Cyber Manager - Governance, Risk and Compliance

Steelcase

Grand Rapids (MI)

Hybrid

USD 150,000 - 200,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Continual learning opportunities
Competitive wages and benefits

Job summary

Steelcase in Grand Rapids seeks a Senior GRC leader to scale governance, risk, and compliance enterprise-wide. You will lead a growing team, align risk appetite with strategy, and push continuous improvement using automation and AI to surface gaps in real time across frameworks.

You will partner with the CISO, executives, auditors, and business partners to translate risk into clear decisions, shape policies, and build a proactive, evidence-driven program spanning SOX ITGC, NIST CSF, CIS

Qualifications

  • Bachelor's degree or equivalent experience in a related field.
  • Hands-on background in governance, risk, compliance, or security audit in an enterprise environment.
  • Familiarity with major frameworks (NIST CSF, CIS Controls, SOX ITGC, COBIT) and how controls map across frameworks.

Responsibilities

  • Lead and grow the Governance, Risk & Compliance team, setting direction and coaching staff.
  • Own the enterprise cybersecurity risk program and communicate risk to prioritize with confidence.
  • Reimagine compliance as a continuous, evidence-driven capability using automation and AI to gather evidence and surface gaps across frameworks.
  • Run a third-party risk program and apply AI to assess vendor questionnaires and contracts.
  • Write and maintain security policies and standards that are actually read and followed.
  • Serve as primary security partner to Internal Audit, external auditors, Legal, and Privacy; make audit season uneventful.

Skills

Leadership
GRC
Risk management
Communication
CISA
CRISC
CISM
CISSP
CGEIT

Education

Bachelor's degree in related field

Tools

OneTrust
Bitsight

Job description

Company DescriptionJob Description

Who you are:

You believe governance, risk, and compliance should make a company safer and faster, not slower. You have seen GRC done as spreadsheets, checklists, and annual fire drills, and you want to build something better.

You are a builder and a people leader. You enjoy growing a team, designing programs from first principles, and turning evidence collection, control testing, and risk assessment into continuous, largely automated work, with AI increasingly handling the tedious parts so your team can focus on judgment.

You are comfortable in the room with executives, auditors, engineers, and business partners, translating between them and helping leaders make risk decisions with clear information rather than fear.

Helping You Thrive By:
  • Offering competitive wages and benefits, that support your life both in and out of work
  • Providing a flexible hybrid work schedule, meaning we expect the office to be your primary place of work, balanced with choice and control.
  • Creating continuous learning opportunities to help you grow and upskill.
  • Fostering a culture of inclusion where employees feel seen, heard and valued - and living it out every day.
  • Empowering you to make a meaningful impact on people and the planet through your work and Steelcase's ongoing commitment.
You'll Support Meaningful Work By:
  • Leading and growing the Governance, Risk & Compliance team, setting direction, coaching, and creating the conditions for people to do their best work.
  • Owning the enterprise cybersecurity risk program: identifying, quantifying, and communicating risk so the CISO and business leaders can prioritize with confidence.
  • Reimagining compliance as a continuous, evidence-driven capability rather than an annual event, using automation and AI to gather evidence, test controls, and surface gaps in near real time across frameworks such as SOX ITGC, NIST CSF, and the CIS Controls.
  • Running a third-party risk program that scales with the business, applying AI to assess vendor questionnaires, contracts, and external risk signals so your team spends its time on decisions rather than paperwork.
  • Writing and maintaining security policies and standards that people actually read and follow, and retiring the ones that no longer serve a purpose.
  • Serving as the primary security partner to Internal Audit, external auditors, Legal, and Privacy, and making audit season uneventful.
  • Helping shape how Steelcase governs its own use of AI, partnering across the company on responsible AI practices, controls, and risk assessment as new capabilities are adopted.
  • Building metrics and reporting that tell an honest story about our risk posture to the CISO, executive leadership, and the Board.

Qualifications

Minimum Qualifications
  • Three or more years of formal people leadership, managing a governance, risk, and compliance team or an equivalent security, audit, or risk function, with direct responsibility for hiring, coaching, and developing the people on it.
  • Hands‑on background in governance, risk, compliance, or security audit work in an enterprise environment.
  • Working knowledge of at least one major security or compliance framework (for example NIST CSF, the CIS Controls, SOX ITGC, or COBIT) and how controls map across frameworks.
  • Ability to assess risk and communicate it clearly to technical and non‑technical audiences, including senior leaders.
  • A track record of improving processes, not just running them.
  • Bachelor's degree in a related field, or equivalent experience.
Desired Skills and Experience
  • Certifications such as CISA, CRISC, CISM, CISSP, or CGEIT.
  • Experience with GRC or privacy platforms such as OneTrust, and with security ratings services such as Bitsight.
  • Experience building or maturing a third‑party risk management program.
  • Hands‑on experience using AI tools or automation to streamline evidence collection, control testing, or risk analysis, or a strong appetite to learn.
  • Familiarity with emerging AI governance frameworks such as the NIST AI RMF or the EU AI Act.
  • Experience in a global manufacturing or multi‑entity organization.

Qualified applicants must be authorized to work in the United States on a full‑time basis. Steelcase will not provide support for or sponsor work authorization and/or visas for this role.

#mid_senior_level

#LI-Onsite

#Information_Technology

#Management

#Consulting

#LI-EW1

At Steelcase, we put people at the center of everything we do. We understand the role of work and believe that it can bring meaning and purpose to the lives of our customers and our employees. We prioritize supporting our employees both in and out of work, in all aspects of their lives. When we bring our talents together, we make a positive lasting impact through our work and communities.

Steelcase provides employment opportunities to all qualified employees and applicants without regard to race, color, creed, genetic information, religion, national origin, gender, sexual orientation, gender identity and expression, age, disability, or veteran status and bases all employment decisions only on valid job requirements. If we can make the application process easier through accommodation, please email us at myhr@steelcase.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Global Security Governance, Risk & Compliance Manager (Remote)
Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Aerospace • United States

Remote
USD 140,000 - 190,000
Senior Identity Management Engineer
Senior Identity Management Engineer

Steelcase • Grand Rapids (MI)

Hybrid
USD 100,000 - 135,000
Hybrid work schedule
Competitive wages and benefits
Continuous learning opportunities
+1
Senior Identity Management Engineer
Senior Identity Management Engineer

Purchaseyourfreedom • Grand Rapids (MI)

On-site
USD 100,000 - 135,000
Vulnerability Management Engineer
Vulnerability Management Engineer

Purchaseyourfreedom • Grand Rapids (MI)

Hybrid
USD 110,000 - 160,000
Competitive wages & benefits
Flexible hybrid work schedule
Continuous learning opportunities
+2
Manager, Governance, Risk and Compliance
Manager, Governance, Risk and Compliance

Path Robotics • Columbus (OH)

On-site
USD 100,000 - 130,000
Daily free lunch
Flexible PTO
Comprehensive medical, dental, and vision coverage
+3
Senior Information Security Engineer
Senior Information Security Engineer

SmartRecruiters Inc • Town of Poland (NY)

Hybrid
USD 110,000 - 150,000
Competitive salaries
Remote-friendly culture
Strong internal mobility
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Sr Manager - IT Governance, Risk and Compliance
Sr Manager - IT Governance, Risk and Compliance

Plexus Corp • Neenah (WI)

On-site
USD 130,000 - 194,000
Medical insurance
Dental insurance
Vision insurance
+3
Director, IT Governance, Risk & Compliance
Director, IT Governance, Risk & Compliance

Commercial Metals Company • Irving (TX), Northern (KY)

Hybrid
USD 180,000 - 240,000
Day 1 benefits coverage
401(k) company match
Life and disability insurance
+2
Vulnerability Management Engineer
Vulnerability Management Engineer

Steelcase • Grand Rapids (MI)

Hybrid
USD 110,000 - 150,000
Hybrid work schedule
Continuing education and learning
Inclusive culture
+1