Jobs and Careers
CE

IT Cyber Security & Compliance Officer (A&D)

Celestica
Richardson, United Statesfull_timeVerifiedPosted 19 Nov 2023

About the role

Req ID: 118430 
Region: Americas 
Country: United States 
State/Province: Texas 
City:  Richardson 

Summary

This role is primarily responsible for Cybersecurity & Compliance of the A&D sites in Celestica. This role reports into the CISO for Celestica. This selected person will have to work within the Legal function, IT function and the business to ensure that we meet and exceed the compliance requirements from Celestica customers and the U.S. Government. This role will also have to coordinate with external vendors and internal IT teams to ensure that the cybersecurity requirements are met and exceeded. Coordination with customers and government agencies to support assessment and compliance requirements is a must for this role

Knowledge/Skills/Competencies

  • Overall NIST on-going governance and compliance at all of our A&D sites. The Order of precedence is following the company security policies and processes, NIST 800-171 and NIST 800-53 standards.
  • CMMC certification preparation for all the sites/applications in scope
  • Performs on demand and annual validation of Controlled Unclassified Information (CUI) data in scope and related controls;  risk assessment and addresses mitigation steps as needed.
  • Support remote U.S. and European employees supporting A&D and Asia A&D manufacturing facilities 
  • Demonstrates expertise in compartmentalizing US National access requirements from Canadian access requirements as well as additional foreign national access
  • Must be proficient in data sovereignty requirements
  • Responds to customer and government enquiries as to NIST800-171 and DFARS compliance, specifically by completing security questionnaires in conjunction with site IT as appropriate.
  • US DoD incident reporting 
  • Works with all A&D sites to have a CUI/Tech data warning automatically produced on all tech data type documents Celestica produces. 
  • Must have strong knowledge of Access Management, DLP solution, SIEM technology and Auditing and Log monitoring (tools, processes, techniques)
  • Builds up the governance process for DLP, e.g. changes to policies and rules, data in scope.
  • Breach containment and coordination with Site IT and Corporate IT.
  • Ensures and manages governance and maintenance of A&D Architecture landscape (applications, systems, etc) and roadmap.
  • Maintains Celestica NIST 800-171 compliance and updates all IT security and risk policies, procedures, and controls.
  • Establishes and maintains effective relationships with process owners/sites to proactively assess business risks and develop risk mitigation.
  • Develops and enhances the information security management framework based on the NIST 800-171 standard (IT and National Institute of Standards and Technology) and DFARS requirements.
  • Evaluates general and specific training needs; delivers training to support the control environment and associated control framework; communicates governance and compliance objectives, fosters a compliant and risk aware culture.

 

Required knowledge of the U.S. GOVERNMENT COMPLIANCE but not limited to:

  • DFAR 252.204-7012/NIST 800-171. Safeguarding Covered Defense Information and Cyber Incident Reporting.
  • NIST 800-171 and DFARS 252.204-7008, 252.204-7009, and 252.204–7012 clauses to identify any gaps and non-compliance, and provide remediation planning recommendations for Celestica’s corporate information assets pertaining to CUI.
  • CMMC Model Version 2.0 and associated testing requirements
  • 48 CFR 52.204-21 - Basic Safeguarding of Covered Contractor Information Systems
  • Identify CUI and maintain data for gaps and non-compliance -  Physical location, network, authentication, and infrastructure must all be evaluated to ensure that the CUI is accessed only by those authorized to use it.
  • CMMC guidelines and requirements
     

Physical Demands

  • Duties of this position are performed in a normal office environment.
  • Duties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required.
  • Occasional overnight travel is required.
     

Typical Experience

  • 10+ years previous experience in a similar role/industry

Technical Skills:

  • IT Security Best Practices
  • IT Governance and Audit Procedures
  • Knowledge of common information security frameworks and IT controls frameworks, such as ISO/IEC 27001, ITIL, COBIT/COSO and ones from NIST.
  • Knowledge and understanding of relevant legal and regulatory requirements, such as NIST 800-171,

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Celestica

View company profile →