Information Security Program Lead

MSA - The Safety Company

Cranberry Township (Butler County)

On-site

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

MSA Safety is seeking an ISMS Owner to lead and coordinate the Information Security Management System across global operations. You will drive ISO 27001:2022 alignment, manage audits, and guide cross-framework compliance including SOC 2, CMMC, and NIST requirements.

The role requires strong risk assessment experience, policy development, and effective communication with stakeholders worldwide.

Qualifications

  • Deep ISO 27001:2022 knowledge and practical ISMS leadership.
  • Experience leading certification audits and readiness.
  • Ability to map controls across multiple frameworks.
  • Excellent written and verbal communication skills.
  • Experience conducting structured risk assessments and risk treatment.

Responsibilities

  • Own and maintain the ISMS per ISO 27001:2022 requirements.
  • Lead internal and external ISO 27001 audits and follow-up.
  • Conduct gap analyses, risk assessments, and risk treatment planning.
  • Develop, review, and maintain information security policies and procedures.
  • Coordinate SOC 2 Type II readiness and CMMC/NIST activities.
  • Engage with external auditors and regulatory bodies across regions.

Skills

ISO 27001
GRC methodologies
SOC2 readiness
CMMC/NIST 800-171
GDPR knowledge
Cross-framework mapping
Strong communication
Independent work

Education

Bachelor's in CS/InfoSec

Tools

AWS security controls
Office 365 security
SSDLC tooling

Job description

Overview

Are you someone who is passionate, motivated, and driven to make a difference? If so, MSA Safety is the perfect fit for your career.

Overview

Are you someone who is passionate, motivated, and driven to make a difference? If so, MSA Safety is the perfect fit for your career.

At MSA, SAFETY is who we are AND it is what we do. We are a purpose-driven company committed to deploying innovation and technology to deliver on our Mission to help protect people and assets all around the world. We continue to be relentless in our pursuit of solving our customers greatest problems so they can go home safe each and every day.

Are you in? Read on for more details about this particular role.

Responsibilities
ISMS Ownership & ISO 27001
  • Own and maintain the Information Security Management System (ISMS), ensuring alignment with ISO 27001:2022 requirements and organizational objectives
  • Lead and coordinate internal and external ISO 27001:2022 audits, including audit planning, execution, and follow-up
  • Conduct gap analyses, risk assessments, and risk treatment planning in line with ISO 27001 Annex A controls
  • Develop, review, and maintain information security policies, standards, and procedures
Multi-Framework Compliance
  • Drive and coordinate compliance activities across SOC 2 Type II, including control documentation, evidence collection, and readiness reviews in preparation for external assessments
  • Support CMMC 2.0 Level 2 readiness and compliance, including control implementation guidance aligned with NIST SP 800-171 and coordination for third-party assessment organization (C3PAO) engagements
  • Maintain working knowledge of NIST SP 800-171 requirements and their relationship to CMMC, supporting Controlled Unclassified Information (CUI) scoping and handling requirements
  • Ensure compliance activities reflect applicable regional data protection obligations, including GDPR and other jurisdiction-specific requirements relevant to global operations
  • Maintain a cross-framework control mapping to identify overlaps, reduce duplication of effort, and ensure consistent control coverage across ISO 27001, SOC 2, CMMC, and NIST
Global Governance & Stakeholder Engagement
  • Serve as a key point of contact for external certification bodies, auditors, and regulatory inquiries
  • Report on the state of the ISMS, compliance posture, and key risk indicators to senior management across global business units
  • Contribute to security awareness programs and training initiatives, adapting content for regional and cultural relevance where needed
  • Collaborate with cross-functional and geographically distributed stakeholders to embed security and compliance requirements into business processes
Third-Party & Engineering Collaboration
  • Support and collaborate with the Third-Party Risk Management (TPRM) function, providing GRC expertise on vendor risk assessments and due diligence processes
  • Work closely with the software development function to integrate compliance requirements into the Secure Software Development Lifecycle (SSDLC)
Qualifications
Required Skills / Knowledge / Abilities
  • Deep understanding of ISO 27001:2022 and associated standards (e.g., ISO 27002), including practical ISMS management experience
  • Solid grasp of GRC methodologies, control frameworks, and structured risk assessment practices
  • Working knowledge of SOC 2 (Trust Services Criteria) and readiness or audit support experience
  • Working knowledge of CMMC 2.0 and/or NIST SP 800-171, including their application to CUI environments and U.S. federal compliance obligations
  • Familiarity with GDPR or equivalent data protection regulations as they apply to global enterprise operations
  • Experience with cross-framework control mapping across two or more of the above frameworks
  • Excellent written and verbal communication skills — ability to translate complex compliance topics for both technical and non-technical audiences across different cultural and organizational contexts
  • Proven ability to work independently and drive compliance initiatives with minimal supervision in a globally distributed team environment
Preferred Skills
  • Hands-on experience with SOC 2 Type II audit support and evidence collection
  • Direct involvement in CMMC readiness activities or C3PAO-facilitated assessments
  • Knowledge of cloud security controls, particularly in AWS and Office 365 environments
  • Familiarity with AI-enhanced GRC tooling and compliance automation approaches
  • Understanding of TPRM frameworks, vendor risk methodologies, and associated tooling
  • Familiarity with SSDLC principles and their integration with compliance requirements
  • Experience working across multiple time zones and jurisdictions in a multinational organization
Education & Experience
Required
  • Bachelor's degree in Computer Science, Information Security, or a relevant field
  • Demonstrated experience leading or supporting ISO 27001 certification or re-certification audits
  • Experience developing and implementing security policies and controls across multiple frameworks
  • Experience conducting structured risk assessments and managing risk treatment plans in complex, multi-jurisdictional environments
Preferred
  • ISO 27001 Lead Auditor or Lead Implementer certification (e.g., PECB, BSI, or equivalent)
  • Master's degree in Computer Science, Information Security, or a relevant field
  • Additional certifications such as CISM, CISA, CISSP, or ISO 27005 Risk Manager
  • Certifications or formal training in CMMC, NIST, or SOC 2 methodologies
  • Experience working in or supporting regulated industries subject to U.S. government compliance requirements
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Program Lead
Information Security Program Lead

MSA, The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
Information Security Program Lead
Information Security Program Lead

MSA, The Safety Company • Pennsylvania

On-site
USD 120,000 - 155,000
ISMS Compliance Manager
ISMS Compliance Manager

Hexagon Mining, Inc. • Tucson (AZ)

On-site
USD 80,000 - 100,000
ISMS Compliance Manager
ISMS Compliance Manager

Hexagon Mining • Tucson (AZ)

On-site
USD 90,000 - 120,000
Information Security and Compliance Manager
Information Security and Compliance Manager

Transhield, Inc. • Elkhart (IN)

On-site
USD 120,000 - 180,000
ISMS & Compliance Leader - ISO 27001 & SOC 2
ISMS & Compliance Leader - ISO 27001 & SOC 2

MSA, The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Senior Information Security Specialist
Senior Information Security Specialist

Insight Global • Horsham (PA)

On-site
USD 120,000 - 170,000
Cyber Security Compliance Engineer
Cyber Security Compliance Engineer

Leonardo • Philadelphia

On-site
USD 120,000 - 160,000
Global ISMS & Compliance Lead
Global ISMS & Compliance Lead

MSA - The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000