See all roles

Director, Cybersecurity Governance, Risk, and Compliance (GRC)

Work from home Full-time role Hiring

About the position ATI is seeking a knowledgeable Cybersecurity professional to join our organization as the Director of Cybersecurity Governance, Risk, and Compliance (GRC) as we continue to grow our team. As a leader in the Cybersecurity organization, this individual will work proactively with internal and external stakeholders, including auditors, executives, and project teams, to document and implement practices that meet ATI's defined policies, standards, and procedures. This role requires a strategic thinker who can align cybersecurity initiatives with overall business objectives. The successful candidate will be a passionate people leader who has familiarity and an appreciation of the field’s concepts, standards, and frameworks, as well as a solid digital technology skillset. The director will also play a significant role in helping to influence the organization at all levels to effect change in the way the organization thinks about cybersecurity. Ideally this person will sit at our Enterprise Resource Center located in Pittsburgh, PA, or our Corporate Headquarters in Dallas, TX.

Responsibilities

  • Provide operational oversight and serve as the leadership point of contact for the Cybersecurity Governance, Risk, and Compliance team.
  • Manage, mentor, coach, and train cybersecurity staff.
  • Manage internal and external vendors and teams conducting security assessments.
  • Proactively gather evidence from key stakeholders prior to external assessments and automate attestations when possible.
  • Manage and continuously improve an effective cybersecurity awareness program for all of ATI.
  • Develop and deliver briefings, reports, dashboards, and metrics for various levels of management and leadership.
  • Maintain responsibility for deadlines and provide analytical support for budgets in managed area.
  • Continuously evaluate cybersecurity controls to ensure effectiveness, compliance and adherence to key controls and policies.
  • Work with stakeholders across Cybersecurity, Internal Audit, Digital Technology, and the business to collaborate and execute cybersecurity standards and requirements.
  • Manage and ensure proper documentation of technical and non-technical risk and vulnerability assessments of digital technology.
  • Provide technical advisory services to business and technology teams concerning cybersecurity compliance, controls, and measurement.
  • Identify areas for improvement and assist in the development of solutions.

Requirements

  • At least five (5) years of experience in a leadership role, performing risk and vulnerability management and implementing cybersecurity frameworks, such as NIST and CMMC.
  • At least three (3) years of experience with risk management frameworks and implementation, as well as vulnerability analysis and metrics.
  • High School Diploma or GED required.
  • Must be eligible to obtain a security clearance.
  • Applied knowledge in: Cybersecurity concepts and technical implementations, Cybersecurity standards, policies, and frameworks, Cybersecurity risk management, Common risk and cybersecurity assessment methods, Cybersecurity laws, regulations, and standards.
  • Understanding of information technology, and cybersecurity compliance assessment methods.
  • Working knowledge of network interoperability, cybersecurity, and survivability issues, including cybersecurity best practices and standards.
  • Ability to communicate effectively across various levels and organizational lines.
  • Reasoning and problem-solving skills.
  • Ability to work independently with limited supervision.

Nice-to-haves

  • Bachelor's Degree in Cybersecurity, Information Systems, Computer Science, Engineering, or related discipline.
  • Prior experience working in a manufacturing or industrial business environment.
  • Industry standard certification in cybersecurity (OSCP, CISSP, CISA, etc.).
  • Experience with third party and supply chain risk.

Apply tot his job Apply To this Job

You might like

The GRC Process Architect

Work from home Full-time role

GRC Specialist; Risk and Compliance - Fully Remote

Work from home Full-time role

GRC Analyst — FedRAMP & Cloud Compliance (Remote)

Work from home Full-time role

Copy of GRC Reporting and Metrics Specialist

Work from home Full-time role

Senior GTS GRC Analyst, Europe

Work from home Full-time role

Defense Intelligence and Operations Analyst, Senior

Work from home Full-time role

Analyst, Strategic Intelligence

Work from home Full-time role

Business Intelligence Analyst - $45. .12 per hour

Work from home Full-time role

Sr. Cyber Security Engineer, GRC Admin (Remote)

Work from home Full-time role

Sr. Market Intelligence Analyst – Stop Loss – Remote

Work from home Full-time role

Office Administrator job at CentralReach in Ft. Lauderdale, FL, Holmdel, NJ, Verona, Italy

Work from home Full-time role

Digital Marketing Project Coordinator - 1331 - Pretoria, South Africa

Work from home Full-time role

Sr Clinical Project Associate

Work from home Full-time role

Senior Tableau Analyst/Developer

Work from home Full-time role

Experienced Full Stack Data Entry Specialist – Remote Opportunity for Teens with No Experience at arenaflex

Work from home Full-time role

Occupational Therapy Remote - South Dakota

Work from home Full-time role

Experienced Data Analyst – Global Marketplace Evaluation and Platform Experience

Work from home Full-time role

Licensed Marriage & Family Therapist (LMFT) - Couples & Family Therapy

Work from home Full-time role

[Remote] Business Development Representative (Mississauga, Remote)

Work from home Full-time role

Experienced Customer Support Representative – Healthcare Solutions Expert (FULLY REMOTE)

Work from home Full-time role