What are the responsibilities and job description for the Governance Risk and Compliance Manager position at The Timken Company?
Personal and Professional Growth
Governance Risk and Compliance Manager
Those who came before us helped land a man on the moon, create the world's infrastructure, and introduce renewable energy alternatives. Now you can join the Timken team to write your own unique story and help drive what's next.
- Own and operate the Information Security Management System (ISMS) aligned to ISO 27001 and lead CMMC certification efforts
- Define, maintain, and report program scope, objectives, success metrics, and multi-year roadmap for ISO and CMMC compliance
- Establish and run governance forums (e.g., ISMS steering committee, compliance working groups)
- Develop, update, and maintain ISMS documentation: Information Security Policy, Scope, Statement of Applicability (SoA), risk methodology, procedures, and work instructions
- Plan, coordinate, and execute compliance assessments, readiness assessments, and external certification assessments (ISO and CMMC); act as primary point of contact for assessors
- Ensure alignment of security objectives with business goals and legal/regulatory requirements
- Respond to inquiries from Timken customers and support the IT organization with various audits
- Research, and apply relevant laws, regulations, and industry standards to the organization's information systems and practices
- Train and educate employees on cybersecurity compliance requirements
- Stay up to date on emerging compliance issues
- Communicate cybersecurity risks and compliance requirements to senior management and business stakeholders
- Lead continuous improvement initiatives, implement lessons learned from audits and incidents, and mature compliance processes and tooling
- Experience with a variety of compliance frameworks, such as HIPAA and PCI DSS
- Experience with cybersecurity frameworks, such as the NIST Cybersecurity Framework, ISO 27001, ISO 27002, CMMC and SOC2
- Proven track record with auditing and reporting
- Experience of implementing, operating and maturing cybersecurity compliance with relevant frameworks, standards and regulations
- Adept at planning, executing, and tracking compliance projects within allocated budgets.
- Demonstrated experience with internal audits and working with external certification bodies/assessors
- Excellent stakeholder management and communication skills; able to translate technical requirements to business leaders and vice versa
- Project management skills with ability to manage multiple concurrent initiatives and remediation efforts
- Bachelor's in Business, Computer Science, Computer Engineering, or related discipline with a minimum of 8 years’ experience required
- Master's in Business, Computer Science, Computer Engineering, or related discipline with 12 years’ experience preferred
Timken is a global technology leader in engineered bearings and industrial motion. Our expanding portfolio of next-generation solutions helps customers around the world improve efficiency, solve their toughest challenges, and push the boundaries of performance. We employ 19,000 people globally, operate from 45 countries, and posted $4.6 billion in sales in 2025.
We have been recognized as one of America's Most Responsible Companies 6x by Newsweek and one of the World's Most Ethical Companies® 15x by Ethisphere.
Why Choose Timken?
- Over a century of knowledge and innovation
- A culture of top performance
- A global, diverse environment
- Products that contribute to a sustainable world
- A conviction to improve communities around us
- Competitive salary and benefits
Not Ready To Apply?
Stay connected by joining our network and we'll keep you informed about upcoming events and opportunities that match your interests.
Talent Community
Job Segment: Information Security, Computer Science, Cyber Security, Manager, Project Manager, Technology, Security, Management