Compliance and Risk Manager - US Remote

Hexion CareersWorthington, OH
Remote

About The Position

Hexion is seeking a Compliance and Risk Manager, a senior practitioner responsible for designing, implementing, and continuously improving the company's information security compliance and enterprise risk management programs. This role requires deep expertise across ISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, CIS Controls (Levels 1 and 2), and NIST 800-53. The position ensures Hexion maintains certification and audit readiness, that enterprise risk is identified, assessed, tracked, and reported, that controls are operationalized across IT and OT environments, that compliance obligations in manufacturing and OT contexts are understood and addressed, and that the security and risk posture is communicated clearly to executive leadership and the Board. This is a hands-on practitioner's role focused on managing compliance and risk programs, conducting audits, writing controls, managing risk registers, and preparing organizations for certification.

Requirements

  • Bachelor's degree in Information Security, Computer Science, Business Administration, or related field (Master's preferred).
  • 7+ years of progressive experience in information security compliance, GRC, or risk management roles.
  • Demonstrated, hands-on experience managing ISO 27001 certification programs — including internal audits, SoA management, and external audit coordination.
  • Deep knowledge of ISO 27017 and ISO 27018 cloud security and privacy controls.
  • Practical SOC 2 Type II experience — control design, evidence collection, auditor management, and exception resolution.
  • Proficiency with CIS Controls (IG1 and IG2) including control mapping, gap assessment, and implementation road mapping.
  • Working knowledge of NIST 800-53 control families and the NIST Risk Management Framework.
  • Experience operating enterprise risk management programs — risk registers, treatment plans, risk reporting to leadership.
  • Ability to build and maintain control crosswalks across multiple frameworks (ISO, SOC 2, CIS, NIST).
  • Strong written communication — able to produce policy documents, audit evidence packages, and executive risk reports.
  • Framework fluency — ability to navigate ISO 27001, SOC 2, CIS Controls, and NIST.
  • Controls precision — ability to write controls that are specific, testable, and defensible under audit scrutiny.
  • Risk judgment — ability to distinguish material risk from noise and help leadership make informed decisions.
  • Operational credibility — understanding of how manufacturing and OT environments work and ability to design implementable compliance requirements.
  • Stakeholder influence — ability to earn trust with engineering, legal, finance, and operations.
  • Audit readiness — ability to maintain an organization's readiness posture year-round.

Nice To Haves

  • Experience with OT/ICS environments — familiarity with IEC 62443, NIST SP 800-82, or industrial cybersecurity frameworks.
  • Experience with manufacturing or chemical industry regulatory landscape (OSHA PSM, EPA RMP, REACH, or similar).
  • Experience with third-party risk management (TPRM) programs and vendor risk assessment methodologies.
  • Experience with GDPR, CCPA, or other data privacy regulatory frameworks.
  • CISM (Certified Information Security Manager).
  • CRISC (Certified in Risk and Information Systems Control).
  • ISO 27001 Lead Auditor or Lead Implementer.
  • CISSP, CCSP, or CGEIT.
  • SOC 2 practitioner credentials (AICPA TSC or equivalent).

Responsibilities

  • Own Hexion's ISO 27001 Information Security Management System (ISMS) and related cloud-specific extensions, including managing the full audit lifecycle, applying ISO 27017 controls for cloud service security, and implementing ISO 27018 controls for protection of personally identifiable information (PII) in cloud environments.
  • Manage the Statement of Applicability (SoA), control selection rationale, and exceptions register, and drive continuous improvement of the ISMS through management review cycles, nonconformity tracking, and corrective action management.
  • Coordinate with external certification bodies, manage audit evidence packages, and facilitate auditor access.
  • Lead Hexion's SOC 2 compliance program across all applicable Trust Services Criteria, including defining and maintaining SOC 2 control mapping, managing the common controls library, and coordinating readiness assessments and external audits.
  • Oversee evidence collection workflows, vendor attestation, and control testing documentation, and track and resolve audit exceptions and management responses.
  • Communicate SOC 2 report status to customers and prospects in coordination with sales and legal.
  • Operationalize the CIS Controls as the enterprise's security baseline framework, maintaining the CIS Controls implementation roadmap and prioritizing and governing IG1 and IG2 controls across IT and OT environments.
  • Partner with security engineering to implement and validate technical controls mapped to CIS safeguards, and measure and report CIS Controls maturity using CIS CSAT or equivalent tooling.
  • Use CIS Controls as a practical lens for remediation prioritization and risk reduction sequencing.
  • Maintain fluency in NIST 800-53 and apply it to enterprise risk governance, mapping organizational controls to NIST 800-53 control families and leveraging NIST 800-53 as a reference framework for control gap analysis and risk treatment prioritization.
  • Apply NIST Risk Management Framework (RMF) concepts to information system authorization and risk acceptance decisions, and maintain control crosswalks across multiple frameworks.
  • Own the internal controls assurance program, including designing, documenting, and maintaining the enterprise controls library, and executing and managing the internal control testing calendar.
  • Identify control deficiencies, document findings, and drive remediation to closure with defined timelines.
  • Develop control self-assessment (CSA) programs and implement GRC tooling to automate evidence collection, control monitoring, and reporting.
  • Maintain the policy architecture that underpins the compliance program, owning the information security policy library and managing the policy exception process.
  • Ensure policies are mapped to applicable control frameworks and regulatory requirements, and coordinate policy acknowledgment and awareness campaigns.

Benefits

  • Periodic travel to Hexion manufacturing facilities, partner locations, and auditor or certification body engagements as required (~10–15%).
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service