Manager, IT Risk & Compliance 2

Celestica

United States

On-site

USD 107,000 - 147,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Celestica is seeking a Manager of IT Risk & Compliance to drive the Governance, Risk, and Compliance (GRC) program. This role involves leading cybersecurity initiatives that support secure business growth while ensuring compliance with frameworks such as NIST and CMMC. Ideal candidates will have over 5 years of experience in IT security and risk management, a strong understanding of regulatory standards, and a Bachelor’s degree in a related field. A salary range of $107,000 - $147,000 USD is offered, along with a comprehensive benefits package.

Qualifications

  • 5–7+ years of experience in IT Security, Risk Management, or Compliance.
  • Strong working knowledge of NIST 800-171, CMMC, ITAR, and GDPR.
  • Ability to manage multiple complex initiatives in regulated environments.

Responsibilities

  • Lead enterprise-wide governance for frameworks and regulations.
  • Drive organizational readiness and execution of CMMC assessments.
  • Oversee internal and external IT audits.
  • Implement and manage the enterprise GRC platform.
  • Define and enforce access control standards.

Skills

IT security frameworks and standards
Regulatory requirements
Risk management
Project and program management
Change management
Analytical and problem-solving
Communication skills

Education

Bachelor’s degree in Computer Science or related field

Tools

Enterprise GRC tools and platforms

Job description

The Manager of IT Risk & Compliance is a strategic leader within the Global IT Security organization, responsible for driving the enterprise Governance, Risk, and Compliance (GRC) program. This role ensures that information systems align with global security strategies, regulatory requirements, and the IT roadmap.

Acting as a key liaison between IT Security and business stakeholders, the Manager leads proactive, data-driven cybersecurity initiatives that strengthen enterprise resilience, reduce risk exposure, and support secure business growth.

Detailed Description

Performs tasks such as, but not limited to, the following:

Regulatory & Compliance Leadership

Lead enterprise-wide governance for frameworks and regulations including NIST 800-171, DFARS, and CMMC, ensuring consistent implementation and ongoing compliance.

CMMC Program Execution

Drive organizational readiness and successful execution of CMMC Level 2 assessments across Aerospace & Defense (A&D) sites.

Audit & Assurance Management

Oversee the full lifecycle of internal and external IT audits, including preparation, stakeholder coordination, and timely remediation of findings.

GRC Program Management

Implement and manage the enterprise GRC platform to centralize compliance tracking, POA&M management, and risk reporting.

Identity & Access Governance

Define and enforce access control standards, including compliance with complex global requirements such as ITAR and EAR.

Security Documentation & Standards

Direct the development and maintenance of System Security Plans (SSPs) and supporting security documentation.

Risk Identification & Mitigation

Partner with site-level IT teams to identify vulnerabilities and embed security controls into business processes.

Lead cross-functional security and compliance initiatives, managing scope, timelines, resources, and executive reporting.

  • Strong understanding of IT security frameworks and standards (e.g., NIST, ISO/IEC 27001, COBIT, ITIL)
  • Expertise in regulatory requirements including CMMC, DFARS, SOX, HIPAA, PCI DSS, and global compliance standards
  • Ability to translate complex security and risk concepts for both technical and non-technical audiences
  • Proven experience in risk management, internal controls, and audit processes
  • Strong project and program management capabilities
  • Advanced analytical and problem‑solving skills
  • Effective communication, collaboration, and stakeholder management skills
  • Experience with enterprise GRC tools and platforms
  • Solid understanding of change management processes
Typical Experience
  • 5–7+ years of experience in IT Security, Risk Management, or Compliance, preferably in manufacturing or defense environments
  • Strong working knowledge of NIST 800-171, CMMC, ITAR, and GDPR
  • Demonstrated ability to manage multiple complex initiatives in regulated environments

Preferred Certifications:

  • CMMC Certified Professional (CCP) (highly preferred)
  • CMMC Certified Assessor (CCA)
  • CISSP, CISA, ISO/IEC 27001 Lead Auditor, or PMP
Typical Education

Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.

The stated range includes Base Salary and target Short-Term Incentive (STI) compensation only. A comprehensive benefits package is offered in addition to this range.

The range described in this posting is an estimate by the Company, and may change based on several factors, including but not limited to a change in the duties covered by the job posting, or the credentials, experience or geographic jurisdiction of the successful candidate.

Salary Range: $107,000 - 147,000 USD

Physical Demands

Duties of this position are performed in a normal office environment.

Duties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required.

Notes

This job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
Employee-owned
Equal opportunity employer
Cybersecurity Audit Analyst
Cybersecurity Audit Analyst

Applied Aerospace • Huntsville (AL)

On-site
USD 70,000 - 90,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • North Stonington (CT)

On-site
USD 90,000 - 110,000
Employee-owned company
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus • Neenah (WI)

On-site
USD 112,000 - 169,000
Cybersecurity Audit Analyst
Cybersecurity Audit Analyst

Elevate Ventures • Huntsville (AL)

On-site
USD 74,000 - 110,000
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus Corp • Neenah (WI)

On-site
USD 112,000 - 169,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
IT Director
IT Director

Continuum Powders • Houston (TX)

On-site
USD 180,000 - 280,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000