×
Register Here to Apply for Jobs or Post Jobs. X

Lead Information Security Engineer - Governance & Risk (GRC)

Job in Los Angeles, Los Angeles County, California, 90079, USA
Listing for: Ferguson Enterprises, Inc.
Full Time position
Listed on 2026-08-05
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 94536 - 165558 USD Yearly USD 94536.00 165558.00 YEAR
Job Description & How to Apply Below
## Lead Information Security Engineer - Governance & Risk (GRC)
Apply locations:
Remote time type:
Full time posted on:
Posted Todayjob requisition :
R-138654
** Job Posting:
** Since 1953, Ferguson has been a source of quality supplies for a variety of industries. Together We Build Better infrastructure, better homes and better businesses. We exist to make our customers’ complex projects simple, successful, and sustainable. We proactively solve problems, adapt and grow to continuously serve our customers, communities and each other. Ferguson, a Fortune 500 company, is proud to provide best-in-class products, service and capabilities across the following industries:
Commercial/Mechanical, Facilities Supply, Fire and Fabrication, HVAC, Industrial, Residential Trade, Residential Building and Remodel, Waterworks and Residential Digital Commerce. Ferguson has approximately 36,000 associates across 1,700 locations. Ferguson is a community of proud associates who operate with the shared purpose of building something meaningful. You will build a career that you are proud of, at a company you can believe in.
** Lead Information Security Engineer - Governance & Risk (GRC)
** The Lead Information Security Engineer - Governance & Risk is an experienced cybersecurity leader responsible for strengthening Ferguson's overall security framework through enterprise risk management, security governance, third-party risk oversight, and security awareness programs. This role serves as a trusted advisor throughout the company. It helps identify, assess, communicate, and reduce cybersecurity risks. It also drives ongoing improvement in security maturity and risk management practices.

This role centers on leading Ferguson's phishing simulation and security awareness initiative. The job includes crafting risk-informed campaigns, analyzing user behavior and program efficiency, and supporting a strong culture of cybersecurity awareness throughout the organization. The role also leads enterprise risk assessments, third-party security reviews, governance initiatives, along with executive reporting which supports informed decision-making and risk-based prioritization.

Partnering closely with peers in Information Security, Technology, Internal Audit, Procurement, Legal, HR, Communications, and business leaders, the Lead Information Security Engineer dedicated to Governance and Risk transforms sophisticated cybersecurity risks into actionable business insights and recommendations. The ideal candidate combines deep expertise in risk and cybersecurity governance along with threat assessment and mitigation, paired with good communication, customer influence, and program leadership skills.

Location:

This role is approved to be fully remote and can be based anywhere in the continental United States.## ## ##
*
* Duties & Responsibilities:

*** Lead cybersecurity risk assessments and security maturity evaluations using industry frameworks, including NIST CSF, identifying control gaps, emerging risks, and opportunities to strengthen Ferguson's security posture.
* Develop risk mitigation strategies, remediation plans, and governance recommendations, partnering with business and technology teams to drive sustainable risk reduction.
* Support the development and continuous improvement of cybersecurity governance processes, security roadmaps, risk registers, and program performance metrics.
* Coordinate and support internal and external audits, independent security assessments, regulatory reviews, and risk management initiatives.
* Lead Ferguson's enterprise simulated phishing exercises and cybersecurity education program, developing risk-based campaigns and targeted training initiatives that improve employee awareness and cyber resilience.
* Analyze phishing simulation results, reporting trends, and awareness metrics to identify risks, measure efficiency, and drive ongoing improvement of security culture.
* Partner with business leaders, Human Resources, Corporate Communications, and Information Security teams to reduce phishing susceptibility and increase employee engagement in security procedures.
* Conduct security assessments of vendors, suppliers,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary