Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for the organization’s information security program aligned to the National Institute of Standards and Technology (NIST), the Center for Internet Security (CIS), and the International Organization for Standardization (ISO) 27000 family of frameworks. Drive policy, risk assessments, third party risk, audit readiness, and continuous compliance with regulatory and industry standards, using an organized and project managed approach.
REQUIRED QUALIFICATIONS:
- Bachelor's degree
- 10+ years experience in information security, including GRC, or risk/compliance roles.
- Demonstrated experience with NIST frameworks (NIST CSF, NIST SP 800-53, NIST RMF, NIST SP 800-171), CIS 8.1, and ISO 27001.
- Hands-on experience conducting risk assessments, control assessments, and audit responses.
- Experience with regulatory requirements relevant to the organization (e.g., CMMC, TISAX, CTPAT, GDPR, IATF).
- Strong communication skills; experience producing executive-level reporting.
- Experience with GRC tooling (e.g., Archer, ServiceNow GRC, OneTrust, RSA) and security monitoring platforms.
PREFERRED QUALIFICATIONS:
- Master’s degree or relevant advanced certification.
- Certifications: CISSP, CISM, CRISC, CGEIT, or equivalent.
- Experience with cloud security (AWS/Azure/GCP) controls and cloud compliance frameworks.
Kyocera-AVX is an Equal Opportunity Employer: All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or status as a protected veteran.