# Cybersecurity Compliance Analyst

**Company**: Ford Motor Company
**Location**: Michigan, MI
**Work arrangement**: remote
**Experience**: mid
**Job type**: full-time
**Salary**: $86,600-$166,200
**Category**: IT
**Industry**: Automotive
**Wikidata**: https://www.wikidata.org/wiki/Q44294

**Apply**: https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/67315?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_537e63db-f98

## Description

This is a hands-on execution role, ideal for someone building foundational GRC expertise while contributing to certification lifecycle management, evidence collection, control monitoring, and regulatory reporting support.

Responsibilities:

- Support the Service Manager in maintaining relationships with OGC, the application teams and other across the shared services teams, by preparing documentation, tracking action items, and coordinating meeting logistics.

- Assist in the collection, organization, and validation of evidence artifacts, metrics, and control documentation required for the Global IT risk management framework.

- Help monitor information security controls on an ongoing basis and flag deviations, gaps, or emerging risks to the Service Manager for escalation to the global GRC team.

- Coordinate the annual risk assessment process for selected applications by gathering data, coordinating stakeholder input, and drafting supporting documentation.

- Contribute to the preparation of annual reports and governance materials, including drafting content and compiling data for C-level presentations.

- Assist in disseminating GRC training materials and coordinating regional awareness sessions, including scheduling, content adaptation, and tracking participation.

- Maintain and update trackers/logs of newly identified IT risks and compliance gaps, ensuring accurate documentation before escalation to the global GRC team.

- Support certification lifecycle activities (e.g., audit scheduling, evidence readiness checks, tracking remediation actions) for relevant frameworks.

- Conduct research on regional regulatory requirements and summarize findings to support the Service Manager's representation of regional needs within the global team.

Qualifications:

- Foundational knowledge of information security risk management, governance, and compliance principles and practices.

- Basic understanding of information systems auditing, control monitoring, and risk assessment concepts.

- Strong research and data-gathering skills, with the ability to synthesize information from internal and external sources.

- Ability to define problems, collect and analyze data, and draw clear, well-supported conclusions.

- Clear written and verbal communication skills, with the ability to translate technical information for varied audiences.

- Strong organizational skills and attention to detail, particularly with sensitive or confidential information.

- Ability to learn quickly, adapt to new tools/frameworks, and work effectively in a fast-paced, evolving environment.

- Good collaboration and stakeholder support skills; customer-service mindset.

- Eagerness to build functional GRC expertise and grow into more senior compliance/certification roles.

Benefits:

- Immediate medical, dental, vision and prescription drug coverage

- Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more

- Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more

- Vehicle discount program for employees and family members and management leases

- Tuition assistance

- Established and active employee resource groups

- Paid time off for individual and team community service

- A generous schedule of paid holidays, including the week between Christmas and New Year's Day

- Paid time off and the option to purchase additional vacation time.

## Skills

### Required
- information security risk management
- governance
- compliance principles
- information systems auditing
- control monitoring
- risk assessment
- research
- data-gathering
- written and verbal communication
- organizational skills

### Nice to have
- security frameworks such as NIST or ISO
- audits
- assessments
- compliance projects
- Excel/PowerPoint skills

---

Source: [Apply at efds.fa.em5.oraclecloud.com](https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/67315?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
