×
Register Here to Apply for Jobs or Post Jobs. X

Senior Cybersecurity Risk & Compliance Associate

Job in Alameda, Alameda County, California, 94501, USA
Listing for: BOSTON TRUST WALDEN COMPANY
Full Time position
Listed on 2025-12-09
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Job Description & How to Apply Below

Equal Opportunity Employer

Wind River is an Equal Opportunity Employer with a commitment to diversity. We prohibit discrimination based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.

About the Opportunity

We are hiring a professional to support and help lead the Wind River Risk & Compliance function, with a primary focus on maintaining our ISO 27001 certification and supporting our obligations on NIST 800‑171. The right candidate will support the Wind River Risk and Compliance program, which includes Governance Risk and Compliance (GRC) and Third‑Party Risk Management (TPRM), bring structure to our processes, and help stabilize and scale the function.

Key Responsibilities Regulatory & Standards Support
  • Contribute to all ISO 27001 activities, including internal audit readiness, external recertification, and ongoing control maintenance.
  • Support NIST 800‑171 compliance efforts, including maintenance of System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and gap assessments.
  • Have working knowledge and be able to support GDPR, NIST CSF, CMMC, TISAX, ITAR, and AI related compliance, as well as the ability to gain knowledge on future certification and regulation requirements.
  • Assist in engagement with government compliance stakeholders and maintain awareness of requirements.
Risk & Compliance Operations – Governance Risk and Compliance (GRC) and Third‑Party Risk Management (TPRM)
  • Maintain the Wind River Risk Register and track mitigation progress across all functional areas.
  • Coordinate the Security Exception process, ensuring proper documentation, approvals, and governance.
  • Conduct vendor assessments, reviews, remediation follow‑up, and monitoring.
  • Write and update policy and standards and provide governance, oversight, and assurance.
  • Administer GRC/TPRM tooling (ZenGRC) and ensure evidence management and workflows are maintained and audit‑ready. Have an understanding or ability to use Service Now and Audit Board risk management products.
Audit & Customer Response
  • Prepare audit documentation and assist with responses for internal and external audits.
  • Draft and maintain clear, consistent, and audit‑ready documentation, including policies, control responses, and program updates.
  • Support customer assurance efforts related to ISO, NIST, and general cyber compliance.
  • Lead internal audits and assessments against Wind River.
Program Execution & Scalability
  • Help implement scalable, repeatable governance processes for policy and standard creation and lifecycle management.
  • Assist in developing compliance procedures, checklists, and review frameworks.
  • Support workflows for User Access Reviews (UAR), TPRM, and continuous monitoring.
Collaboration
  • Work cross‑functionally with Aptiv Cybersecurity, IT, Legal, HR, and Engineering, across Aptiv, Hellermann Tyton, Winchester, and Intercable.
  • Support communication and coordination with external auditors and internal stakeholders (including Primary Security Officer, Aptiv Legal, WR and Aptiv leadership).
  • Support Cybersecurity Training at Wind River.
Required Qualifications
  • 5+ years of cybersecurity, compliance, or GRC experience.
  • Familiarity with ISO 27001, NIST 800‑171, and enterprise GRC operations.
  • Strong writing skills, with experience contributing to SSPs and POA&Ms.
  • Working knowledge of ZenGRC or similar tools.
  • Demonstrated ability to work across matrixed teams.
  • Experience with customer audit responses and regulatory compliance.
  • U.S. citizenship required due to regulatory requirements.
  • Must be a local resident (or willing to relocate to) Alameda, CA or Boston, MA and agree to be on site three days per week in the office.
Preferred Qualifications
  • Experience supporting government‑mandated compliance frameworks.
  • Involvement in ISO 27001 recertification efforts or similar standards.
  • Experience with third‑party risk tools (e.g., Blue Voyant, Bit Sight).
  • Familiarity with Wind River or embedded systems companies is a plus.
Why This Role Matters

Wind River's ability to operate in national security and critical infrastructure markets…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary