Jobs
>
Marquand

    Manager, IT Security Governance, Risk, and Compliance - Indianapolis, United States - Allison Transmission

    Allison Transmission
    Allison Transmission Indianapolis, United States

    2 weeks ago

    Default job background
    Description

    JOIN THE TEAM THAT'S POWERING PROGRESS
    Building cities. Driving commerce. Saving lives. For over 100 years, Allison Transmission has powered the vehicles and technology that move our world forward.
    What powers us? Our employees.

    From the first person hired by James Allison in 1915 to the thousands across the globe who work for Allison today, we're driving progress everywhere because we employ top talent worldwide.

    Learn more about this role and how you can begin driving your career forward

    Job Title:
    Manager, IT Security Governance, Risk, and Compliance

    Pay Grade:
    M3

    Job Description:

    JOIN THE TEAM THAT'S POWERING PROGRESS
    Building cities. Driving commerce. Saving lives. For over 100 years, Allison Transmission has powered the vehicles and technology that move our world forward.
    What powers us? Our employees.

    From the first person hired by James Allison in 1915 to the thousands across the globe who work for Allison today, we're driving progress everywhere because we employ top talent worldwide.

    This is an exciting opportu nity in Indianapolis, IN for an IT Security Governance, Risk, and Compliance (GRC) Manager .

    Learn more about this role and how you can begin driving your career forward
    This position serves as a critical member of the Information Systems and Services and Information Security team. You will be responsible for supporting the CISO with the adoption and implementation of Cybersecurity Strategy, Policies and Standards.

    You will build and maintain a GRC roadmap that encompasses industry standards like Sarbanes Oxley, NIST CSF, CMMC, and various privacy regulations.

    The IT Security GRC Manager will be responsible for day-to-day activities in implementing the information security and compliance program.

    You will assist in maintaining audit and compliance initiatives to ensure policies, standards, procedures, and audit activities are in alignment with business, IT, and regulatory requirements.

    You will participate in and support various department activities which may include development and monitoring of IT general controls, quarterly user access reviews, the development and maintenance of information security policies, procedures, and standards; training, and awareness activities; review and respond to security requirements and inquiries regarding existing or proposed solutions.

    In this role you will liaison with internal and external audit functions to gather evidence and collaboratively determine how to best track and resolve identified deficiencies.

    In addition, this role will collaborate closely with Human Resources, Legal, and other business partners to ensure compliance requirements are understood.

    You will also coordinate efforts with Information Security, Project Management Office, Enterprise Architecture, and IT Operations teams to ensure that compliance requirements are appropriately addressed, supervised, and reported to business stakeholders.


    Key Responsibilities:

    • Develop and lead an IT security risk management program to identify, assess, and manage risks, including effective data-driven reporting and tracking of risk reduction activities.
    • Understand and interpret laws and regulatory requirements related to information protection and develop and implement appropriate processes to keep the Allison in compliance and reduce legal liabilities.
    • Measure and assure that controls are in place and managed properly to meet legal and regulatory compliance for the protection of all of Allison information assets.
    • Identify gaps and potential security concerns, provide mitigation strategies, and lead all aspects of remediation activities.
    • Provide domain expertise in the creation, implementation, and maintenance of appropriate IT security risk programs, policies, and procedures to be aligned with all applicable regulations including ITAR (International traffic in Arms Regulation), EAR (Export Administration Regulation), NIST (National Institute of Standards and Technology), SOX (Sarbanes Oxley Act), and various privacy regulations across the IT environment.
    • Provide security expertise and guidance around security issues and recommend solutions to mitigate and eliminate compliance risks to Allison information assets.
    • Take the helm in monitoring, measuring, and reporting on controls effectiveness for security and compliance, nimbly adjusting strategy and implementation as needed.
    • Provide periodic updates to IT leadership regarding the status of the ITGC SOX testing plans, the issues identified, and the decisions regarding the solutions to address the identified problems.
    • Employ manual and automated techniques to verify ongoing technical and procedural compliance with organizational standards.
    • Assist organization in maintaining a security posture commensurate with the risk tolerance of the organization while meeting business objectives, and regulatory requirements.
    • Lead the tracking and periodic reviews of defined exceptions to security policies and standards.
    • Maintain relationships with internal and external audit and compliance agencies to facilitate execution of audits.
    • Participate and act as a point of contact for IT security risk assessment, customer due diligence questionnaires, audits, regulatory responses.
    • Track and report on IT audit and risk findings, including coordinating IT management forums for discussion and reporting of these findings.
    • Lead the Information Security Awareness Training program across the global organization, including training tools and reporting.
    • Lead the Allison Transmission Third Party Cyber Risk management program.
    • Lead a small team (less than 5) of direct reports.

    Key Performance Indicators:

    • Execute, lead, enhance, and implement processes to stay in sync with IT regulatory and corporate requirements.
    • Lead the IT Security GRC team by monitoring the team's workload, assigning tasks, reviewing work, meeting the goals of the global organization.
    • Implement Governance, Risk, and Compliance (GRC) methodologies and tools to support structured, traceable, and repeatable processes.
    • Develop processes to efficiently collect data to demonstrate control effectiveness for security frameworks.
    • Develop and maintain the program roadmap; drive, prioritize, and implement an agenda to deliver tangible results
    • Develop, implement, and supervise reporting mechanisms for governance, security, and risk practices to support compliance and highlight areas of exposure
    • Develop, improve, operationalize enterprise-level security, risk and privacy policies, processes, and controls to mitigate risk and follow applicable laws and regulations
    • Engineer a comprehensive control library, mapping our current controls to our corporate and regulatory requirements, addressing any gaps and/or inefficiencies identified.
    • Initiate, facilitate, and promote activities to build information security awareness within the ATI Organization and deliver training and oversight in accordance with established information security policies and procedures.
    • Provide guidance, expertise, and support for on-going program and process improvements for exceptions management within the ServiceNow system
    • Drive remediation efforts and recommendations as they relate to external and internal security audits.
    • Provide oversite and direction related to auditing automation software and applications to handle governance tasks and SOX financial reporting functions such as ServiceNow GRC and SAP GRC Process Control and Access Control software.
    • Perform continuous monitoring and maintain Plans of Actions and Milestones (POA&Ms).

    Qualifications:

    • Bachelor's degree in Computer Science, Information Technology, Cyber Security, or related subject area.
    • Risk Management certification (e.g., CRISC, CISSP, CISA, CRCM, or CIPP) is highly desired but not required.

    Experience:

    Required:

    • At least 5 years' experience in Risk Management, Audit, Compliance, Information Security, or IT Governance, with 2 years in a managerial role

    Preferred:

    • Understanding of SOX Controls and Requirements
    • Experience leading the design and execution of IT general controls
    • Experience with IT GRC platforms
    • Experience with policy and control development as it relates to meeting compliance requirements from relevant regulations such as ITAR, EAR, SOX, NIST, GDPR and others.
    • Experience developing System Security Plans (SSP) and maintaining Plans of Actions and Milestones (POA&Ms).
    • Experience applying cybersecurity and privacy principles to organizational requirements
    • Experience working with internal and external auditors
    Allison Transmission is an equal opportunity employer.

    We have opportunities for all qualified applicants regardless of age, race, color, sex, religion, creed, national origin, disability, sexual orientation, gender identity/expression or veteran status.

    If you are an individual with a disability or a disabled veteran requiring assistance and/or reasonable accommodations reviewing any of the careers information, please contact us at

    Please note that Allison Transmission will make an offer of employment only to individuals who have applied for a position using our official application.

    Be on alert for possible fraudulent offers of employment. Allison Transmission will not solicit money or banking information from applicants.

    Primary Location:
    Indianapolis, IN

    Additional Locations:
    Allison Transmission is an equal opportunity employer.

    We have opportunities for all qualified applicants regardless of age, race, color, sex, religion, creed, national origin, disability, sexual orientation, gender identity/expression or veteran status.

    If you are an individual with a disability or a disabled veteran requiring assistance and/or reasonable accommodations reviewing any of the careers information, please contact us at ati+- .

    Please note that Allison Transmission will make an offer of employment only to individuals who have applied for a position using our official application.

    Be on alert for possible fraudulent offers of employment. Allison Transmission will not solicit money or banking information from applicants.
    Allison Transmission is the world's largest manufacturer of commercial-duty automatic transmissions and hybrid propulsion systems.

    Our products are specified by more than 300 of the world's leading vehicle manufacturers and are used in a range of market sectors—from bus, refuse and emergency to construction, distribution and defense.

    Allison was founded in 1915 in Indianapolis, Indiana, where the company's global headquarters is still located.

    We have approximately 1,400 dealer and distributor locations, employ more than 2,700 people around the world and our international presence spans more than 80 countries.

    Allison Transmission is an equal opportunity employer.

    We have opportunities for all qualified applicants regardless of age, race, color, sex, religion, creed, national origin, disability, sexual orientation, gender identity/expression or veteran status.

    If you are an individual with a disability or a disabled veteran requiring assistance and/or reasonable accommodations reviewing any of the careers information, please contact us at

    Please note that Allison Transmission will make an offer of employment only to individuals who have applied for a position using our official application.

    Be on alert for possible fraudulent offers of employment. Allison Transmission will not solicit money or banking information from applicants.


  • Apex Systems Indianapolis, United States

    Apex Systems is looking for a qualified individual to fill an immediate opening for a Jr. Security Risk and Compliance Analyst. Please see the job description below for details of the role. · Job Duties and Responsibilities: · As a key member of the security team, the analyst mus ...


  • Allison Transmission Holdings, Inc Indianapolis, United States

    JOIN THE TEAM THAT'S POWERING PROGRESS · Building cities. Driving commerce. Saving lives. For over 100 years, Allison Transmission has powered the vehicles and technology that move our world forward. · What powers us? Our employees. From the first person hired by James Allison ...


  • Allison Transmission Indianapolis, United States

    JOIN THE TEAM THATS POWERING PROGRESS · Building cities. Driving commerce. Saving lives. For over 100 years, Allison Transmission has powered the vehicles and technology that move our world forward.What powers us? Our employees. From the first person hired by James Allison in 19 ...


  • Johnson Controls International Indianapolis, United States contract

    · What you will do · Under general supervision, responsible for the overall execution and performance of mechanical retrofit projects. · Responsible for following consistent and repeatable project management standardized procedures and processes, and achieving financial results ...


  • Pinnacle Partners, Inc Indianapolis, United States

    The Electrical System Engineer will utilize plant system knowledge to assist in the mitigation of risks within the facilities. · Responsibilities: · Provide OSHA arc flash and hazardous energy support to field maintenance teams for new product integration or facility renovation. ...


  • Selby Jennings Indianapolis, United States

    Purpose: · The Senior Credit Risk Analyst will report to the Credit Risk Analysis Manager and provide expertise for a range of credit risks impacting the Bank. Perform credit analysis through identifying, measuring, monitoring, and evaluating the risk of the Bank's secured and un ...


  • ERM Indianapolis, United States

    ERM is hiring a Health & Safety Manager in Indianapolis, IN. In this critical role, you will be responsible for establishing, implementing, managing and continuously improving the environment, health and safety programs for the facility. The H&S Manager will have broad knowledge ...

  • Pinnacle Partners, Inc

    Electrical Engineer

    2 weeks ago


    Pinnacle Partners, Inc Indianapolis, United States

    TITLE: Electrical Engineer · COMP: $100K-$140K · LOCATION ONSITE: Indianapolis, In · Pinnacle Partners is assisting our client in the search for an Electrical Engineer · RESPONSIBILITIES: · Provide OSHA arc flash and hazardous energy control support · Travel to industrial jobsi ...


  • UnitedHealth Group Indianapolis, United States

    At UnitedHealthcare, we're simplifying the health care experience, creating healthier communities and removing barriers to quality care. The work you do here impacts the lives of millions of people for the better. Come build the health care system of tomorrow, making it more resp ...


  • Laguna Source Indianapolis, United States

    This is an exciting opportunity to join a leading food manufacturing company that produces and distributes low-calorie nutritional products as well as innovative powders and low acid aseptic beverages targeting consumers who seek healthier alternatives. Your overall responsibilit ...

  • Elevance Health

    Compliance Director

    16 hours ago


    Elevance Health Indianapolis, United States

    Compliance Director · Location: Richmond, VA. · Open to other Pulse Point locations, must be within a 50 mile radius of a Pulse Point location. · This position will take part in Elevance Health's hybrid workforce strategy which includes virtual work and 1-2 days in office per ...


  • Indy Gov Indianapolis, United States

    Enterprise Security Manager · Print ) · Apply · Enterprise Security Manager · Salary · $87,402.16 Annually · Location · City County Building, IN · Job Type · Full Time · Job Number · 08002 · Department · Information Services Agency · Opening Date · 12/14/2023 · Closing Date · Con ...

  • Travelex Deutschland Gmbh

    Senior Manager

    2 weeks ago


    Travelex Deutschland Gmbh Indianapolis, United States

    Working in the Compliance and Risk Team, C&R Manager will be working alongside the Head -C&R to ensure the integrity of the day-to-day operations of a wide range of Compliance processes being delivered from the service centre. This is a generalist role where C&R Manager would be ...


  • Option Care Health Indianapolis, United States

    Extraordinary Careers. Endless Possibilities. · With the nation's largest home infusion provider, there is no limit to the growth of your career. · Option Care Health, Inc. is the largest independent home and alternate site infusion services provider in the United States. With ...


  • Enscicon Corporation Indianapolis, United States

    Our client is seeking a highly qualified, experienced Senior Process Engineer at their Indianapolis, IN location to support their work in creating sustainable manufacturing processes for a better future. · Responsibilities: · Lead process engineering projects, including feasibi ...


  • Federal Home Loan Bank of Indianapolis Indianapolis, United States

    Don't let our name scare you, we are not your average bank. · With nearly a century of service, FHLBI is one of 11 independent regional cooperative banks across the U.S. Simply put, we're a bank for banks, credit unions, community development financial institutions and insurers ...

  • Travelex Deutschland Gmbh

    Team Lead

    2 weeks ago


    Travelex Deutschland Gmbh Indianapolis, United States

    Team Lead - Compliance & Risk page is loaded · Team Lead - Compliance & Risk · Apply · locations · IND - Mumbai - Corporate Office · time type · Full time · posted on · Posted 30+ Days Ago · job requisition id · JR42933 · Role purpose · Why does this role exist in the ...

  • Creative Financial Staffing

    Finance Manager

    5 days ago


    Creative Financial Staffing Indianapolis, United States

    Finance Manager · Our client, a dynamic and impactful non-profit organization, is seeking a new Finance Manager to join their team in Indianapolis, IN. · Position Overview: The Finance Manager will play a critical role in managing the financial operations of the organization, e ...


  • Knewin Indianapolis, United States

    Employer Industry: Life Sciences · Why Consider this Job Opportunity: · - Salary up to $150,000 · - Opportunity for career advancement and growth within the organization · - Work remotely with a flexible work arrangement · - Eligible for bonus/incentive pay · - Comprehensive ben ...

  • Creative Financial Staffing

    Finance Manager

    2 weeks ago


    Creative Financial Staffing Indianapolis, United States

    Finance Manager · Our client, a dynamic and impactful non-profit organization, is seeking a new Finance Manager to join their team in Indianapolis, IN. · Position Overview: The Finance Manager will play a critical role in managing the financial operations of the organization, e ...