Information Security and Compliance Manager
Indexed description
Information Security and Compliance Manager
Department
Information Technology
Reports To
Director of IT
Classification
Exempt / Full-Time
Location
Elkhart, IN
Frameworks
CMMC Level 2 (C3PAO), TISAX Level 3, SOX ITGCs, PCI-DSS, ISO 9001
Position Summary
This is a founding security role — our first dedicated information security hire, functioning as a de facto individual-contributor CISO. Reporting to the Director of IT, you will design, implement, and own the company's information security program and serve as the hands-on accountable owner across a portfolio of regulatory frameworks for a modest-sized discrete manufacturer as an internationally operating Business Unit of a larger conglomerate. You will do the work directly: writing policy, managing audits, maintaining evidence, and tracking compliance obligations — while communicating clearly with leadership and external auditors.
Key Responsibilities
Security Program
• Build and maintain the company ISMS: policies, standards, risk register, and control framework.
• Own the vulnerability management program, security architecture reviews, and Incident Response plan.
• Manage the vendor/third-party risk program, including security requirements in supplier contracts.
• Administer annual security awareness training and phishing simulation program.
• Report program status, open risks, and compliance calendar to the Director of IT.
CMMC Level 2 (C3PAO)
• Own the System Security Plan (SSP), POA&M, and CUI environment boundary documentation.
• Serve as primary contact for C3PAO assessments; maintain audit-ready posture year-round.
• Manage DFARS 252.204-7021 obligations and any subcontractor security flow-down requirements.
TISAX Level 3
• Own the full TISAX assessment lifecycle: scoping, VDA ISA gap analysis, remediation, and ENX audit coordination.
• Maintain the TISAX label and manage exchange requests; support OEM/Tier-1 customer verification requirements.
SOX IT General Controls
• Own ITGC design and evidence across logical access, change management, and computer operations.
• Serve as primary liaison to external financial auditors for ITGC walkthroughs and evidence delivery.
• Manage access certifications, privileged access reviews, and separation of duties controls.
PCI-DSS
• Own CDE scope, network segmentation documentation, and annual ROC/SAQ process with QSA.
• Maintain ASV scanning and penetration testing schedules; drive remediation of findings.
Contract Compliance Requirements Tracking (ISO 9001 Support)
• Maintain a contract requirements register capturing security, data handling, and compliance obligations from customer and supplier contracts — supporting the company's ISO 9001 QMS.
• Review incoming contracts for security and IT compliance obligations; communicate requirements to relevant teams and track fulfillment.
• Partner with the Quality Manager on internal audits where contract requirements intersect with IT controls.
Qualifications
Required
• 5+ years in information security and/or IT compliance.
• Experience as the primary security owner or sole practitioner — comfortable building, not just inheriting.
• Experience as an auditor or managed third-party auditors directly (C3PAO, QSA, or external financial auditors).
• Reviewed contracts for security/compliance obligations and translated them into actionable IT requirements.
• Proficiency with vulnerability management, SIEM, IAM/MFA, and endpoint protection tooling.
• Strong written communication: policy writing, SSPs, control narratives, and executive summaries.
Preferred
• Direct, hands-on experience managing preparation for at least two of: CMMC/NIST 800-171, TISAX, SOX ITGCs, PCI-DSS.
• Background in defense manufacturing, automotive supply chain, or regulated SME manufacturing.
• CISSP, CISM, CISA, or equivalent certification (or active pursuit within 12 months).
• CMMC Registered Practitioner (RP) or Certified Professional (CP).
• PCI-ISA or QSA credential.
• Experience with Microsoft 365 / Entra ID in a compliance-scoped environment.
• Familiarity with GRC platforms (Drata, Vanta, Archer, or similar).
• Exposure to ITAR/EAR requirements as they intersect with information security.
Who You Are
• Ownership mentality — you build the program, not just maintain a checklist.
• Practitioner first — comfortable writing the SSP and presenting to the CFO in the same week.
• Multi-framework fluency — you hold CMMC, TISAX, SOX, and PCI context simultaneously.
• Collaborative — you get compliance outcomes by working with operations, not around them.
• Detail-oriented — audit-ready records are your professional standard, not a pre-audit sprint and you read agreements for business obligations as a matter of routine.
• Right-sized mindset — you know how to apply enterprise-grade thinking pragmatically in a SME.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search