Senior Engineer, Global Cybersecurity Governance, Risk and Compliance

DonaldsonBloomington, MN
$86,200 - $111,000

About The Position

Donaldson is committed to solving the world’s most complex filtration challenges. Together, we make cool things. As an established technology and innovation leader, we are continuously evolving to meet the filtration needs of our changing world. Join a culture of collaboration and innovation that matters and a chance to learn, effect change, and make meaningful contributions at work and in communities. The Senior Engineer, Global Governance, Risk & Compliance (GRC) is responsible for executing and advancing enterprise risk management and compliance assessment capabilities across global operations. This role leads risk tracking, assessment, and reporting processes to ensure consistent identification, prioritization, and communication of cybersecurity and regulatory risks. The position supports global initiatives related to IT and Information Security governance, risk, and compliance. This role is responsible for driving risk assessment execution, enhancing process maturity, and improving visibility of enterprise risk to leadership. The Senior Engineer partners with IT, Privacy, Legal, Procurement, and business stakeholders to ensure alignment with internal policies, industry standards, and global regulatory requirements.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or related field and/or corresponding experience in the necessary knowledge and skills of the position
  • Minimum 5 years of professional-level IT and information security experience, with a focus on IT controls, risk management, data protection, and technology compliance
  • Experience conducting risk assessments and evaluating controls against frameworks such as ISO 27001, NIST, or SOC2
  • Communication skills (in English) in describing technical risks and issues to business and operational individuals
  • Strong understanding of third-party risk management and regulatory compliance requirements
  • Demonstrated ability to communicate technical risks to business and executive stakeholders
  • At least one relevant, current industry certification, such as CISSP, CISM, CRISC, or CISA, etc.

Nice To Haves

  • Experience in global or multi-regional organizations with diverse regulatory requirements
  • Familiarity with some of the following: SOX 404, PCI DSS, NIST 800-171, ISO 27001, MLPS, Oracle security, IT policies, and procedures
  • IT Audit/Consulting experience
  • Familiarity with GRC platforms (e.g., ServiceNow, Archer or equivalent)
  • Experience supporting audits, regulatory inquiries, or certification programs (e.g., ISO, TISAX, CMMC)
  • Any additional current industry certification(s), such as CISSP, CISM, CRISC, or CISA, etc.

Responsibilities

  • Lead and maintain the enterprise GRC risk tracking framework
  • Coordinate global risk review meetings with IT, business, and operational stakeholders
  • Assess, rate, and prioritize security risks against internal criteria, industry standards, and regulatory requirements
  • Compile and communicate risk posture to executive leadership and IT owners, ensuring appropriate awareness and accountability
  • Manage and facilitate risk assessments for new technologies, processes, and acquisitions
  • Improve risk assessment processes through alignment with IT architecture and Privacy
  • Lead compliance assessments against internal policies, standards, and procedures
  • Perform vendor and supplier security reviews, including execution of third-party risk assessments
  • Review third-party attestations (e.g., SOC2), support contract security provisions with Legal, and enhance vendor risk management processes and reporting

Benefits

  • health benefits
  • retirement plan (401k)
  • paid time away
  • paid leaves (including paid parental leave)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service