Senior Cybersecurity Risk & Compliance Associate

Remote Full-time
About the position We are hiring a professional to support and help lead the Wind River Risk & Compliance function, with a primary focus on maintaining our ISO 27001 certification and supporting our obligations on NIST 800-171. The right candidate will support the Wind River Risk and Compliance program, which includes Governance Risk and Compliance (GRC), and Third Party Risk Management (TPRM), bring structure to our processes, and help stabilize and scale the function. Responsibilities • Regulatory & Standards Support: Contribute to all ISO 27001 activities, including internal audit readiness, external recertification, and ongoing control maintenance. Support NIST 800-171 compliance efforts, including maintenance of System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and gap assessments. Have working knowledge and able support GDPR, NIST CSF, CMMC, TISAX, ITAR, and AI related compliance as well as the ability to gain knowledge on future certification and regulation requirements. Assist in engagement with government compliance stakeholders and maintain awareness of requirements. • Risk & Compliance Operations Governance Risk and Compliance (GRC) and Third-Party Risk Management (TPRM): Maintain the Wind River Risk Register and track mitigation progress across all functional areas. Coordinate the Security Exception process, ensuring proper documentation, approvals, and governance. Including vendor assessments, reviews, remediation follow-up, and monitoring. Write and update policy and standards and provide governance, oversight, and assurance. Administer GRC/TPRM tooling (ZenGRC) and ensure evidence management and workflows are maintained and audit-ready. Have an understanding or ability to use ServiceNow and AuditBoard risk management products. • Audit & Customer Response: Prepare audit documentation and assist with responses for internal and external audits. Draft and maintain clear, consistent, and audit-ready documentation, including policies, control responses, and program updates. Support customer assurance efforts related to ISO, NIST, and general cyber compliance. Lead internal audits and assessments against Wind River. • Program Execution & Scalability: Help implement scalable, repeatable governance processes for policy and standard creation and lifecycle management. Assist in developing compliance procedures, checklists, and review frameworks. Support workflows for User Access Reviews (UAR), TPRM, and continuous monitoring. • Collaboration: Work cross-functionally with Aptiv Cybersecurity, IT, Legal, HR, and Engineering, across Aptiv, HellermannTyton, Winchester, and Intercable. Support communication and coordination with external auditors and internal stakeholders (including Primary Security Officer, Aptiv Legal, WR and Aptiv leadership). Support Cybersecurity Training at Wind River. Requirements • 5+ years of cybersecurity, compliance, or GRC experience • Familiarity with ISO 27001, NIST 800-171, and enterprise GRC operations • Strong writing skills, with experience contributing to SSPs and POA&Ms • Working knowledge of ZenGRC or similar tools • Demonstrated ability to work across matrixed teams • Experience with customer audit responses and regulatory compliance • U.S. citizenship required due to regulatory requirements • Must be a local resident (or willing to relocate to) Alameda, CA or Boston, MA and agree to being on site three days per week in the office. Nice-to-haves • Experience supporting government-mandated compliance frameworks • Involvement in ISO 27001 recertification efforts or similar standards • Experience with third-party risk tools (e.g., BlueVoyant, BitSight) • Familiarity with Wind River or embedded systems companies is a plus Benefits • Hybrid work model for workplace flexibility • Comprehensive health, dental, and life insurance • Short and long-term disability coverage • RRSP matching for financial security • Flexible time-off policies for work-life balance • Employee assistance program for mental well-being • Learning benefits, including a LinkedIn Learning subscription and seminars Apply tot his job
Apply Now

Similar Opportunities

Security & Compliance Operations Support Specialist

Remote Full-time

Director, Cybersecurity - Remote or Hybrid in DC, NC and MN

Remote Full-time

Associate Director, Cybersecurity

Remote Full-time

[Remote] Client Director – Strategic Accounts (Enterprise / Fortune 1000)

Remote Full-time

Cybersecurity Operations Director (Remote)

Remote Full-time

Cybersecurity Consultant

Remote Full-time

Director of IT, Cybersecurity, Application Support, and FinOps

Remote Full-time

Experienced Information Security Risk and Compliance Specialist – Cybersecurity, Risk Management, and Compliance Expertise

Remote Full-time

PCI Compliance Specialist, French

Remote Full-time

Security & Compliance Engineer; Remote

Remote Full-time

Remote Customer Service Representative - blithequark - Delivering Exceptional Travel Experiences from the Comfort of Your Home

Remote Full-time

Remote Hospice Triage RN- PT 3:30p-12a rotating Sat & Sun 3:30p-12a

Remote Full-time

Experienced Part-Time Customer Service Representative – Delivering Exceptional Service and Support to Diverse Customer Base at blithequark

Remote Full-time

**Director, Partner & Customer Service (Remote) - Lead the Way in Delivering Exceptional Experiences**

Remote Full-time

Small Group Sales Assistant

Remote Full-time

**Experienced Remote Data Entry Clerk - Flexible Part-Time Opportunity with arenaflex**

Remote Full-time

Corporate Vice President - Strategic Business Production Support and Operations Lead

Remote Full-time

Experienced Customer Services and Member Experience Specialist – Delivering Exceptional Support and Sales in a Dynamic Fitness Environment at blithequark

Remote Full-time

**Experienced Part-Time Work From Home Amazon Customer Service Online Chat Representative – Delivering Exceptional Service with Flexibility and Growth Opportunities at blithequark**

Remote Full-time

QA Automation Engineer (Rules Testing) #1687477

Remote Full-time
← Back to Home