Now hiring

Cybersecurity GRC Manager (Pittsburgh, PA, US, 15222) @ Excelitas Technologies Corp.

Pittsburgh, PA, US, 15222OnsiteFull-timePosted 20 days ago

Opens on the employer's site

About this role

<p style="margin:0.0in 0.0in 11.25pt;background-color:white;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;color:black;background-color:white;font-size:12.0pt">Excelitas is a global technology leader with more than 7,500 employees, focused on delivering market-driven solutions to fulfill the illumination, optical, detection and imaging needs of OEMs and end-users across the biomedical, semiconductor, industrial, consumer products, scientific, security, defense and aerospace sectors.</span></p> <p style="margin:0.0in 0.0in 11.25pt;background-color:white;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="color:black;background-color:white">ENGAGE with us today and make your contribution to the future! Join the team that leading technology companies turn to for cutting-edge photonic innovation. </span><span style="color:black">At Excelitas Technologies you are how we EXCEL.</span></span></p> <p style="margin:0.0in 0.0in 8.25pt;text-align:justify;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="color:black;background-color:white">We are presently seeking a <strong>Cybersecurity GRC Manager</strong> who will work out of our corporate headquarters in Pittsburgh, PA. </span><span style="color:black;background-color:white">and is committed to ensuring overall business success and corporate governance. In addition to a vast portfolio of high-performance photonic products and technologies, Excelitas offers single source convenience and reliability for integrated end-to-end photonic solutions… from light source to sensor, and everything in between. We excel at delivering innovative and customized components, sub-assemblies and fully integrated photonic systems to meet the unique illumination, optronic, sensing and optical technology needs of global OEM customers. </span></span></p> <p style="margin:0.0in 0.0in 8.25pt;text-align:justify;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in 0.0in 6.0pt;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><a name="Annexe"></a>Main responsibilities: </span></p> <p style="margin:0.0in 0.0in 6.0pt;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>Governance &amp; Policy Development</strong></span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Develop, maintain, and govern information security policies, standards, and procedures, ensuring alignment with regulatory, contractual, and customer requirements; </span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Ensure policies and related documentation are clear, practical, enforceable, and reviewed on a defined, documented cadence; </span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Translate external regulatory, contractual, and customer security requirements into internal control expectations and actionable guidance; </span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Monitor changes in regulatory requirements and industry frameworks, assessing organizational impact and driving updates to policies and controls as needed; </span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Manage the policy exception and waiver process, ensuring risk assessment, appropriate approval, time-bound tracking, and resolution;</span></li> </ul> <p style="margin:0.0in 0.0in 10.0pt 0.25in;line-height:115%;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>Compliance &amp; Regulatory Assurance</strong></span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Support and manage compliance with CMMC Level 2, SOX, and other regulatory or customer-driven security requirements; </span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Develop and maintain CMMC program documentation, including system boundaries, data flows, interconnections, and control implementations; </span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Maintain the organization’s SPRS score in coordination with Cybersecurity, Infrastructure, and control owners, ensuring alignment with the current security assessment posture; </span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Support SOX IT General Controls (ITGCs), including access reviews, change management, and IT operations controls; </span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Manage remediation activities across audit findings, control gaps, and POA&amp;Ms, ensuring clear ownership, validated closure evidence, and timely resolution; </span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Serve as the primary point of contact for internal and external audits, coordinating walkthroughs, evidence collection, control testing, and ensuring timely, high-quality responses;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 10.0pt 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif"> </span></li> </ul> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>IT Security Risk Management</strong></span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Conduct IT security risk assessments, documenting risks, impacts, likelihood, and mitigation plans;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Maintain the enterprise IT security risk register and track risks through remediation or formal risk acceptance;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Provide risk-based guidance to stakeholders on control design, security architecture decisions, and risk acceptance;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Develop and maintain GRC dashboards, metrics, and reporting to provide visibility into risk posture, control effectiveness, and program health;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Prepare and deliver risk briefings and GRC program updates to senior leadership, ensuring informed decision-making and documented risk acceptance; </span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Support and mature the Third-Party Risk Management (TPRM) program, including risk assessments and ongoing monitoring;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Support the development and delivery of security awareness and compliance training programs aligned with organizational and regulatory requirements; </span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 10.0pt 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Identify opportunities for process improvement and automation within GRC workflows, including evaluation and implementation of GRC tooling;</span></li> </ul> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>GRC Team Management</strong></span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Manage day-to-day activities of GRC analysts;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Conduct performance reviews and annual goal setting;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 10.0pt 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Drive team development, capability building, and professional growth;</span></li> </ul> <p style="text-align:justify;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>Requirements:</strong></span></p> <p style="text-align:justify;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">· 5+ years of progressive experience in IT Security Governance, Risk &amp; Compliance (GRC) or related disciplines; </span></p> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">· Strong working knowledge of CMMC and NIST SP 800-171 requirements, SOX IT General Controls (ITGCs), Third-Party Risk Management (TPRM), and IT security risk management frameworks; </span></p> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">· Demonstrated ability to develop and maintain security policies, procedures, and standards that are clear, enforceable, and audit-ready; </span></p> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">· Hands-on experience supporting internal and external audits, including evidence preparation, walkthrough facilitation, and remediation of findings; </span></p> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">· Strong analytical, organizational, documentation, and communication skills; </span></p> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">· Proven ability to manage multiple concurrent workstreams and drive activities to timely completion with minimal supervision; </span></p> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">· U.S. Person status as defined under ITAR (22 CFR §120.62), required due to access to export-controlled information and Controlled Unclassified Information (CUI);</span></p> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>Preferred Qualifications:</strong></span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Experience in regulated environments such as a public company, defense, aerospace, manufacturing, or other highly regulated industries;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Familiarity with frameworks such as NIST SP 800-171, NIST SP 800-53, ISO/IEC 27001/27002, NIST CSF, COSO, COBIT;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Experience with GRC tools (e.g., AuditBoard/Optro, Archer, ZenGRC, or similar);</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Working knowledge of safeguarding CUI and export control<strong> </strong>requirements (ITAR, EAR, DFARS 252.204-7012);</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Experience with cloud security compliance in Microsoft 365 / Azure environments, including GCC-High;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Experience developing or maintaining System Security Plans (SSPs) and POA&amp;Ms;</span></li> <li style="line-height:15.0pt;margin:0.0in 0.0in 0.0in 0.0px;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Professional certifications such as CISA, CISM, CRISC, CISSP, RP, CCP.</span></li> </ul> <p style="line-height:15.0pt;margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>Please Note:</strong></span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;line-height:115%;font-family:arial, helvetica, sans-serif;color:#222222">This position requires the use of information which is subject to the International Traffic in Arms Regulations (ITAR)</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;line-height:115%;font-family:arial, helvetica, sans-serif;color:#222222">No relocation offered for this position</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;line-height:115%;font-family:arial, helvetica, sans-serif;color:#222222">Must be a US Persons/No sponsorship offered for this position</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;line-height:115%;font-family:arial, helvetica, sans-serif;color:#1c1e29">Equal Opportunity/Affirmative Action Employer</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:12.0pt;line-height:115%;font-family:arial, helvetica, sans-serif;color:#1c1e29">Equal opportunity employer; Minorities/Females/Disability/Gender Identity/Sexual Orientation</span></li> <li style="margin:0.0in 0.0in 10.0pt 0.0px;line-height:115%;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;line-height:115%;font-family:arial, helvetica, sans-serif;color:black;background-color:white">Excelitas is seeking leaders and innovators to join our global team! Visit: www.excelitas.com/join-our-team </span></li> </ul> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><span style="font-family:'Arial Narrow', sans-serif;color:#e7e6e6;background-color:white">#LI-AM1</span></p> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:10.0pt;font-family:'Times New Roman', serif"><strong><span style="font-family:'Arial Narrow', sans-serif"> </span></strong></p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

Get the extension →
See how your CV scores
Cybersecurity GRC Manager (Pittsburgh, PA, US, 15222) at Excelitas Technologies Corp. | ResuMinder Jobs