Demo

Information Security and Compliance Manager

Transhield, Inc.
Elkhart, IN Full Time
POSTED ON 8/7/2026
AVAILABLE BEFORE 2/2/2027

Information Security and Compliance Manager


Department

Information Technology

Reports To

Director of IT

Classification

Exempt / Full-Time

Location

Elkhart, IN

Frameworks

CMMC Level 2 (C3PAO), TISAX Level 3, SOX ITGCs, PCI-DSS, ISO 9001


Position Summary

This is a founding security role — our first dedicated information security hire, functioning as a de facto individual-contributor CISO. Reporting to the Director of IT, you will design, implement, and own the company's information security program and serve as the hands-on accountable owner across a portfolio of regulatory frameworks for a modest-sized discrete manufacturer as an internationally operating Business Unit of a larger conglomerate. You will do the work directly: writing policy, managing audits, maintaining evidence, and tracking compliance obligations — while communicating clearly with leadership and external auditors.


Key Responsibilities

Security Program

•    Build and maintain the company ISMS: policies, standards, risk register, and control framework.

•    Own the vulnerability management program, security architecture reviews, and Incident Response plan.

•    Manage the vendor/third-party risk program, including security requirements in supplier contracts.

•    Administer annual security awareness training and phishing simulation program.

•    Report program status, open risks, and compliance calendar to the Director of IT.

CMMC Level 2 (C3PAO)

•    Own the System Security Plan (SSP), POA&M, and CUI environment boundary documentation.

•    Serve as primary contact for C3PAO assessments; maintain audit-ready posture year-round.

•    Manage DFARS 252.204-7021 obligations and any subcontractor security flow-down requirements.

TISAX Level 3

•    Own the full TISAX assessment lifecycle: scoping, VDA ISA gap analysis, remediation, and ENX audit coordination.

•    Maintain the TISAX label and manage exchange requests; support OEM/Tier-1 customer verification requirements.

SOX IT General Controls

•    Own ITGC design and evidence across logical access, change management, and computer operations.

•    Serve as primary liaison to external financial auditors for ITGC walkthroughs and evidence delivery.

•    Manage access certifications, privileged access reviews, and separation of duties controls.

PCI-DSS

•    Own CDE scope, network segmentation documentation, and annual ROC/SAQ process with QSA.

•    Maintain ASV scanning and penetration testing schedules; drive remediation of findings.

Contract Compliance Requirements Tracking (ISO 9001 Support)

•    Maintain a contract requirements register capturing security, data handling, and compliance obligations from customer and supplier contracts — supporting the company's ISO 9001 QMS.

•    Review incoming contracts for security and IT compliance obligations; communicate requirements to relevant teams and track fulfillment.

•    Partner with the Quality Manager on internal audits where contract requirements intersect with IT controls.


Qualifications

Required

•    5 years in information security and/or IT compliance.

•    Experience as the primary security owner or sole practitioner — comfortable building, not just inheriting.

•    Experience as an auditor or managed third-party auditors directly (C3PAO, QSA, or external financial auditors).

•    Reviewed contracts for security/compliance obligations and translated them into actionable IT requirements.

•    Proficiency with vulnerability management, SIEM, IAM/MFA, and endpoint protection tooling.

•    Strong written communication: policy writing, SSPs, control narratives, and executive summaries.

Preferred

•    Direct, hands-on experience managing preparation for at least two of: CMMC/NIST 800-171, TISAX, SOX ITGCs, PCI-DSS.

•    Background in defense manufacturing, automotive supply chain, or regulated SME manufacturing.

•    CISSP, CISM, CISA, or equivalent certification (or active pursuit within 12 months).

•    CMMC Registered Practitioner (RP) or Certified Professional (CP).

•    PCI-ISA or QSA credential.

•    Experience with Microsoft 365 / Entra ID in a compliance-scoped environment.

•    Familiarity with GRC platforms (Drata, Vanta, Archer, or similar).

•    Exposure to ITAR/EAR requirements as they intersect with information security.


Who You Are

•    Ownership mentality — you build the program, not just maintain a checklist.

•    Practitioner first — comfortable writing the SSP and presenting to the CFO in the same week.

•    Multi-framework fluency — you hold CMMC, TISAX, SOX, and PCI context simultaneously.

•    Collaborative — you get compliance outcomes by working with operations, not around them.

•    Detail-oriented — audit-ready records are your professional standard, not a pre-audit sprint and you read agreements for business obligations as a matter of routine.

•    Right-sized mindset — you know how to apply enterprise-grade thinking pragmatically in a SME.

Salary.com Estimation for Information Security and Compliance Manager in Elkhart, IN
$122,392 to $146,459
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Information Security and Compliance Manager?

Sign up to receive alerts about other jobs on the Information Security and Compliance Manager career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$123,739 - $165,355
Income Estimation: 
$163,270 - $214,905
Income Estimation: 
$150,417 - $183,047
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Not the job you're looking for? Here are some other Information Security and Compliance Manager jobs in the Elkhart, IN area that may be a better fit.

  • Johnson & Johnson MedTech Warsaw, IN
  • At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are preven... more
  • 7 Days Ago

  • Johnson & Johnson MedTech Warsaw, IN
  • At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are preven... more
  • 12 Days Ago

AI Assistant is available now!

Feel free to start your new journey!