# Manager - Cybersecurity GRC Compliance

**Company**: Ford Motor Company
**Location**: MI
**Work arrangement**: remote
**Experience**: senior
**Job type**: full-time
**Salary**: $115,500-$218,100
**Category**: IT
**Industry**: Automotive
**Wikidata**: https://www.wikidata.org/wiki/Q44294

**Apply**: https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/67310?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_3d1b8212-f79

## Description

The Enterprise GRC (Governance, Risk, and Compliance) team functions as a second line of defense, responsible for developing and maintaining Enterprise Technology (ET) risk management and compliance in alignment with the organization's aligned framework.

As regulatory landscapes grow more complex and cybersecurity threats continue to evolve, the need for a robust GRC framework has become mission-critical to the business.

### Responsibilities

A particular focus of this role is driving the organization's certification expansion roadmap, maintaining continuous evidence readiness, and ensuring ongoing internal and external audit preparedness , while proactively monitoring and mitigating risks that could impact certification scope or annual audit outcomes.

- Develops and executes a multi-year certification roadmap while driving continuous readiness through proactive gap analyses, mock audits, and a centralized, continuous evidence repository mapped to business and regulatory demands.

- Leads enterprise risk assessments, including internal self-risk assessments to identify compliance gaps, maintaining a continuous risk register with clear mitigation timelines while driving cross-functional corrective actions (CAPAs) through verified closure.

- Partners cross-functionally with engineering, legal, IT, cybersecurity, and business leadership to embed audit readiness into daily operations, translating complex regulatory requirements into actionable guidance while continuously updating security policies and control narratives.

- Optimizes GRC tooling to automate compliance processes and continuous control monitoring, streamlining evidence collection while tracking emerging regulations to proactively adapt the certification roadmap.

- Delivers executive-level compliance metrics and risk dashboards that track certification roadmap progress, audit statuses, and open findings, providing leadership with the actionable visibility needed to support strategic decision-making.

### Qualifications

- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Risk Management, or equivalent professional experience.

- At least 5+ years of experience in cybersecurity compliance, GRC, IT audit, or certification management.

- Demonstrated hands-on experience managing initial certification, scope expansion, and annual/surveillance audits, such as ISO 27001, SOC2, NIST CSF, or similar.

- Proven experience building and maintaining audit readiness programs, including continuous evidence management processes.

- Proficiency with GRC platforms/tools for evidence, control management, and continuous monitoring (e.g., Archer GRC, ServiceNow GRC, OneTrust).

- Exceptional verbal and written communication skills to effectively translate technical issues to non-technical audiences.

- Experience directly interfacing with external auditors/certification bodies and managing audit logistics.

- Strong program management skills with the ability to balance multiple concurrent audit timelines.

### Preferred Qualifications

- Active industry credential certification such as ISO 27001 lead auditor/implementer, CISA, CRISC CISSP, or CISM.

- Experience operating within a three-line-of-defense(3LOD) risk governance model, particularly within a second-line GRC/risk oversight function.

- Prior experience managing certification scope expansion (e.g., adding new sites, business units, or product lines to an existing certification with business/IT alignment).

- Familiarity with continuous control monitoring (CCM) approaches and GRC tool compliance features.

- Experience managing relationships with multiple certification bodies/external audit firms simultaneously.

- Background in leading mock audits or internal audit programs.

### Benefits

- Immediate medical, dental, vision and prescription drug coverage.

- Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more.

- Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more.

- Vehicle discount program for employees and family members and management leases.

- Tuition assistance.

- Established and active employee resource groups.

- Paid time off for individual and team community service.

- A generous schedule of paid holidays, including the week between Christmas and New Year’s Day.

- Paid time off and the option to purchase additional vacation time.

## Skills

### Required
- GRC
- Cybersecurity
- Compliance
- Risk Management
- Audit Readiness
- GRC Tooling
- Communication

### Nice to have
- ISO 27001
- CISA
- CRISC
- CISSP
- CISM
- Continuous Control Monitoring
- GRC Tool Compliance

---

Source: [Apply at efds.fa.em5.oraclecloud.com](https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/67310?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
