Back to Jobs

9959 - Cybersecurity Governance, Risk, Compliance, Training & Resilience Manager

Remote, USA Full-time Posted 2026-04-22
About the position We are hiring a Manager to lead the day-to-day execution of cybersecurity Governance, Risk & Compliance (GRC) and enterprise resilience programs across both Wind River and Aptiv. This dual-entity role will serve as a key operational leader, ensuring regulatory compliance, audit readiness, risk tracking, and documentation integrity across multiple frameworks including ISO 27001, NIST 800-171, SOX, GDPR, FedRamp, CMMC and TISAX. While the Director maintains strategic ownership of all four functional areas (GRC, TPRM, Training, and Resilience), this role will provide hands-on coverage for Wind River's TPRM and Training efforts, working closely with the Aptiv TPRM & Training Manager to ensure continuity and alignment. In addition, this role will own GRC workstreams supporting OneAptiv integration, directly supporting Aptiv, Wind River, and other OneAptiv companies as needed, including TSA execution and M&A onboarding. This position is critical to stabilizing day-to-day operations and enabling long-term scalability across the enterprise. Responsibilities • Lead execution of GRC programs across Aptiv and Wind River, including control maintenance, risk register updates, and audit readiness. • Maintain documentation, controls, and audit-ready evidence for ISO 27001, NIST 800-171, TISAX, SOX, NIS2, CMMC and GDPR across both Aptiv and Wind River, incorporating new regulatory or customer requirements as they arise. • Administer GRC tooling (ZenGRC, AuditBoard, ServiceNow), ensuring accuracy, auditability, and workflow continuity. • Manage internal risk exceptions, maturity roadmaps, and control owners' engagement. • Provide daily operational support to maintain compliance posture and support regulatory assessments. • Own documentation and execution for business impact assessments (BIAs), continuity planning, and tabletop exercises. • Coordinate resilience planning with cross-functional partners including IT, Facilities, Cyber Defense, and Legal. • Maintain continuity playbooks, incident response records, and recovery planning materials. • Provide execution support for Wind River's third-party risk assessments, evidence collection, and remediation tracking. • Execute and drive enforcement of cybersecurity right-to-audit clauses with vendors and partners. • Review and provide redlines on cybersecurity and compliance sections of both buy-side and sell-side contracts. • Collaborate with the Aptiv TPRM Manager to align vendor risk governance across both companies. • Help coordinate Wind River's cybersecurity awareness campaigns, mandatory training compliance, and role-based content support. • Lead evidence preparation and walkthroughs for external audits, customer assessments, and internal audit reviews. • Maintain and update System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and customer documentation requests. • Coordinate audit response activities across control owners, internal SMEs, and external parties. • Support cybersecurity onboarding and governance alignment for newly acquired companies. • Assist with Transitional Services Agreements (TSA) by managing control design, evidence preparation, and GRC tooling integration. • Track risks and compliance issues related to integration timelines, especially where inherited entities lack cybersecurity maturity. • Support Director-led strategic initiatives through dependable execution and documentation follow-through. • Work closely with Architecture, Legal, Product Security, and external vendors to manage dependencies and unblock progress. • Escalate capacity or clarity issues early to avoid unnecessary risk acceptance or execution gaps. Requirements • 7-10+ years of cybersecurity risk, compliance, audit, or GRC program experience. • Experience managing or contributing to ISO 27001, NIST 800-171, SOX, GDPR, or TISAX efforts. • Proficiency with GRC platforms and internal controls execution. • Strong writing and documentation skills. • Must reside in Greater Boston area with ability to be present on site at least 3 days/weekly. • United States Citizenship required. Nice-to-haves • Experience working in a multi-entity environment or during M&A integration. • Familiarity with SBOM, secure SDLC, vendor risk workflows, and cybersecurity awareness campaigns. • CISA, CISSP, CISM, ISO Lead Auditor, or similar certification preferred. • Strong stakeholder management and execution discipline across matrixed teams. Benefits • Hybrid work model for workplace flexibility. • Comprehensive health, dental, and life insurance. • Short and long-term disability coverage. • RRSP matching for financial security. • Flexible time-off policies for work-life balance. • Employee assistance program for mental well-being. • Learning benefits, including a LinkedIn Learning subscription and seminars. Apply tot his job Apply tot his job Apply To this Job

Similar Jobs

**Experienced Data Entry Specialist – Remote Work Opportunity at arenaflex**

Remote, USA Full-time

**Experienced Commercial Enterprise Strategist – Amazon Vendor Management and Growth**

Remote, USA Full-time

Experienced Customer Service Representative – 100% Remote Opportunity for Delivering Exceptional Customer Experiences and Driving Business Growth at arenaflex

Remote, USA Full-time

Experienced Remote Data Entry Specialist – Entry-Level Opportunity for Detail-Oriented Individuals to Join arenaflex and Enhance Data Management Skills

Remote, USA Full-time

Experienced Remote Data Entry Specialist – Accurate Data Management and Organization for a Global Entertainment Leader at arenaflex

Remote, USA Full-time

Experienced Data Engineer and IT Analytics Specialist for Remote Data Entry and Analysis – arenaflex

Remote, USA Full-time

**Experienced Remote Customer Service/Data Entry Representative – Claims Coordination Team Support**

Remote, USA Full-time

Experienced E-commerce Data Entry Specialist – Remote Work Opportunity with arenaflex, Enhancing Product Information Accuracy on a Global Scale

Remote, USA Full-time

Experienced Absence Management Customer Service Representative for Remote Position - Delivering Exceptional Support in a Dynamic Healthcare Environment

Remote, USA Full-time

**Experienced Full Stack Data Entry Specialist – Remote Customer Service & Data Management**

Remote, USA Full-time

Pharmacy Technician - Overnight Shift 7on/7off

Remote, USA Full-time

LPN – IV Certified – Evelyn’s House at Home in Saint Louis, MO in BJC HealthCare (job Id: 1677037102)

Remote, USA Full-time

Overnight Housekeeping

Remote, USA Full-time

Principal/Senior Principal Machine Learning Engineer, Generative AI

Remote, USA Full-time

Senior Backend Engineer, Data Infrastructure

Remote, USA Full-time

United Airlines Work From Home Jobs :: Us $27/Hour

Remote, USA Full-time

Experienced Amazon Product Reviewer and Spokesperson for User-Generated Content (UGC) - Remote Work Opportunity to Create Engaging Product Demonstration Videos

Remote, USA Full-time

Experienced Virtual Customer Service and Sales Representative - Fully Remote Amazon Job Opportunity with Comprehensive Benefits and Professional Growth

Remote, USA Full-time

Customer Engagement Associate

Remote, USA Full-time

UM Nurse Consultant - Remote Full-Time Position with CVS Health - Utilization Management and Healthcare Benefits Coordination

Remote, USA Full-time