Enerpac Tool Group Corporation
IT GRC Lead
Skills
Job description
Overview About Enerpac Tool Group Enerpac Tool Group is a premier industrial tools and services company serving a broad and diverse set of customers in more than 25 countries. The Company’s businesses are global leaders in high-pressure hydraulic tools, controlled force products and solutions for precise positioning of heavy loads that help customers safely and reliably tackle some of the most challenging jobs around the world. The Company was founded in 1910 and is headquartered in Milwaukee, Wisconsin. Enerpac Tool Group trades on the NYSE under the symbol “EPAC”. Our vision is to be our customer’s preferred partner through relentless innovation of industrial tools and services that help them safely and reliably tackle their toughest jobs around the world. For further information on Enerpac Tool Group and its businesses, visit the Company's website at https://www.enerpactoolgroup.com/ What You Will Do Governance, Policies & Standards Establish and maintain the company's IT and cybersecurity GRC framework. Develop, document, maintain, and communicate security policies, standards, procedures, and guidelines. Map policies and controls to applicable regulatory, industry, and customer requirements. Establish processes for periodic policy review, approval, exception management, and attestation. Help define and maintain security control objectives and supporting documentation. Risk Management Coordinate IT and cybersecurity risk assessments across the organization. Maintain the enterprise IT and cybersecurity risk register, including risk identification, ownership, mitigation plans, and reporting. Track remediation activities and risk acceptance/exceptions through completion. Support risk reporting and metrics for IT leadership and other stakeholders. Help establish a consistent approach for assessing and prioritizing technology and cybersecurity risks. Compliance & Controls Support the company's compliance obligations and control activities, including but not limited to SOX, CMMC, UK Cyber Essentials, and other applicable regulatory, contractual, customer, and industry requirements. Monitor changes in applicable compliance requirements and assess their impact on the organization. Coordinate evidence collection, control testing, remediation, and audit requests. Support internal and external audits and assessments. Develop and maintain compliance/control matrices and documentation. Identify gaps and work with control owners to develop remediation plans. Security Awareness & Training Support the development and administration of security awareness and training programs. Coordinate required cybersecurity training and employee communications. Track training completion and follow up on outstanding requirements. Help develop security awareness content, campaigns, and communications tailored to different employee audiences. Coordinate and execute quarterly phishing simulation activities, to include follow on learning for any failures. Third-Party & Supply Chain Risk Establish and manage a third-party cybersecurity risk management process in partnership with Procurement, Legal, IT, and business stakeholders. Perform or coordinate security risk assessments of vendors, suppliers, and other third parties. Review security questionnaires, SOC reports, certifications, and other third-party security documentation. Track identified vendor risks, remediation activities, and risk acceptances. Help establish security requirements and ongoing monitoring practices for critical suppliers and service providers. Reporting & Program Development Develop GRC metrics, dashboards, and management reports. Maintain accurate GRC documentation and records. Help identify opportunities to automate and improve GRC processes. Support cybersecurity initiatives and other activities as needed within a small, collaborative IT and Cybersecurity team. What Makes You an Ideal Candidate Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or a related field, or equivalent experience. 7–10 years of experience in cybersecurity, IT risk, GRC, IT audit, compliance, or a related field, including oversight and responsibilities pertaining to SOX ITGCs. Working knowledge of cybersecurity principles, IT controls, risk management, and compliance frameworks. Experience developing or managing policies, standards, controls, risk assessments, or compliance programs. Strong analytical, organizational, documentation, and communication skills. Ability to work effectively with technical and non-technical stakeholders across a global organization. Comfortable working independently and building processes in an environment where GRC capabilities are still being established. Strong attention to detail and ability to manage multiple priorities and deadlines. Enerpac Tool Group Values Be an ambassador for the businesses and ensure that Enerpac Tool Group Values always come first: SAFETY - Safety is our highest priority and is at the heart of everything we do. INTEGRITY - We will act with honesty and transparency and always do the right thing. OWNERSHIP - We will own our commitments, act with a sense of urgency, and deliver what is expected of us on time, or ask for help early enough. TEAMWORK - We will act as one Enerpac team, operate with an enterprise-wide mindset, and support each other to deliver for our stakeholders. AGILITY - We will act with purpose and speed, and we will adapt quickly to changing circumstances What we offer Our employee benefits including flexible workplace policies, employee resource groups, learning and development resources, career progression pathways, and community engagement initiatives are some of the reasons why we have had great success in bringing in new talent. In addition, our global employee wellness programs are crafted to support the physical, emotional, and financial well-being of our employees. *Benefits & Perks vary by Country. If you are an individual with a disability and you need assistance or a reasonable accommodation during the application process, please reach out to us at: recruiter@enerpac.com If you’re looking for a unique, exciting career with variety and potential for growth, Enerpac Tool Group offers challenges & extraordinary rewards for people on a global scale. Never Compromise – choose ETG!