×
Register Here to Apply for Jobs or Post Jobs. X

Compliance and Risk Manager - US Remote

Remote / Online - Candidates ideally in
Columbus, Franklin County, Ohio, 43216, USA
Listing for: Hexion
Remote/Work from Home position
Listed on 2026-07-20
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant, IT Business Analyst
Job Description & How to Apply Below
Company Overview

Hexion is a global leader in specialty chemicals, delivering innovative solutions that improve performance, sustainability, and efficiency across industries. Our manufacturing operations span multiple continents, integrating complex Operational Technology (OT) environments with enterprise IT systems. As regulatory expectations and cyber risk continue to evolve, Hexion is investing in a mature Governance, Risk, and Compliance (GRC) function to protect our business, our customers, and the integrity of our operations.

The Compliance and Risk Manager is a critical role in that function - translating regulatory requirements into operational controls and ensuring that risk is measured, managed, and communicated with rigor.

Position Overview

The Compliance and Risk Manager is a senior practitioner responsible for designing, implementing, and continuously improving Hexion's information security compliance and enterprise risk management programs. This role requires deep expertise across ISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, CIS Controls (Levels 1 and
2), and NIST 800-53, with a clear ability to map controls across frameworks and translate requirements into practical, auditable processes.

This role ensures:

* Hexion maintains certification and audit readiness across all applicable compliance frameworks

* Enterprise risk is identified, assessed, tracked, and reported with a consistent, repeatable methodology

* Controls are operationalized - not just documented - across IT and OT environments

* Compliance obligations in manufacturing and OT contexts are understood and addressed

* Security and risk posture is communicated clearly to executive leadership and the Board

This is a practitioner's role. The ideal candidate has spent years in the field - conducting audits, writing controls, managing risk registers, and preparing organizations for certification. They bring the authority of deep experience, the discipline of a compliance professional, and the judgment of a senior risk advisor.

Work Environment & Travel

* This is a remote-first position with periodic travel to Hexion manufacturing facilities, partner locations, and auditor or certification body engagements as required (~10-15%).

One-Line Summary

* Own Hexion's compliance and risk management programs across ISO 27001/17/18, SOC 2, CIS Controls, and NIST - ensuring that controls are real, risks are measured, and the organization is audit-ready every day of the year.

Job Responsibilities

1. Compliance Program Management (ISO 27001 / 27017 / 27018)

Own Hexion's ISO 27001 Information Security Management System (ISMS) and related cloud-specific extensions:

* Maintain ISO 27001 certification - manage the full audit lifecycle including internal audits, surveillance audits, and recertification, leveraging ISO 27002.

* Apply ISO 27017 controls cloud service security, governing Hexion's obligations as both a cloud service customer and, where applicable, a cloud service provider

* Implement ISO 27018 controls for protection of personally identifiable information (PII) in cloud environments

* Manage the Statement of Applicability (SoA), control selection rationale, and exceptions register

* Drive continuous improvement of the ISMS through management review cycles, nonconformity tracking, and corrective action management

* Coordinate with external certification bodies, manage audit evidence packages, and facilitate auditor access

2. SOC 2 Type II Program

Lead Hexion's SOC 2 compliance program across all applicable Trust Services Criteria:

* Define and maintain SOC 2 control mapping across Security, Availability, Confidentiality, Processing Integrity, and Privacy categories

* Manage common controls library - identify controls that satisfy multiple frameworks simultaneously to reduce compliance overhead

* Coordinate readiness assessments and work with external auditors throughout the Type II observation period

* Oversee evidence collection workflows, vendor attestation, and control testing documentation

* Track and resolve audit exceptions and management responses

* Communicate SOC 2 report status to customers and prospects in coordination with sales and legal

3. CIS Controls Implementation (Levels 1 and
2)

Operationalize the CIS Controls as the enterprise's security baseline framework:

* Maintain the CIS Controls implementation roadmap, tracking adoption across all 18 control families

* Prioritize and govern IG1 (basic cyber hygiene) and IG2 (foundational) controls across IT and OT environments

* Partner with security engineering to implement and validate technical controls mapped to CIS safeguards

* Measure and report CIS Controls maturity using CIS CSAT or equivalent tooling

* Use CIS Controls as a practical lens for remediation prioritization and risk reduction sequencing

Additional

Job Responsibilities

4. NIST 800-53 & Enterprise Risk Framework

Maintain fluency in NIST 800-53 and apply it to enterprise risk governance:

* Map organizational controls to NIST 800-53 control families to…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary