About Lubrizol
The Lubrizol Corporation, a Berkshire Hathaway company, is a specialty chemical company whose science delivers sustainable solutions to advance mobility, improve wellbeing and enhance modern life. Founded in 1928, Lubrizol owns and operates more than 100 manufacturing facilities, sales, and technical offices around the world and has about 8,000 employees. For more information, visit www.Lubrizol.com.
We value diversity in professional backgrounds and life experiences. By enabling a consistent, unbiased, and transparent recruitment process, Lubrizol seeks to create a positive experience for candidates so we can get to know them at their best. We recognize unique work and life situations and offer flexibility, ensuring our employees feel engaged and fulfilled in every aspect of life.
Role Accountability
The manager position is accountable to manage the global Information Security Governance, Risk and Compliance functions and team furthering the maturity of both. The Team is responsible for the policies, procedures, and technologies that Lubrizol uses to comply with regulations and to mitigate threats from malicious actors and reduce the information technology vulnerabilities that negatively impact data confidentiality, integrity, and availability. The position reports into the Sr. Manager Information Security (Predictive) within the Information Technology (IT) Division of Lubrizol. The IT Division has team members around the world to support global IT standards and systems.
Essential Job Functions
- Lead the team to ensure compliance with cybersecurity aspects of laws or regulations, mitigate threats, and reduce vulnerabilities utilizing the risk management program to identify, assess, evaluate, and treat risks
- Mature the Risk Management and Compliance Program by recommending and implementing process improvements as well as ensuring proper governance is in place to support the program
- Develop strong relationships with IT managers, IT service owners, and control owners
- Report on overall Program progress to senior management
- Track and ensure key tasks are successfully completed by the team such as responding to risk assessments and audits from external and internal customers, governance of IT policies and standards, and compliance with regulatory controls
- Collaborate with IT staff and management to ensure proper controls are embedded within IT services, processes, and systems
- Lead the 3rd Party Risk Management program
- Other information security activities as needed
Critical Competencies
Strong interpersonal and leadership skillsAbility to effectively build relationships and work in a collaborative, matrix-driven, global environmentDemonstrated effectiveness of working independently, establishing priorities, and managing task completion aligned to the needs of the organizationOrganizational awareness with an understanding of how to engage to achieve resultsSound decision making, proactive / creative problem solving and strategic thinking skillsStrong IT process discipline and critical thinking skillsMust be able to drive clear accountability and expectationsStrong written and verbal communication skills required to communicate with local users, global colleagues, and leadershipRequired Qualifications
Education / Certifications :
Bachelor's degree in Information Technology (IT) or related field or equivalent experience.Experience :
Minimum of 5 years of relevant industry and professional experience (e.g., risk management, audit, third party risk, operational risk, information security, etc.)Minimum of 3 years leading a teamExperience presenting to governance committees or senior managementIn-depth practical knowledge of third-party risk management, IT risk assessments, operational processes, and applicable techniques for implementation of regulatory requirementsOperational experience with a risk management system (Archer, SAI360, etc.)Familiarity in security domains including identity, access, authentication, encryption, application security, network security, vulnerability and patch management, information security metrics, policies, standards, and procedures, etc.Experience with ISO and NIST security standardsCRISC, CISM or CISA certifications preferredExperience with standards to secure industrial automation and control systems such as ISA / IEC 62443 preferredExpertise in tracking and analyzing emerging cybersecurity threats, risks and trends contextualizing them specific to company business processes, assets and personnel and informing stakeholders preferredSkills & Systems :
Microsoft Windows-based operating systems and collaboration toolsUnderstanding of risk management processesKnowledge of basic IT security, network security, active directory, and SAP ECC / S4 conceptsAbility to resolve issues via undocumented methods via research and investigationExperience in documenting issues and solutions to assist end user / co-worker understandingWork Environment
Role Scope :
Primary : Manager Information Security Governance, Risk and ComplianceTravel :
Very Limited;Work Hours :
M-F 1st shiftPhysical Demands :
General office-type activityReady for your next career step? Apply today and let's shape the future together!
It's an exciting time to be part of Lubrizol. Lubrizol is not staying put. We are continually learning and evolving. Our passion delivers our success - not only for Lubrizol but for those who count on us every day : our employees, customers and communities.
We work with a relentless commitment to operate safely and responsibly, keeping safety, sustainability, ethics, and compliance at the forefront of everything we do. The well-being of our employees, customers and communities is paramount to our culture and in the way we approach our work.
As a diverse, global team, we work together to solve some of the world's most pressing challenges. We impact everyday lives through science only Lubrizol can deliver, and we never stop pushing to do it better.
One of the founding principles of The Lubrizol Corporation more than 90 years ago was treating every employee with dignity and respect. That same commitment is only stronger today.
More than that, we are committed to providing an environment where every employee can be the best they can be, no matter their race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veteran status or any other characteristic.