cook up global risk review meetings with IT, business, and operational stakeholders
- Absorb, rate, and prioritize security risks against internal criteria, industry standards, and regulatory requirements
- Compile and communicate risk posture to executive leadership and IT owners, ensuring appropriate awareness and accountability
- Manage and facilitate risk assessments for new technologies, processes, and acquisitions
- Improve risk assessment processes through alignment with IT architecture and Privacy
- Lead compliance assessments against internal policies, standards, and procedures
- Partner with vendors and suppliers to conduct security reviews, including third-party risk assessments
- Review third-party attestations (e.g., SOC2), support contract security provisions with Legal, and enhance vendor risk management processes and reporting
Minimum Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or related field and/or corresponding experience
- Minimum 5 years of professional-level IT and information security experience, with a focus on IT controls, risk management, data protection, and technology compliance
- Experience conducting risk assessments and evaluating controls against frameworks such as ISO 27001, NIST, or SOC2
- Strong communication skills in describing technical risks and issues to business and operational individuals
- Strong understanding of third-party risk management and regulatory compliance requirements
- Demonstrated ability to communicate technical risks to business and executive stakeholders
- At least one relevant, current industry certification, such as CISSP, CISM, CRISC, or CISA, etc.
Preferred Qualifications
- Experience in global or multi-regional organizations with diverse regulatory requirements
- Familiarity with SOX 404, PCI DSS, NIST 800-171, ISO 27001, MLPS, Oracle security, IT policies, and procedures
- IT Audit/Consulting experience
- Familiarity with GRC platforms (e.g., ServiceNow, Archer or equivalent)
- Experience supporting audits, regulatory inquiries, or certification programs (e.g., ISO, TISAX, CMMC)
- Additional current industry certifications, such as CISSP, CISM, CRISC, or CISA, etc.
Annual Salary Range
$86,200-111,000. Actual salaries will vary based on several factors including, but not limited to applicable work experience, training, education, performance. Employee benefits are part of the competitive total rewards package that Donaldson Company, Inc. provides to you. Our comprehensive benefits program includes health benefits, retirement plan (401k), paid time away, paid leaves (including paid parental leave) and more.