Hexion is seeking a Compliance and Risk Manager, a senior practitioner responsible for designing, implementing, and continuously improving the company's information security compliance and enterprise risk management programs. This role requires deep expertise across ISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, CIS Controls (Levels 1 and 2), and NIST 800-53. The position ensures Hexion maintains certification and audit readiness, that enterprise risk is identified, assessed, tracked, and reported, that controls are operationalized across IT and OT environments, that compliance obligations in manufacturing and OT contexts are understood and addressed, and that the security and risk posture is communicated clearly to executive leadership and the Board. This is a hands-on practitioner's role focused on managing compliance and risk programs, conducting audits, writing controls, managing risk registers, and preparing organizations for certification.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior