About this role
<p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">At Ball, integrity and trust are the foundation of who we are. Guided by our core values—"We Care. We Work. We Win.”—we create a culture where every voice matters and every idea drives progress. </span></p> <p> </p> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Together with our global employees, customers, and partners, we’re turning bold sustainability goals into reality and shaping a future we can all be proud of. </span></p> <p> </p> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Create a new future. Apply Today. </span></p><p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><strong>Primary purpose of the position: </strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">The Senior Analyst, Cybersecurity Governance, Risk, and Compliance (GRC) is responsible for defining and supporting the execution and day‑to‑day operation of Ball Corporation’s enterprise cybersecurity governance, risk management, and compliance programs.</span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Reporting to the Director of Cybersecurity Governance, Risk, and Compliance, this role serves as a senior individual contributor who translates governance requirements and risk management expectations into practical, repeatable processes. The Senior Analyst ensures cybersecurity risks are identified, documented, tracked, and reported consistently, and that compliance obligations are supported through evidence, analysis, and coordination with internal stakeholders.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><strong>Essential Responsible Areas: </strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Support execution of the enterprise cybersecurity risk management program, including risk identification, assessment, documentation, and tracking.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Perform cybersecurity risk analyses and prioritizate risk based on business impact, likelihood, and risk tolerance.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Support cybersecurity governance activities, including policy & standard creation, and security control lifecycle management.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Lead cybersecurity compliance activities, including control evidence collection, assessment support, and remediation tracking.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Partner with key stakeholders to lead internal and external cybersecurity audits by preparing documentation, responding to inquiries, developing remediation plans, and tracking findings.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Lead cyber supply‑chain and third‑party risk management activities, including assessments and follow‑up actions.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Contribute to cybersecurity metrics, dashboards, and management reporting.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Document risk decisions, exceptions, and remediation actions to ensure transparency and audit readiness.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Partner with Cyber Defense Operations, Security Architecture & Engineering, IT, and OT Security to ensure risk and compliance requirements are understood and addressed.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Support regional business and technology teams in executing cybersecurity risk and compliance activities aligned to global standards.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Assist with region‑specific regulatory and compliance requirements in coordination with the Director and other stakeholders.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Facilitate communication between regional teams and corporate cybersecurity functions regarding risk assessments, findings, and remediation activities.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Help ensure consistent application of cybersecurity governance processes across regions while supporting approved regional variations.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><strong>Professional & </strong><strong>Education Qualification:</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Bachelor’s degree in Information Security, Computer Science, Risk Management, Business Administration, or a related discipline required.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Minimum of 5–8 years of experience in cybersecurity, technology risk, compliance, or related roles.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Experience supporting risk assessments, audits, or compliance programs in a global or regulated environment preferred.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Relevant cybersecurity or risk certifications preferred.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><strong>Skills:</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Strong analytical skills with the ability to assess and document cybersecurity risks clearly and accurately.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Attention to detail and disciplined approach to documentation and evidence management.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Ability to communicate effectively with technical and non‑technical stakeholders.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Strong organizational and coordination skills across multiple teams and activities.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Ability to manage competing priorities and meet deadlines.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Practical mindset that balances governance rigor with business realities.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><strong>Knowledge:</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Working knowledge of cybersecurity governance, risk, and compliance concepts and frameworks.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Understanding of how cybersecurity risk impacts business operations, manufacturing environments, and supply chains.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Familiarity with audit processes, control assessments, and remediation tracking.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Awareness of data protection and regulatory considerations affecting global organizations.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Understanding of how cybersecurity governance supports resilience, regulatory posture, and executive decision‑making.</span></li> </ul><div> <div> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><strong>Compensation & Benefits: </strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Expected Hiring Salary Range: $110,300 - $157,620 (Salary to be determined by the applicant’s education, experience, knowledge, skills, and abilities, as well as internal equity and alignment with market data.) </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">This role will be eligible to participate in the annual incentive compensation plan. </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Please visit our "Total Rewards" page to learn more about Ball’s comprehensive benefits structure. </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">The preferred location for this role is our Westminster, CO campus; but we will consider a remote candidate, dependent on experience, qualifications and willingness to engage in regular travel to the Colorado campus. Hybrid On-Site Work Environment: If based in Colorado, this position requires regular in-person engagement by working on-site for three (3) or more days per work week (with core collaboration days of Tuesday, Wednesday and Thursday). Travel and local commute between Ball locations and other possible non-Ball locations may be required.</span></li> </ul> <p> </p> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif;color:black">When submitting your application to Ball, we encourage you to emphasize your skills, experience, and qualifications that align with the role. </span></p> <p> </p> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif;color:black">Ball Corporation is proud to be an Equal Opportunity Employer. We actively encourage applications from everybody. All qualified job applicants will receive consideration without regard to race, color, religion, creed, national origin, aboriginality, genetic information, ancestry, marital status, sex, sexual orientation, gender identity or expression, physical or mental disability, pregnancy, veteran status, age, political affiliation or any other non-merit characteristic. </span></p> <p> </p> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif;color:black">Please note the advertised job title might vary from the job title on the contract due to local job title structure and global HR systems. </span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif;color:black">Under Colorado, California, Connecticut, Minnesota, and Pennsylvania law, you have the right to exclude or redact age-related details—such as your date of birth, school attendance dates, or graduation dates—from your resume, cover letter, CV, or other supporting documents (e.g., transcripts, certificates). </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Legal authorization to work in the U.S. We will not sponsor individuals for employment visa, now or in the future, for this job opening. </span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">* This position will be posted internally for a minimum of 5 days and will remain open until filled or adjusted based on the volume of applicants. </span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">No agencies please. </span></p> <p><span style="font-size:8.0pt;color:white">#LI-CK1</span><br><span style="font-size:8.0pt;color:white">#LI-Hybrid</span></p> </div> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif;color:black"> </span></p> </div> <p> </p>