Sr. Manager, Risk and Compliance
Leggett & PlattAbout the role
We, at Leggett & Platt Inc., are searching for an experienced Sr. Manager, Risk and Compliance within our Corporate IT team to help support our business. As a global-diversified manufacturing company, it’s sometimes hard to explain all the different things we do. We like to say, “we’re the biggest company no one has ever heard of.” We are confident you interact with one of our products in your daily life without knowing it. Whether it’s the mattress you sleep on, the car you drive, the plane you fly on, or the furniture you sit on, our high-quality components are there supporting you. If you join our team, your work will ensure people across the world have a little more comfort in their lives.
As a Sr. Manager, Risk and Compliance, you will have the opportunity to stay current on security assessments and risk management as Leggett continually strives to match the right security approaches while meeting business goals, objectives, and regulatory requirements. Your contributions will have a direct impact on the business by enriching customer confidence while protecting information security at Leggett. The team you will lead is engaging, innovative, and encouraging with a common goal of making continuous improvements to compliance while enhancing and supporting business needs.
So, what will you be doing as a Sr. Manager, Risk and Compliance?
Risk Management:
- Develop, grow, and manage risk management program, by institutionalizing policies and procedures that assess, identify, quantify, and track risk
- Manage a global enterprise information security risk registry
- Work with key stakeholders, leadership, business units, and other internal and external constituents to evaluate and manage information security risks.
- Drive an enterprise information security risk management and operational maturity program using industry recognized standards such as NIST, CMMC, ITIL, ISO, etc.
- Manage program to conduct information security assessments of third-party vendors, solutions, partners value added resellers, supply chain providers, and other external entities to track and manage risks associated to the vendors
- Demonstrated ability to qualify & quantify information security risks and provide recommendations and methodology for managing, prioritizing risks, and guiding mitigation efforts
- Manage efforts to perform targeted risk and control assessments of new and existing service providers
Compliance:
- Ensure the company complies with relevant cyber laws, regulations, and industry standards
- Manage Sarbanes Oxley Act compliance (for public company) ensuring IT general controls adherence and compliance
- Monitor changes in regulations
- Lead efforts to coordinate and complete information security assessments, to include third party vendors, which may include identifying, compiling, and analyzing assessment inputs and/or the execution and documentation of the risk or controls assessment in accordance with the defined approach
- Drive the creation and operation of IT general controls, program processes, procedures, and workflows
- Lead gaps analysis against regulatory expectations or industry standards.
- Track compliance processes such as remediation plans, exception/variance handling, audit requests, and recurring audit reviews to ensure timely completion
Reporting:
- Generate reports, presentations, documents, and other collateral to present assessment updates to senior leadership <
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s