Director of Cybersecurity Governance, Risk, and Compliance

BallWestminster, CO
$143,000 - $225,000Onsite

About The Position

The Director of Cybersecurity Governance, Risk, and Compliance (GRC) is accountable for designing, building, and leading enterprise‑wide cyber risk governance, regulatory compliance strategy, and board‑level risk reporting for Ball Corporation’s global manufacturing and supply‑chain‑driven business. This role sets the enterprise cyber risk posture, translates business risk appetite into enforceable governance mechanisms, and ensures cybersecurity risk is measured, reported, and managed as a business risk and not a purely technical concern. The Director serves as Ball’s primary authority on cybersecurity risk governance, regulatory compliance and assurance, and acts as a trusted advisor to the CISO, executive leadership, Legal, Internal Audit, and the Board. The role owns and governs all Security GRC sub‑capabilities: 1) Security Governance & Program Management, 2) Security Risk Management, 3) Security Assessments & Compliance Management, 4) Cyber‑Supply Chain Risk Management, 5) Business Continuity Planning (cyber integration), 6) Security Training & Awareness, 7) Cyber Metrics and Reporting.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Risk Management, Business Administration, or a related field required; Master’s degree (e.g., MBA or MS in Information Security/Risk Management) strongly preferred.
  • Minimum of 15 years of progressive experience in cybersecurity, technology risk, or enterprise risk management, including 7+ years leading and building GRC, risk, or compliance functions within complex, preferably global, organizations.
  • Demonstrated experience operating in regulated, asset‑intensive, or manufacturing‑centric environments.
  • Deep knowledge of cybersecurity governance, risk, and compliance frameworks (with experience implementing NIST CSF and ISO 27001), and familiarity with relevant regulations (e.g., SOX ITGC, data protection laws).
  • CISSP or CISM certification required; CRISC, CGEIT, or similar risk‑focused certification strongly preferred.

Responsibilities

  • Establish and maintain the enterprise cybersecurity governance framework, including policies, standards, risk taxonomy, and accountability models, with a focus on building out missing program elements to elevate maturity.
  • Define and operationalize the enterprise cyber risk management program, including risk identification, assessment, prioritization, escalation, and reporting.
  • Own executive‑ and Board‑level cybersecurity risk & metrics reporting, ensuring alignment to business impact, materiality, and risk tolerance.
  • Lead the global cybersecurity compliance strategy, ensuring alignment with applicable regulatory, legal, and contractual requirements, with an emphasis on establishing rigorous security controls and repeatable compliance processes.
  • Provide senior oversight of cybersecurity audits, assessments, and assurance activities; ensure consistent and defensible outcomes.
  • Govern cyber supply‑chain and third‑party risk management, embedding security risk considerations into vendor lifecycle processes.
  • Ensure cybersecurity risk is integrated into business continuity, crisis management, and enterprise resilience planning.
  • Build, lead, develop, and mentor the Security GRC team, establishing clear interfaces with other cybersecurity and business functions.
  • Ensure cybersecurity governance and compliance requirements are appropriately tailored to regional regulatory, legal, and operational realities while maintaining global consistency.
  • Partner with regional business and technology leaders to address localized cyber risk scenarios, including manufacturing, operational technology (OT), and supply‑chain considerations.
  • Oversee regional regulatory compliance obligations (e.g., data protection, critical infrastructure, export controls) and support regulatory inquiries or audits as required.
  • Enable effective risk communication and escalation between regions and corporate leadership, ensuring timely visibility of material risks.

Benefits

  • Annual incentive compensation plan
  • Comprehensive benefits structure
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service