Jobs and Careers
ST

Director, Cybersecurity - Governance, Risk and Compliance (GRC)

Stanley Black & Decker
New Britain, United Statesfull_timeVerifiedPosted 25 Apr 2024

About the role

Make A Difference For Those Who Make The World™

It takes great people to achieve greatness. People with a sense of purpose and integrity. People with a relentless pursuit of excellence. People who care about making things better For Those Who Make The World™. Sound like you? Join our top-notch team of nearly 60,000 professionals globally who are making their mark on some of the world’s most beloved brands, including DEWALT®, CRAFTSMAN®, CUB CADET®, STANLEY® and BLACK+DECKER®

What You’ll Do

As Director, Governance, Risk & Compliance (GRC) you’ll be part of our Cybersecurity Office located virtually. Reporting directly to the CISO, this role will help mature the cybersecurity governance, risk, audit and compliance program at SBD. This person will work with business and IT partners across the enterprise to ensure strong executive sponsorship and engagement from the right team of stakeholders and subject matter experts. This role is an integral lead for the GRC program and will assist in overseeing all aspects of the program.

 You’ll get to:  

  • Mature the cybersecurity Governance, Risk, Audit and Compliance program
  • Be responsible for every aspect of GRC across the enterprise
  • Author and update policies, standards, and procedures that are related to security risk management
  • Create and maintain a 3-year strategic roadmap to continue to mature the Risk Management program
  • Conduct an annual Risk Management maturity assessment
  • Partner and maintain strong relationships with the business stakeholders including Legal, Supply Chain, IT business analysts, architecture teams, operational teams, and technical leadership
  • Manage and oversee the vendor risk management processes
  • Manage and ensure security assessments are conducted to reduce risk for various projects within the organization
  • Create comprehensive GRC reports for the executive leadership and board of directors that provide clear insights into the company's risk profile, compliance status, and governance effectiveness.
  • Manage the review of issues and policy exceptions to ensure risk is being managed appropriately
  • Manage compliance regulations and audit requirements
  • Develop a robust change management strategy including training and communication plans to properly onboard the end user community
  • Identify threats and business activities that introduce risk to the company
  • Conduct quantitative and qualitative risk assessments
  • Produce reports and metrics that support the analysis from the risk assessment and be able to articulate the findings to both technical and non-technical audiences and collaborate with risk owners on risk treatment strategies
  • Business Resiliency| BC/DR

Who You Are

You always strive to do a good job…but wouldn’t it be great if you could do your job and do a world of good? You care about quality – at every level. You love to learn and grow and be acknowledged for your valuable contributions. You’re not intimidated by innovation. In fact, you embrace it.

You also have: 

  • BS degree in Business, Information Security, Management Information Systems or related major
  • Cybersecurity degree and/or certifications strongly preferred
  • 7-10 years of cybersecurity experience
  • Strong Cyber Risk Management experience
  • Experience with FAIR methodology
  • Strong technical and business acumen
  • Strong knowledge of frameworks such as ISO 27001, NIST Cyber Security Framework, Center for Internet Security
  • Certified in Factor Analysis of Information Risk (FAIR) and Certified in Risk and Information Systems Control (CRISC) desired, but not required
  • Experience in coordinating work across multiple functions and be adept at building consensus across organizational and functional lines
  • Strong analytical, including data mining, analysis, trending, problem solving and project management skills
  • Manufacturing and OT cybersecurity experience a plus
  • Strong written, verbal communication and interpersonal skills
  • Ability to communicate constantly | effectively throughout highly-matrixed organization
  • Must possess a high degree of integrity and trust along with the ability to work independently as well as motivate others

What You’ll Receive

You’ll receive a competitive salary and a great benefits plan:

  • Medical, dental, life, vision, wellness program, disability, 401(k), Employee Stock Purchase Plan, paid time off and tuition reimbursement.
  • Discounts on Stanley Black & Decker tools and other partner programs.

How You’ll Feel

We want our company to be a place you’ll want to be – and stay. Being part of our team means you’ll get to:

  • Grow: Be part of our global company with 20+ brands to grow and develop y

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Stanley Black & Decker

View company profile →