IT GRC Lead
IT GRC Lead
Enerpac Tool Group- Posted 17 hours ago
- Be among the first 10 applicants
Job Description
Overview
About Enerpac Tool Group
Enerpac Tool Group is a premier industrial tools and services company serving a broad and diverse set of customers in more than 25 countries. The Company's businesses are global leaders in high-pressure hydraulic tools, controlled force products and solutions for precise positioning of heavy loads that help customers safely and reliably tackle some of the most challenging jobs around the world. The Company was founded in 1910 and is headquartered in Milwaukee, Wisconsin. Enerpac Tool Group trades on the NYSE under the symbol EPAC.
Our vision is to be our customer's preferred partner through relentless innovation of industrial tools and services that help them safely and reliably tackle their toughest jobs around the world.
For further information on Enerpac Tool Group and its businesses, visit the Company's website at https://www.enerpactoolgroup.com/
What You Will Do
Governance, Policies & Standards
Be an ambassador for the businesses and ensure that Enerpac Tool Group Values always come first:
What We Offer
Our employee benefits including flexible workplace policies, employee resource groups, learning and development resources, career progression pathways, and community engagement initiatives are some of the reasons why we have had great success in bringing in new talent. In addition, our global employee wellness programs are crafted to support the physical, emotional, and financial well-being of our employees.
Never Compromise – choose ETG!
About Enerpac Tool Group
Enerpac Tool Group is a premier industrial tools and services company serving a broad and diverse set of customers in more than 25 countries. The Company's businesses are global leaders in high-pressure hydraulic tools, controlled force products and solutions for precise positioning of heavy loads that help customers safely and reliably tackle some of the most challenging jobs around the world. The Company was founded in 1910 and is headquartered in Milwaukee, Wisconsin. Enerpac Tool Group trades on the NYSE under the symbol EPAC.
Our vision is to be our customer's preferred partner through relentless innovation of industrial tools and services that help them safely and reliably tackle their toughest jobs around the world.
For further information on Enerpac Tool Group and its businesses, visit the Company's website at https://www.enerpactoolgroup.com/
What You Will Do
Governance, Policies & Standards
- Establish and maintain the company's IT and cybersecurity GRC framework.
- Develop, document, maintain, and communicate security policies, standards, procedures, and guidelines.
- Map policies and controls to applicable regulatory, industry, and customer requirements.
- Establish processes for periodic policy review, approval, exception management, and attestation.
- Help define and maintain security control objectives and supporting documentation.
- Coordinate IT and cybersecurity risk assessments across the organization.
- Maintain the enterprise IT and cybersecurity risk register, including risk identification, ownership, mitigation plans, and reporting.
- Track remediation activities and risk acceptance/exceptions through completion.
- Support risk reporting and metrics for IT leadership and other stakeholders.
- Help establish a consistent approach for assessing and prioritizing technology and cybersecurity risks.
- Support the company's compliance obligations and control activities, including but not limited to SOX, CMMC, UK Cyber Essentials, and other applicable regulatory, contractual, customer, and industry requirements.
- Monitor changes in applicable compliance requirements and assess their impact on the organization.
- Coordinate evidence collection, control testing, remediation, and audit requests.
- Support internal and external audits and assessments.
- Develop and maintain compliance/control matrices and documentation.
- Identify gaps and work with control owners to develop remediation plans.
- Support the development and administration of security awareness and training programs.
- Coordinate required cybersecurity training and employee communications.
- Track training completion and follow up on outstanding requirements.
- Help develop security awareness content, campaigns, and communications tailored to different employee audiences.
- Coordinate and execute quarterly phishing simulation activities, to include follow on learning for any failures.
- Establish and manage a third-party cybersecurity risk management process in partnership with Procurement, Legal, IT, and business stakeholders.
- Perform or coordinate security risk assessments of vendors, suppliers, and other third parties.
- Review security questionnaires, SOC reports, certifications, and other third-party security documentation.
- Track identified vendor risks, remediation activities, and risk acceptances.
- Help establish security requirements and ongoing monitoring practices for critical suppliers and service providers.
- Develop GRC metrics, dashboards, and management reports.
- Maintain accurate GRC documentation and records.
- Help identify opportunities to automate and improve GRC processes.
- Support cybersecurity initiatives and other activities as needed within a small, collaborative IT and Cybersecurity team.
- Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or a related field, or equivalent experience.
- 7–10 years of experience in cybersecurity, IT risk, GRC, IT audit, compliance, or a related field, including oversight and responsibilities pertaining to SOX ITGCs.
- Working knowledge of cybersecurity principles, IT controls, risk management, and compliance frameworks.
- Experience developing or managing policies, standards, controls, risk assessments, or compliance programs.
- Strong analytical, organizational, documentation, and communication skills.
- Ability to work effectively with technical and non-technical stakeholders across a global organization.
- Comfortable working independently and building processes in an environment where GRC capabilities are still being established.
- Strong attention to detail and ability to manage multiple priorities and deadlines.
Be an ambassador for the businesses and ensure that Enerpac Tool Group Values always come first:
- SAFETY - Safety is our highest priority and is at the heart of everything we do.
- INTEGRITY - We will act with honesty and transparency and always do the right thing.
- OWNERSHIP - We will own our commitments, act with a sense of urgency, and deliver what
- TEAMWORK - We will act as one Enerpac team, operate with an enterprise-wide mindset, and
- AGILITY - We will act with purpose and speed, and we will adapt quickly to changing
What We Offer
Our employee benefits including flexible workplace policies, employee resource groups, learning and development resources, career progression pathways, and community engagement initiatives are some of the reasons why we have had great success in bringing in new talent. In addition, our global employee wellness programs are crafted to support the physical, emotional, and financial well-being of our employees.
- Benefits & Perks vary by Country. If you are an individual with a disability and you need assistance or a reasonable accommodation during the application process, please reach out to us at: [Confidential Information]
Never Compromise – choose ETG!
More Info
Key Skills
IT audit compliance
Third-party cybersecurity risk management
Security awareness and training programs
Cybersecurity principles
Compliance control matrices and documentation
GRC metrics dashboards and management reports
IT and cybersecurity GRC framework
Security questionnaires
and guidelines
SOC reports
Phishing simulation activities
