Information Security Governance, Risk, and Compliance (GRC) Manager
CTS CorporationAbout the role
CTS is a $550 million corporation that employs 3,500+ dedicated people. CTS designs and manufactures electronic components, actuators, and sensors to OEMs in the automotive, communications, medical, defense and aerospace, industrial, and computer markets. The company manufactures products in North America, Europe, and Asia. Founded in 1896 as Chicago Telephone Supply, CTS is headquartered in Lisle, IL.
Job/Position Summary
The Information Security Governance, Risk, and Compliance (GRC) Manager in CTS plays a crucial role in developing and maintaining CTS’s information security framework and Cybersecurity posture. The GRC Manager assesses and prioritizes information security and cybersecurity risk across the organization, facilitates compliance with regulatory requirements and information security policies, and develops and reports on information security metrics.
This position is based at our corporate headquarters in Lisle, IL. It requires occasional travel to other company sites.
Major Areas of Responsibility
- Cyber Risk Assessments: Conducting thorough assessments to identify and evaluate potential cybersecurity risks.
- Policy Development: Creating and enforcing cybersecurity policies and standards to ensure compliance with industry regulations and best practices.
- Risk Mitigation: Implementing strategies to mitigate identified risks and protect the organization’s assets.
- Compliance Management: Ensuring the organization adheres to relevant security standards and regulations such as NIST, ISO 27001, CMMC/DFARS and GDPR.
- Audit and Compliance Activities: Managing internal and external audits, participate in customer audits, tracking remediation efforts, and ensuring continuous compliance.
- Vendor Risk Management: Conducting due diligence and risk assessments for third-party vendors to ensure they meet the organization’s security requirements.
- User Awareness Training: Overseeing and developing training programs to educate employees on cybersecurity best practices and compliance requirements.
- Collaboration: Working closely with internal teams, including legal, IT, and data privacy, to align cybersecurity efforts with organizational goals.
- This role requires a strong understanding of cybersecurity frameworks, excellent communication skills, and the ability to manage multiple projects simultaneously. Certifications like CGRC (Certified in Governance, Risk, and Compliance) can be beneficial.
Required Knowledge, Skills and Abilities
- Strong understanding of cybersecurity frameworks and standards (e.g., NIST CSF, ISO 27001, TiSAX).
- Experience in creating, managing, and maturing an Information Security Management System
- Information Security Auditing and Compliance Experience
- Proficiency in risk assessment and management tools.
- Excellent analytical and problem-solving skills.
- Strong communication and interpersonal skills to effectively interact with stakeholders at all levels.
- Ability to manage multiple projects and prioritize tasks efficiently.
- In-depth knowledge of data privacy laws and regulations such as GDPR, CCPA, and others.
Required Education and Experience
- Bachelor's degree in computer science, information technology, Cybersecurity or a related field or equivalent experience.
- At least 5-7 years of experience in cybersecurity, risk management, or compliance roles.
- Experience in managing GRC programs and leading teams is highly valued.
- Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), and Cert
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s