Jobs
>
Marquand

    Manager, IT Security Governance, Risk, and Compliance - Indianapolis, United States - Allison Transmission

    Allison Transmission
    Allison Transmission Indianapolis, United States

    3 weeks ago

    Default job background
    Description

    JOIN THE TEAM THATS POWERING PROGRESS

    Building cities. Driving commerce. Saving lives. For over 100 years, Allison Transmission has powered the vehicles and technology that move our world forward.What powers us? Our employees. From the first person hired by James Allison in 1915 to the thousands across the globe who work for Allison today, were driving progress everywhere because we employ top talent worldwide.

    Learn more about this role and how you can begin driving your career forward

    Job Title:

    Manager, IT Security Governance, Risk, and Compliance

    Pay Grade:

    M3

    Job Description:

    JOIN THE TEAM THATS POWERING PROGRESS

    Building cities. Driving commerce. Saving lives. For over 100 years, Allison Transmission has powered the vehicles and technology that move our world forward.What powers us? Our employees. From the first person hired by James Allison in 1915 to the thousands across the globe who work for Allison today, were driving progress everywhere because we employ top talent worldwide.

    This is an exciting opportu nity in Indianapolis, IN for an IT Security Governance, Risk, and Compliance (GRC) Manager .

    Learn more about this role and how you can begin driving your career forward

    This position serves as a critical member of the Information Systems and Services and Information Security team. You will be responsible for supporting the CISO with the adoption and implementation of Cybersecurity Strategy, Policies and Standards. You will build and maintain a GRC roadmap that encompasses industry standards like Sarbanes Oxley, NIST CSF, CMMC, and various privacy regulations.

    The IT Security GRC Manager will be responsible for day-to-day activities in implementing the information security and compliance program. You will assist in maintaining audit and compliance initiatives to ensure policies, standards, procedures, and audit activities are in alignment with business, IT, and regulatory requirements. You will participate in and support various department activities which may include development and monitoring of IT general controls, quarterly user access reviews, the development and maintenance of information security policies, procedures, and standards; training, and awareness activities; review and respond to security requirements and inquiries regarding existing or proposed solutions.

    In this role you will liaison with internal and external audit functions to gather evidence and collaboratively determine how to best track and resolve identified deficiencies. In addition, this role will collaborate closely with Human Resources, Legal, and other business partners to ensure compliance requirements are understood. You will also coordinate efforts with Information Security, Project Management Office, Enterprise Architecture, and IT Operations teams to ensure that compliance requirements are appropriately addressed, supervised, and reported to business stakeholders.

    Key Responsibilities:

    + Develop and lead an IT security risk management program to identify, assess, and manage risks, including effective data-driven reporting and tracking of risk reduction activities.

    + Understand and interpret laws and regulatory requirements related to information protection and develop and implement appropriate processes to keep the Allison in compliance and reduce legal liabilities.

    + Measure and assure that controls are in place and managed properly to meet legal and regulatory compliance for the protection of all of Allison information assets.

    + Identify gaps and potential security concerns, provide mitigation strategies, and lead all aspects of remediation activities.

    + Provide domain expertise in the creation, implementation, and maintenance of appropriate IT security risk programs, policies, and procedures to be aligned with all applicable regulations including ITAR (International traffic in Arms Regulation), EAR (Export Administration Regulation), NIST (National Institute of Standards and Technology), SOX (Sarbanes Oxley Act), and various privacy regulations across the IT environment.

    + Provide security expertise and guidance around security issues and recommend solutions to mitigate and eliminate compliance risks to Allison information assets.

    + Take the helm in monitoring, measuring, and reporting on controls effectiveness for security and compliance, nimbly adjusting strategy and implementation as needed.

    + Provide periodic updates to IT leadership regarding the status of the ITGC SOX testing plans, the issues identified, and the decisions regarding the solutions to address the identified problems.

    + Employ manual and automated techniques to verify ongoing technical and procedural compliance with organizational standards.

    + Assist organization in maintaining a security posture commensurate with the risk tolerance of the organization while meeting business objectives, and regulatory requirements.

    + Lead the tracking and periodic reviews of defined exceptions to security policies and standards.

    + Maintain relationships with internal and external audit and compliance agencies to facilitate execution of audits.

    + Participate and act as a point of contact for IT security risk assessment, customer due diligence questionnaires, audits, regulatory responses.

    + Track and report on IT audit and risk findings, including coordinating IT management forums for discussion and reporting of these findings.

    + Lead the Information Security Awareness Training program across the global organization, including training tools and reporting.

    + Lead the Allison Transmission Third Party Cyber Risk management program.

    + Lead a small team (less than 5) of direct reports.

    Key Performance Indicators:

    + Execute, lead, enhance, and implement processes to stay in sync with IT regulatory and corporate requirements.

    + Lead the IT Security GRC team by monitoring the teams workload, assigning tasks, reviewing work, meeting the goals of the global organization.

    + Implement Governance, Risk, and Compliance (GRC) methodologies and tools to support structured, traceable, and repeatable processes.

    + Develop processes to efficiently collect data to demonstrate control effectiveness for security frameworks.

    + Develop and maintain the program roadmap; drive, prioritize, and implement an agenda to deliver tangible results

    + Develop, implement, and supervise reporting mechanisms for governance, security, and risk practices to support compliance and highlight areas of exposure

    + Develop, improve, operationalize enterprise-level security, risk and privacy policies, processes, and controls to mitigate risk and follow applicable laws and regulations

    + Engineer a comprehensive control library, mapping our current controls to our corporate and regulatory requirements, addressing any gaps and/or inefficiencies identified.

    + Initiate, facilitate, and promote activities to build information security awareness within the ATI Organization and deliver training and oversight in accordance with established information security policies and procedures.

    + Provide guidance, expertise, and support for on-going program and process improvements for exceptions management within the ServiceNow system

    + Drive remediation efforts and recommendations as they relate to external and internal security audits.

    + Provide oversite and direction related to auditing automation software and applications to handle governance tasks and SOX financial reporting functions such as ServiceNow GRC and SAP GRC Process Control and Access Control software.

    + Perform continuous monitoring and maintain Plans of Actions and Milestones (POA&Ms).

    Qualifications:

    + Bachelor's degree in Computer Science, Information Technology, Cyber Security, or related subject area.

    + Risk Management certification (e.g., CRISC, CISSP, CISA, CRCM, or CIPP) is highly desired but not required.

    Experience:

    Required:

    + At least 5 years experience in Risk Management, Audit, Compliance, Information Security, or IT Governance, with 2 years in a managerial role

    Preferred:

    + Understanding of SOX Controls and Requirements

    + Experience leading the design and execution of IT general controls

    + Experience with IT GRC platforms

    + Experience with policy and control development as it relates to meeting compliance requirements from relevant regulations such as ITAR, EAR, SOX, NIST, GDPR and others.

    + Experience developing System Security Plans (SSP) and maintaining Plans of Actions and Milestones (POA&Ms).

    + Experience applying cybersecurity and privacy principles to organizational requirements

    + Experience working with internal and external auditors

    Allison Transmission is an equal opportunity employer. We have opportunities for all qualified applicants regardless of age, race, color, sex, religion, creed, national origin, disability, sexual orientation, gender identity/expression or veteran status.

    If you are an individual with a disability or a disabled veteran requiring assistance and/or reasonable accommodations reviewing any of the careers information, please contact us at

    Please note that Allison Transmission will make an offer of employment only to individuals who have applied for a position using our official application. Be on alert for possible fraudulent offers of employment. Allison Transmission will not solicit money or banking information from applicants.

    Primary Location:

    Indianapolis, IN

    Additional Locations:

    Allison Transmission is an equal opportunity employer. We have opportunities for all qualified applicants regardless of age, race, color, sex, religion, creed, national origin, disability, sexual orientation, gender identity/expression or veteran status.

    If you are an individual with a disability or a disabled veteran requiring assistance and/or reasonable accommodations reviewing any of the careers information, please contact us at ati+- .

    Please note that Allison Transmission will make an offer of employment only to individuals who have applied for a position using our official application. Be on alert for possible fraudulent offers of employment. Allison Transmission will not solicit money or banking information from applicants.

    Allison Transmission is the worlds largest manufacturer of commercial-duty automatic transmissions and hybrid propulsion systems. Our products are specified by more than 300 of the worlds leading vehicle manufacturers and are used in a range of market sectorsfrom bus, refuse and emergency to construction, distribution and defense.

    Allison was founded in 1915 in Indianapolis, Indiana, where the companys global headquarters is still located. We have approximately 1,400 dealer and distributor locations, employ more than 2,700 people around the world and our international presence spans more than 80 countries.

    Allison Transmission is an equal opportunity employer. We have opportunities for all qualified applicants regardless of age, race, color, sex, religion, creed, national origin, disability, sexual orientation, gender identity/expression or veteran status.

    If you are an individual with a disability or a disabled veteran requiring assistance and/or reasonable accommodations reviewing any of the careers information, please contact us at

    Please note that Allison Transmission will make an offer of employment only to individuals who have applied for a position using our official application. Be on alert for possible fraudulent offers of employment. Allison Transmission will not solicit money or banking information from applicants.



  • Allison Transmission Holdings, Inc Indianapolis, United States

    JOIN THE TEAM THAT'S POWERING PROGRESS · Building cities. Driving commerce. Saving lives. For over 100 years, Allison Transmission has powered the vehicles and technology that move our world forward. · What powers us? Our employees. From the first person hired by James Allison ...


  • Laguna Source Indianapolis, United States

    This is an exciting opportunity to join a leading food manufacturing company that produces and distributes low-calorie nutritional products as well as innovative powders and low acid aseptic beverages targeting consumers who seek healthier alternatives. Your overall responsibilit ...


  • Insight Global Indianapolis, United States

    Description: · Insight Global is seeking a highly skilled and motivated Data Governance Specialist to join their team in Indianapolis. This candidate will need to possess a proven background in data governance frameworks and strategies, which include metadata management, data cat ...


  • Johnson Controls International Indianapolis, United States contract

    · What you will do · Under general supervision, responsible for the overall execution and performance of mechanical retrofit projects. · Responsible for following consistent and repeatable project management standardized procedures and processes, and achieving financial results ...


  • Insight Global Indianapolis, United States

    We are seeking a highly skilled and experienced Subsurface Utility Engineering (SUE) Project · Manager to join our team in Indianapolis, IN. The primary responsibility of this role will be to lead and elevate our SUE department by spearheading utility coordination efforts, expand ...

  • ProTrans

    DOT Safety Manager

    6 days ago


    ProTrans Indianapolis, United States

    Summary: · This position is responsible for ensuring that all aspects of the transportation process, from loading to unloading, meet all DOT safety CTPAT security regulations. The Safety Manager must have an extensive knowledge of DOT standards, including vehicle maintenance, and ...


  • L.L Indianapolis, United States

    We invite you to be part of our team of trailblazers dedicated to helping people discover and enjoy the outside. Come join us. Because on the inside we're all outsiders. And if it's outside, we're all in. · L.L.Bean is searching for a Retail Assistant Store Manager, Operations & ...


  • L.L Indianapolis, United States

    We invite you to be part of our team of trailblazers dedicated to helping people discover and enjoy the outside. Come join us. Because on the inside we're all outsiders. And if it's outside, we're all in. · L.L.Bean is searching for a Retail Associate Store Manager- Head of Visua ...


  • Sonablate Corp. Indianapolis, United States

    Summary · The Quality Control Manager is responsible for managing a team of quality control professionals to ensure the overall quality of manufactured products. · The role of the Quality Control Manager is to monitor, test and report on the quality of products and related proces ...


  • Atlas Oil Company Indianapolis, United States

    About Atlas · Atlas Oil Company was founded in 1985 by Sam Simon, an entrepreneur who started the company with a single credit card. Today, Mr. Simon still owns the company through his holding company, Simon Group Holdings. The Simon Group has a deep history of entrepreneurial su ...

  • Lids

    Merchandise Planner

    2 weeks ago


    Lids Indianapolis, United States

    About Our Company · Lids Sports Group is the largest licensed sports retailer in North America, selling fan and fashion-oriented headwear and apparel across the US, Canada, Mexico, Europe, and Australia. Operating out of Indianapolis, IN, our retail stores offer officially licens ...

  • Onebridge

    AI Product Owner

    4 days ago


    Onebridge Indianapolis, United States

    Onebridge is a Consulting firm with an HQ in Indianapolis, and clients dispersed throughout the United States and beyond. We have an exciting opportunity for a highly skilled AI Product Owner to join an innovative and dynamic group of professionals at a company rated among the to ...

  • Onebridge

    Product Owner

    3 weeks ago


    Onebridge Indianapolis, United States

    Onebridge is a Consulting firm with an HQ in Indianapolis, and clients dispersed throughout the United States and beyond. We have an exciting opportunity for a highly skilled Product Owner (Clinical Data) to join an innovative and dynamic group of professionals at a company rated ...


  • Optum Indianapolis, United States

    $40,000 Student Loan Repayment Or $25,000 Sign-on Bonus for Individuals Who Have Not Previously Participated in this Program · Optum Home & Community Care, part of the UnitedHealth Group family of businesses, is creating something new in health care. We are uniting industry-leadi ...

  • BMWC Constructors

    Project Manager

    4 days ago


    BMWC Constructors Indianapolis, United States

    Project Manager (Mechanical Construction) · Driven by Vision | Powered by Passion · Location: Indianapolis, IN · Company Overview: Working for global leaders in the aerospace, chemical, steel, pharmaceutical, oil & gas, power generation, and semiconductor industries, BMWC build ...


  • Ethan Crossing of Indianapolis Indianapolis, United States

    Ethan Crossing of Indianapolis - New Vista Health and Wellness is currently recruiting Housekeepers at Ethan Crossing of Indianapolis. · Day and Night Positions Available. · WHO WE ARE: · The New Vista mission: Inspiring Hope, Restoring Peace of Mind, Healing Lives. At New Vista, ...


  • Heartland Food Products Group Indianapolis, United States

    Supply Chain Quality Manager · Heartland Food Products Group is a global leader in the consumer packaged goods (CPG) industry, producing low-calorie sweeteners, coffee, coffee creamers and liquid water enhancers. We manufacture and market Splenda, the #1 brand in the low calorie ...


  • ATC Indianapolis, United States

    Title: - Maternal and Fetal Fatality Prevention Coordinator · Location: Indianapolis, IN (Remote) · Interview:- Webcam Only · Purpose of Position/Summary: · This position serves as the Maternal and Fetal Fatality Prevention Coordinator within the Division of Fatality Review and ...

  • Elevance Health

    Compliance Director

    3 weeks ago


    Elevance Health Indianapolis, United States

    Compliance Director · Location: Richmond, VA. · Open to other Pulse Point locations, must be within a 50 mile radius of a Pulse Point location. · This position will take part in Elevance Health's hybrid workforce strategy which includes virtual work and 1-2 days in office per ...


  • Hayes Gibson Property Services Indianapolis, United States

    Job Summary: · The Senior Compliance Specialist plays a critical role in ensuring compliance with government regulations, company policies, and program requirements related to affordable housing, including Low-Income Housing Tax Credit (LIHTC) programs, HUD, and other applicable ...