Cybersecurity Governance, Risk, Compliance, Training - Boston, MA - USA

Only for registered members Boston, MA - USA, United States

2 days ago

Default job background
ABOUT WIND RIVER  ·    · Wind River is a global leader in delivering software for mission-critical intelligent systems. For more than four decades, the company has been an innovator and pioneer, powering billions of systems that require the highest levels of security, safety, and ...
Job description
ABOUT WIND RIVER     Wind River is a global leader in delivering software for mission-critical intelligent systems. For more than four decades, the company has been an innovator and pioneer, powering billions of systems that require the highest levels of security, safety, and reliability.     We help customers across automotive, aerospace, defense, industrial, medical, and telecommunications industries solve complex technology challenges on their journey toward the new intelligent machine economy. The company's software powers generation after generation of the safest, most secure systems in the world.  Examples include playing a key role in NASA space missions such as Artemis I, the James Webb Space Telescope, and multiple Mars rovers. We've achieved recent 5G milestones including the world's first successful 5G data session with Verizon and  building one of the largest Open RAN networks in the world with Vodafone.     The company has received industry recognition for its technology innovation and leadership, and for its workplace culture, including global Great Place to Work certification and being named a "Top Workplace" for ten consecutive years. If you want to be part of a unique culture where experience is based on our cultural attributes of growth mindset, customer-focus, and diversity, equity, inclusion & belonging, come join us & help advance the future software defined world.  ABOUT THE OPPORTUNITY  We are hiring a Manager to lead the day-to-day execution of cybersecurity Governance, Risk & Compliance (GRC) and enterprise resilience programs across both Wind River and Aptiv. This dual-entity role will serve as a key operational leader, ensuring regulatory compliance, audit readiness, risk tracking, and documentation integrity across multiple frameworks including ISO 27001, NIST , SOX, GDPR, FedRamp, CMMC and TISAX.   While the Director maintains strategic ownership of all four functional areas (GRC, TPRM, Training, and Resilience), this role will provide hands-on coverage for Wind River's TPRM and Training efforts, working closely with the Aptiv TPRM & Training Manager to ensure continuity and alignment.   In addition, this role will own GRC workstreams supporting OneAptiv integration, directly supporting Aptiv, Wind River, and other OneAptiv companies as needed, including TSA execution and M&A onboarding. This position is critical to stabilizing day-to-day operations and enabling long-term scalability across the enterprise.   Key Responsibilities:   Governance, Risk & Compliance (GRC)
  • Lead execution of GRC programs across Aptiv and Wind River, including control maintenance, risk register updates, and audit readiness.
  • Maintain documentation, controls, and audit-ready evidence for ISO 27001, NIST , TISAX, SOX, NIS2, CMMC and GDPR across both Aptiv and Wind River, incorporating new regulatory or customer requirements as they arise.
  • Administer GRC tooling (ZenGRC, AuditBoard, ServiceNow), ensuring accuracy, auditability, and workflow continuity.
  • Manage internal risk exceptions, maturity roadmaps, and control owners' engagement.
  • Provide daily operational support to maintain compliance posture and support regulatory assessments.
  Enterprise Resilience
  • Own documentation and execution for business impact assessments (BIAs), continuity planning, and tabletop exercises.
  • Coordinate resilience planning with cross-functional partners including IT, Facilities, Cyber Defense, and Legal.
  • Maintain continuity playbooks, incident response records, and recovery planning materials.
  Wind River Support: TPRM & Training
  • Provide execution support for Wind River's third-party risk assessments, evidence collection, and remediation tracking.
  • Execute and drive enforcement of cybersecurity right-to-audit clauses with vendors and partners.
  • Review and provide redlines on cybersecurity and compliance sections of both buy-side and sell-side contracts.
  • Collaborate with the Aptiv TPRM Manager to align vendor risk governance across both companies.
  • Help coordinate Wind River's cybersecurity awareness campaigns, mandatory training compliance, and role-based content support.
  Audit & Assurance
  • Lead evidence preparation and walkthroughs for external audits, customer assessments, and internal audit reviews.
  • Maintain and update System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and customer documentation requests.
  • Coordinate audit response activities across control owners, internal SMEs, and external parties.
  OneAptiv Integration & M&A Execution
  • Support cybersecurity onboarding and governance alignment for newly acquired companies.
  • Assist with Transitional Services Agreements (TSA) by managing control design, evidence preparation, and GRC tooling integration.
  • Track risks and compliance issues related to integration timelines, especially where inherited entities lack cybersecurity maturity.
  Cross-Functional Delivery
  • Support Director-led strategic initiatives through dependable execution and documentation follow-through.
  • Work closely with Architecture, Legal, Product Security, and external vendors to manage dependencies and unblock progress.
  • Escalate capacity or clarity issues early to avoid unnecessary risk acceptance or execution gaps.
  Required Qualifications:
  • 7–10+ years of cybersecurity risk, compliance, audit, or GRC program experience.
  • Experience managing or contributing to ISO 27001, NIST , SOX, GDPR, or TISAX efforts.
  • Proficiency with GRC platforms and internal controls execution.
  • Strong writing and documentation skills.
  • Must reside in Greater Boston area with ability to be present on site at least 3 days/weekly. 
  • United States Citizenship required 
  Preferred Qualifications:
  • Experience working in a multi-entity environment or during M&A integration.
  • Familiarity with SBOM, secure SDLC, vendor risk workflows, and cybersecurity awareness campaigns.
  • CISA, CISSP, CISM, ISO Lead Auditor, or similar certification preferred.
  • Strong stakeholder management and execution discipline across matrixed teams.
  BENEFITS
  • Hybrid work model for workplace flexibility 
  • Comprehensive health, dental, and life insurance 
  • Short and long-term disability coverage 
  • RRSP matching for financial security 
  • Flexible time-off policies for work-life balance 
  • Employee assistance program for mental well-being 
  • Learning benefits, including a LinkedIn Learning subscription and seminars 
Join us at Wind River, where we're not just shaping technology; we're shaping the future of a safer, more connected world. Your journey to make a meaningful impact begins here.    APPLICANT PRIVACY NOTICE:   Your privacy is of the utmost importance to us. At Wind River, we strictly adhere to all applicable data privacy laws. Please review Wind River's Applicant Privacy Notice, which can be found here.    Wind River is an Equal Opportunity Employer with a commitment to diversity. We prohibit discrimination based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status. SECURITY CLEARANCE REQUIREMENTS     Successful candidates must engage in a security clearance process in regard to their citizenship in order to perform fundamental job duties, as per applicable law. In particular, candidates with certain citizenship may not be able to perform such fundamental job duties. Currently, this includes citizens of the following countries: Belarus; Burma; China; Cuba; Iran; North Korea; Syria; Venezuela; Afghanistan; Cambodia; Central African Republic; Cyprus; Democratic Republic of Congo; Ethiopia; Eritrea; Haiti; Iraq; Lebanon; Libya; Russia; Somalia; South Sudan; Sudan; Zimbabwe. The security clearance process may take a significant amount of time to complete, and any offer of employment will be contingent on the candidate's legal ability to perform the fundamental job duties. Wind River is committed to meeting its obligations to candidates under applicable human rights law and privacy law in this regard.   The annual base salary range for this role's listed grade level is currently $120,000 to 180,000 or $140,000 to $210,200 plus a bonus for MA and Bay area, CA residents. Salary ranges are determined through interviews and a review of the education, experience, knowledge, skills, location, and abilities of the applicant, and equity with other team members.   #LI-JP1 Special Clearance Requirements This position will perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil, and therefore any offer will be contingent upon verification of both of these requirements.

Privacy Notice - Active Candidates:

Aptiv is an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender identity, sexual orientation, disability status, protected veteran status or any other characteristic protected by law.



Similar jobs

  • Work in company

    Training & Compliance Intern (IINE Boston)

    Only for registered members

    The International Institute of New England is a 501(c)(3) non-profit serving refugees and immigrants in Boston, MA. · As a Program Training and Compliance Intern, you will work under the supervision of the Program Training and Compliance Manager to support key training, · complia ...

    Boston

    1 month ago

  • Work in company

    Cybersecurity Governance, Risk, Compliance, Training

    Only for registered members

    Wind River is hiring a Manager to lead cybersecurity Governance Risk & Compliance (GRC) programs across both Wind River and Aptiv.The role will provide hands-on coverage for Wind River's TPRM Training efforts working closely with the Aptiv TPRM & Training Manager ensuring continu ...

    Boston $120,000 - $210,200 (USD)

    1 month ago

  • Work in company

    Cybersecurity Governance, Risk, Compliance, Training

    Only for registered members

    We are hiring a Manager to lead the day-to-day execution of cybersecurity Governance Risk & Compliance GRC enterprise resilience programs across both Wind River and Aptiv. This dual-entity role will serve as a key operational leader ensuring regulatory compliance audit readiness ...

    Boston $120,000 - $210,200 (USD) Full time

    1 month ago

  • Work in company

    Cybersecurity Governance, Risk, Compliance, Training

    Only for registered members

    We are hiring a Manager to lead the day-to-day execution of cybersecurity Governance, Risk & Compliance (GRC) and enterprise resilience programs across both Wind River and Aptiv. · ...

    Boston, MA

    1 month ago

  • Work in company

    ASSISTANT DIRECTOR, NEIDL TRAINING, Research Compliance

    Only for registered members

    This position will manage training programs at NEIDL and other related programs under direction of Director / NEIDL Chief Safety Officer. ...

    Boston $100,275 - $125,000 (USD)

    3 weeks ago

  • Work in company

    ASSISTANT DIRECTOR, NEIDL TRAINING, Research Compliance

    Only for registered members

    The Assistant Director, NEIDL Training will supervise the NEIDL Trainer position as well as contracted vendors providing training and will support others in EHS leadership to ensure that the NEIDL is compliant with federal and local training requirements. · This position will be ...

    Boston $100,275 - $125,000 (USD)

    3 weeks ago

  • Work in company

    ASSISTANT DIRECTOR, NEIDL TRAINING, Research Compliance

    Only for registered members

    This position is responsible for managing training programs at the NEIDL and other related programs under the direction of the Director / NEIDL Chief Safety Officer. · Supervise the NEIDL Trainer position as well as contracted vendors providing training and will support others in ...

    Boston, MA

    3 weeks ago

  • Work in company

    Training & Compliance Specialist (GMP)

    Only for registered members

    A regulated manufacturing organization in the life sciences space is seeking a QA Training Specialist to join their Quality team. · ...

    Framingham, MA

    3 weeks ago

  • Work in company

    Manager/Senior Manager, Compliance

    Only for registered members

    Axsome Therapeutics is seeking a Manager/Senior Manager, Compliance. This role will help execute elements of the Company's healthcare compliance program. · ...

    Boston $115,000 - $130,000 (USD) Full time

    3 weeks ago

  • Work in company

    Training Manager

    Only for registered members

    This role involves implementing training at the direction of the Training Director. · Includes support of Training Needs Analysis, assigning training, interfacing with clients to troubleshoot system issues; check on accuracy training content assigned, · and vendors who supply the ...

    Boston

    1 month ago

  • Work in company

    Senior Compliance Associate

    Only for registered members

    Standish Compliance Services, LLC. (Standish Compliance) is comprised of a team of former SEC regulators, seasoned private fund experts, certified AML/KYC specialists, IT-proficient staff, and professional compliance consultants. We serve as an extension of our clients' in-house ...

    Boston

    2 days ago

  • Work in company

    Manager/Senior Manager, Compliance

    Only for registered members

    + Job summary: Axsome Therapeutics is a biopharmaceutical company leading in CNS conditions treatment. We deliver scientific breakthroughs by identifying critical gaps in care and develop differentiated products with a focus on novel mechanisms of action that enable meaningful ad ...

    Boston, MA

    3 weeks ago

  • Work in company

    Associate Director, Global Ethics

    Only for registered members

    Join us as we transform immunology and deliver medicines that help autoimmune patients get their lives back We are building a new kind of biotech company one that maintains its roots as a science-based start-up and pushes our commitment to innovate across all corners of our busin ...

    Boston

    6 days ago

  • Work in company

    Compliance Analyst

    Only for registered members

    The Compliance Analyst works closely with the Compliance Team to organize, manage and support the firm's compliance efforts. · Respond to client requests for information. · Create, update and maintain database of questionnaire and RFI responses within AG's software to facilitate ...

    Boston $60,000 - $70,000 (USD)

    2 weeks ago

  • Work in company

    Assistant Director, Healthcare Compliance

    Only for registered members

    At Ionis, we pride ourselves on cultivating a challenging, motivating and rewarding environment that fosters innovation and scientific excellence. We know that our success is a direct result of the exceptional talents and dedication of our employees. · With an unprecedented oppor ...

    Boston $108,713 - $153,658 (USD)

    1 month ago

  • Work in company

    Summer 2026 Intern: Legal and Compliance

    Only for registered members

    We're looking for a Legal and Compliance Intern to support key initiatives across Compliance and Legal functions. The role offers hands-on exposure to compliance policy development, training design contract management and legal operations within a global dermatology organization. ...

    Boston

    2 weeks ago

  • Work in company

    MLS Blood Bank Manager

    Only for registered members

    + Oversee daily laboratory operations including staffing allocation, workflow management, quality assurance, safety protocols, and regulatory compliance in the Blood Bank Department. · + Provide management oversight and strategic direction for laboratory functions. · Develop and ...

    Boston

    1 week ago

  • Work in company

    Food Safety Quality Assurance Coordinator

    Only for registered members

    To maintain the Global Quality System of LSG Sky Chefs to ensure compliance with customer, Federal Drug Administration (FDA), US Department of Agriculture (USDA), and Seafood Hazard Analysis and Critical Control Points (HACCP) plans including USDA and FDA regulatory standards. · ...

    Boston $18 - $25 (USD)

    4 weeks ago

  • Work in company

    Compliance Specialist

    Only for registered members

    M&T Securities is the institutional broker-dealer affiliate of M&T Bank. As a member of our Compliance team, you will serve an important role in promoting a culture of ethical conduct and commitment to compliance with securities regulation. · ...

    Boston $72,200 - $120,300 (USD)

    1 month ago

  • Work in company

    Compliance Director

    Only for registered members

    Our client is currently seeking a Compliance Director who will lead the organization's compliance program to ensure adherence to legal, regulatory and internal policies. · ...

    Boston, MA

    1 week ago