LinkedIn and 3rd parties use essential and non-essential cookies to provide, secure, analyze and improve our Services, and to show you relevant ads (including professional and job ads) on and off LinkedIn. Learn more in our Cookie Policy.
Select Accept to consent or Reject to decline non-essential cookies for this use. You can update your choices at any time in your settings.
This range is provided by Cyber Focus AI. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.
Base pay range
$86,600.00/yr - $166,200.00/yr
Cyber Focus AII's mission is to help cybersecurity professionals discover cutting-edge opportunities in their field. We are not a staffing firm or agency. Cyber Focus AI does not hire for these roles—we use advanced technology to locate and verify them from actual employers.
Job Description
The Enterprise GRC (Governance, Risk, and Compliance) team functions as a second line of defense, supporting the development and maintenance of Enterprise Technology (ET) risk management and compliance activities. This Analyst role supports the Cyber GRC Compliance & Certification Service Manager in executing day-to-day compliance, certification, and risk management activities across global and regional (EU/Germany) frameworks, including ISO 27001, SOC 2, NIST CSF GDPR, and other automotive-industry-specific standards.
This is a hands-on execution role, ideal for someone building foundational GRC expertise while contributing to certification lifecycle management, evidence collection, control monitoring, and regulatory reporting support.
Responsibilities
Responsibilities
Support the Service Manager in maintaining relationships with OGC, the application teams and other across the shared services teams, by preparing documentation, tracking action items, and coordinating meeting logistics.
Assist in the collection, organization, and validation of evidence artifacts, metrics, and control documentation required for the Global IT risk management framework.
Help monitor information security controls on an ongoing basis and flag deviations, gaps, or emerging risks to the Service Manager for escalation to the global GRC team.
Coordinate the annual risk assessment process for selected applications by gathering data, coordinating stakeholder input, and drafting supporting documentation.
Contribute to the preparation of annual reports and governance materials, including drafting content and compiling data for C-level presentations.
Assist in disseminating GRC training materials and coordinating regional awareness sessions, including scheduling, content adaptation, and tracking participation.
Maintain and update trackers/logs of newly identified IT risks and compliance gaps, ensuring accurate documentation before escalation to the global GRC team.
Support certification lifecycle activities (e.g., audit scheduling, evidence readiness checks, tracking remediation actions) for relevant frameworks.
Conduct research on regional regulatory requirements and summarize findings to support the Service Manager's representation of regional needs within the global team.
Assist with ad hoc reporting, data analysis, and documentation requests from internal stakeholders, auditors, or the global GRC team.
Qualifications
Required Skills
Foundational knowledge of information security risk management, governance, and compliance principles and practices.
Basic understanding of information systems auditing, control monitoring, and risk assessment concepts.
Strong research and data-gathering skills, with the ability to synthesize information from internal and external sources.
Ability to define problems, collect and analyze data, and draw clear, well-supported conclusions.
Clear written and verbal communication skills, with the ability to translate technical information for varied audiences.
Strong organizational skills and attention to detail, particularly with sensitive or confidential information.
Ability to learn quickly, adapt to new tools/frameworks, and work effectively in a fast-paced, evolving environment.
Good collaboration and stakeholder support skills; customer-service mindset.
Eagerness to build functional GRC expertise and grow into more senior compliance/certification roles.
Qualifications
Bachelor's degree in IT, Cybersecurity, or a relevant business discipline.
2-4 years of relevant IT, security, or compliance experience.
Exposure to security frameworks such as NIST or ISO preferred.
Experience supporting audits, assessments, or compliance projects is a plus.
Familiarity with GDPR or other EU regulatory requirements is advantageous but not required.
Strong Excel/PowerPoint skills for reporting and documentation support.
You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Ford Motor Company, we encourage you to apply!
As an established global company, we offer the benefit of choice. You can choose what your Ford future will look like: will your story span the globe, or keep you close to home? Will your career be a deep dive into what you love, or a series of new teams and new skills? Will you be a leader, a changemaker, a technical expert, a culture builder...or all of the above? No matter what you choose, we offer a work life that works for you, including:
Immediate medical, dental, vision and prescription drug coverage
Flexible family care da
#CyberFocusAI
Seniority level
Entry level
Employment type
Full-time
Job function
Analyst
Industries
Staffing and Recruiting
Referrals increase your chances of interviewing at Cyber Focus AI by 2x