Overview
Lead Plexus’s IT GRC function to strengthen regulatory compliance and cyber risk management across a global operation. Shape and implement the GRC framework, policies, and controls in line with standards like ISO 27001 and NIST CSF. Partner with business units to embed risk-aware practices and drive continuous security improvements. This role offers visibility to executive leadership, cross-functional collaboration, and the chance to elevate Plexus’s cybersecurity posture in a dynamic environment.
Pay / Benefits
- Private medical insurance
- Employee Assistance Program
- Vision care
- Enhanced pension contributions
- Life assurance
- 33 days of annual leave
Responsibilities
- Develop, maintain, and socialize cybersecurity policies, standards, and procedures aligned with regulatory requirements
- Oversee IT risk register, lead risk assessments, and monitor control effectiveness
- Coordinate internal and external audits, track remediation, and oversee customer assessments
- Manage Third-Party risk program and third-party risk assessments
- Lead multi-year GRC program roadmap with KPIs and KRIs for executive leadership
- Drive continuous improvement of security controls, including automation where feasible
- Model and coach teams to embody Plexus values and support development
- Uphold cybersecurity posture through policy adherence, incident awareness, and vulnerability management
Key requirements
- Bachelor degree with 8+ years of related experience
- Advanced leadership experience in fast-paced environments
- Strong decision making, problem solving, and prioritization skills
- Excellent verbal and written communication; ability to motivate and collaborate with partners
- Business acumen and ability to articulate value of new processes
- Functional project management knowledge
- Self-motivated; able to work independently and in a team
- Knowledge of security frameworks (NIST CSF, ISO 27001, CIS Controls) and regulatory requirements (SOX, SEC, GDPR, HIPAA, CMMC)
- leadership
- interpersonal skills
- effective communication
- IT GRC and risk management
- cybersecurity controls design and assessment
- IT and cybersecurity audits
…
