Compliance and Risk Manager - US Remote
Hexion
Company OverviewHexion is a global leader in specialty chemicals, delivering innovative solutions that improve performance, sustainability, and efficiency across industries. Our manufacturing operations span multiple continents, integrating complex Operational Technology (OT) environments with enterprise IT systems. As regulatory expectations and cyber risk continue to evolve, Hexion is investing in a mature Governance, Risk, and Compliance (GRC) function to protect our business, our customers, and the integrity of our operations. The Compliance and Risk Manager is a critical role in that function — translating regulatory requirements into operational controls and ensuring that risk is measured, managed, and communicated with rigor. Position OverviewThe Compliance and Risk Manager is a senior practitioner responsible for designing, implementing, and continuously improving Hexion's information security compliance and enterprise risk management programs. This role requires deep expertise across ISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, CIS Controls (Levels 1 and 2), and NIST 800-53, with a clear ability to map controls across frameworks and translate requirements into practical, auditable processes. This role ensures: Hexion maintains certification and audit readiness across all applicable compliance frameworks Enterprise risk is identified, assessed, tracked, and reported with a consistent, repeatable methodology Controls are operationalized — not just documented — across IT and OT environments Compliance obligations in manufacturing and OT contexts are understood and addressed Security and risk posture is communicated clearly to executive leadership and the Board This is a practitioner's role. The ideal candidate has spent years in the field — conducting audits, writing controls, managing risk registers, and preparing organizations for certification. They bring the authority of deep experience, the discipline of a compliance professional, and the judgment of a senior risk advisor. Work Environment & Travel This is a remote-first position with periodic travel to Hexion manufacturing facilities, partner locations, and auditor or certification body engagements as required (~10–15%). One-Line Summary Own Hexion's compliance and risk management programs across ISO 27001/17/18, SOC 2, CIS Controls, and NIST — ensuring that controls are real, risks are measured, and the organization is audit-ready every day of the year. Job Responsibilities1. Compliance Program Management (ISO 27001 / 27017 / 27018) Own Hexion's ISO 27001 Information Security Management System (ISMS) and related cloud-specific extensions: Maintain ISO 27001 certification — manage the full audit lifecycle including internal audits, surveillance audits, and recertification, leveraging ISO 27002. Apply ISO 27017 controls cloud service security, governing Hexion's obligations as both a cloud service customer and, where applicable, a cloud service provider Implement ISO 27018 controls for protection of personally identifiable information (PII) in cloud environments Manage the Statement of Applicability (SoA), control selection rationale, and exceptions register Drive continuous improvement of the ISMS through management review cycles, nonconformity tracking, and corrective action management Coordinate with external certification bodies, manage audit evidence packages, and facilitate auditor access 2. SOC 2 Type II Program Lead Hexion's SOC 2 compliance program across all applicable Trust Services Criteria: Define and maintain SOC 2 control mapping across Security, Availability, Confidentiality, Processing Integrity, and Privacy categories Manage common controls library — identify controls that satisfy multiple frameworks simultaneously to reduce compliance overhead Coordinate readiness assessments and work with external auditors throughout the Type II observation period Oversee evidence collection workflows, vendor attestation, and control testing documentation Track and resolve audit exceptions and management responses Communicate SOC 2 report status to customers and prospects in coordination with sales and legal 3. CIS Controls Implementation (Levels 1 and 2) Operationalize the CIS Controls as the enterprise's security baseline framework: Maintain the CIS Controls implementation roadmap, tracking adoption across all 18 control families Prioritize and govern IG1 (basic cyber hygiene) and IG2 (foundational) controls across IT and OT environments Partner with security engineering to implement and validate technical controls mapped to CIS safeguards Measure and report CIS Controls maturity using CIS CSAT or equivalent tooling Use CIS Controls as a practical lens for remediation prioritization and risk reduction sequencing Additional Job Responsibilities4. NIST 800-53 & Enterprise Risk Framework Maintain fluency in NIST 800-53 and apply it to enterprise risk governance: Map organizational controls to NIST 800-53 control families to support federal customer requirements, supply chain diligence, and internal governance Leverage NIST 800-53 as a reference framework for control gap analysis and risk treatment prioritization Apply NIST Risk Management Framework (RMF) concepts to information system authorization and risk acceptance decisions Maintain control crosswalks across ISO 27001, SOC 2, CIS Controls, NIST 800-53, and NIST CSF to reduce duplicated effort and provide unified risk visibility and leverage ISO 27005 risk framework. 5. Controls Design, Testing & Assurance Own the internal controls assurance program: Design, document, and maintain the enterprise controls library — mapping each control to owning team, testing frequency, and framework coverage Execute and manage the internal control testing calendar, coordinating evidence collection with control owners across IT, OT, and business functions Identify control deficiencies, document findings, and drive remediation to closure with defined timelines Develop control self-assessment (CSA) programs to extend assurance coverage without reliance solely on external audits Implement GRC tooling to automate evidence collection, control monitoring, and reporting (e.g., ServiceNow GRC, OneTrust, Drata, Vanta) 6. Policy & Standards Governance Maintain the policy architecture that underpins the compliance program: Own the information security policy library — drafting, reviewing, publishing, and retiring policies on a defined lifecycle cadence Ensure policies are mapped to applicable control frameworks and regulatory requirements Manage policy exception process — intake, risk assessment, approval, and time-bound tracking Coordinate policy acknowledgment and awareness campaigns with HR and business unit leadership CompetenciesFramework fluency — you can navigate ISO 27001, SOC 2, CIS Controls, and NIST without needing to look up the basics Controls precision — you write controls that are specific, testable, and defensible under audit scrutiny Risk judgment — you distinguish material risk from noise and help leadership make informed decisions, not just consume reports Operational credibility — you understand how manufacturing and OT environments work and design compliance requirements that are implementable on the plant floor Stakeholder influence — you earn trust with engineering, legal, finance, and operations by being practical, clear, and consistent Audit readiness — you maintain an organization's readiness posture year-round, not in a scramble before the auditor arrives Leadership Expectations Serve as the enterprise subject matter expert on information security compliance, risk management, and control frameworks Build a compliance culture that is embedded in business processes — not bolted on at audit time Influence cross-functional partners without direct authority — driving accountability for controls across teams that do not report to security Translate complex regulatory requirements into plain-language business guidance that operational leaders can act on Represent compliance and risk in vendor evaluations, M&A due diligence, and enterprise architecture discussions Maintain credibility that comes only from experience — auditors, regulators, and business leaders alike should view this role as the authority on Hexion's compliance posture Minimum QualificationsBachelor's degree in Information Security, Computer Science, Business Administration, or related field (Master's preferred) 7+ years of progressive experience in information security compliance, GRC, or risk management roles Demonstrated, hands-on experience managing ISO 27001 certification programs — including internal audits, SoA management, and external audit coordination Deep knowledge of ISO 27017 and ISO 27018 cloud security and privacy controls Practical SOC 2 Type II experience — control design, evidence collection, auditor management, and exception resolution Proficiency with CIS Controls (IG1 and IG2) including control mapping, gap assessment, and implementation road mapping Working knowledge of NIST 800-53 control families and the NIST Risk Management Framework Experience operating enterprise risk management programs — risk registers, treatment plans, risk reporting to leadership Ability to build and maintain control crosswalks across multiple frameworks (ISO, SOC 2, CIS, NIST) Strong written communication — able to produce policy documents, audit evidence packages, and executive risk reports Preferred QualificationsExperience with: OT/ICS environments — familiarity with IEC 62443, NIST SP 800-82, or industrial cybersecurity frameworks Manufacturing or chemical industry regulatory landscape (OSHA PSM, EPA RMP, REACH, or similar) Third-party risk management (TPRM) programs and vendor risk assessment methodologies GDPR, CCPA, or other data privacy regulatory frameworks Certifications (any of the following valued): CISM (Certified Information Security Manager) CRISC (Certified in Risk and Information Systems Control) ISO 27001 Lead Auditor or Lead Implementer CISSP, CCSP, or CGEIT SOC 2 practitioner credentials (AICPA TSC or equivalent) OtherWe are an Equal Opportunity, Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to gender, pregnancy, race, national origin, religion, age, sexual orientation, gender identity, veteran or military status, status as a qualified individual with a disability or any other characteristic protected by law.To be considered for this position candidates are required to submit an application for employment through our career site and, be at least 18 years of age. Any offer of employment will be conditioned upon successful completion of a drug test and background investigation, as well as authorization for the Company to conduct additional periodic background checks as required by the Chemical Facility Anti-Terrorism Standards (CFATS) or regulations adopted by the department of Homeland Security or other regulatory agencies. A prior criminal record is not an automatic bar to employment, and the Company will conduct an individualized assessment and reassessment, consistent with applicable law, prior to making any final employment decision.
$121.36k - $182.04k
Risk Manager - VNE67AWe’re determined to make a difference and are proud to be an insurance company... ...schedule (T, W, Th in office; M, F remote).Responsibilities:Monitor and analyze risk... ...Identity or Expression/Religion/AgeAbout Us | Our Culture | What It’s Like to Work Here...Remote workFull timeTemporary workWork at office$133k - $227k
...world. As a premier global asset management organization with more than 85... ...a spirit of generosity. Join us for the opportunity to grow... ...Role SummaryThe Senior Equity Risk Manager position is an important... ..., Colorado, Washington and remote workers$146,000.00 - $250,000....Remote workFull timeWork experience placementLocal areaWork from home1 day per week$101k - $203k
...nowhere like RSM.Position OverviewAs a Manager in RSM’s expanding Process Risk and Controls Practice, you will play... ...environments, including hybrid and remote workStrong verbal and written... ...current or prospective service in the US uniformed service; US Military/Veteran...Remote workFull timeWork experience placementInternshipLocal areaFlexible hours$69.4k - $158k
Risk, Issue, and Opportunity ManagerThe Opportunity:A Navy ERP transformation... ...program requires a risk manager who is passionate about... ...Washington Metro area.Work with us as we help modernize... ...their cameras on during meetings.Remote: If this position is listed as...Remote workFull timeContract workPart timeWork at officeLocal area$150k - $175k
...FamilyOperational RiskAbout Us At Transamerica, hard... ..., General Counsel, Risk, Internal Audit, Strategy... ...its Operational Risk Management (ORM) program, we are creating... ...Governance, Risk, and Compliance (GRC) technology, data,... ...(in-office, hybrid, remote) and operational needs....Remote workFull timeContract workWork at officeWorldwideRelocation package- ...where your ideas matter, join us as we lead the future of... ...WHAT YOU WILL DOThe Commercial Risk Analytics Manager provides risk analytics and... ...Corporate and field requests3. Compliance and Communication• Perform... ...4 on-site days and 1 remote day per week· Vehicle benefits...Remote workFull timeLocal areaImmediate startFlexible hours1 day per week
$85k - $95k
...forward to having you Hitch on and Prosper with us! Job Title Risk Claims Manager Department Compliance Job Status Exempt Compensation Direct... ...injuries. This position has the potential to be remote. Essential Job Duties Personally investigate...Remote work- ...Join to apply for the Manager - Project Risk role at Worley 1 day ago Be among... ...Management processes, ensuring compliance and continuous improvement.... ...career success. Join us to broaden your horizons, explore... ...Healthcare Risk Adjustment Analyst - Remote Houston, TX $102,890.67-$139...Remote workFull timeWork at officeImmediate start
$95k - $130k
...Get to Know Us Kafene is revolutionizing the lease-to-own space... ...headquarters, Wilmington, and remote talent across the globe-all united... ...About the Team Kafene's Risk team is a key driver of growth for the business. As a Risk Manager, you will report to the VP of...Remote workWork at officeFlexible hours- ...of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays... ...will have in this role:Market Risk Manager is responsible for the monitoring... ...manner to ensure the compliance with Risk Management policies... ...level within DTCC across all US locations. Actual salary is determined...Remote workWork experience placementFlexible hours
$212.7k
Job DescriptionDirector, US Strategic Risk, CCAR and Resolution Planning, Royal Bank of Canada... ...to rationalize various CCAR, Capital management, resolution planning policies, and standards... ...applying this knowledge to regulatory compliance or risk assessment.Developing,...Remote workFull timeWork experience placementMonday to Friday1 day per week- ...OneOncology's mission and vision. Why join us? This is an exciting time to join... ...Description: Role Summary: The Risk Manager is responsible for the day-to-day risk management... ...or attainment of CPHRM Certification within one year of hire. #LI-REMOTERemote workLocal area
$120k - $200k
...is seeking candidates for a Construction Risk Manager to implement risk management methodology... ...week between Jacobs offices/projects and remote locations enabling them to deliver their... ...Your application experience is important to us, and we’re keen to adapt to make every...Remote workFull time$123.57k - $214.1k
...looking to add a Senior Enterprise Project Risk Manager to our growing team in Seattle, WA. The... ...McKinstry Moves onsite gyms or reimbursement for remote workers. See benefit plan documents for... ...be considered if they possess current US Work Authorization, and do not require...Remote workVisa sponsorship$188.18k
Job DescriptionAssociate Director in Global Risk Management Group, Royal Bank of Canada (US), New York, NY: Prepare and oversee risk reporting to identify... ...review trading strategies and products to maintain compliance with risk standards. Monitor portfolio changes daily...Remote workFull timeWork experience placementMonday to Friday1 day per week$43.16 - $72.89 per hour
...Job Description Risk Manager Job Code: RM1505 ABOUT US We are ushering in a new era of healthcare... ...appropriate regulatory, legal, and compliance framework. Demonstrates a high... ...travel between campus buildings, remote facilities, and out of town as needed...Remote workHourly payWork experience placementWork at officeLocal areaShift work$98.7k - $164.5k
...you. Join McKesson's Global Risk Management Team as a Risk Manager... ...records, schedules, and related compliance materials. Support risk reporting... ...Location & Travel Remote role based in Florida (near... ...for employment, please contact us by sending an email to (...Remote workWork at office- ...DescriptionProSidian is a Management and Operations Consulting Services... ...services/solutions for Risk Management, Compliance, Business Process, IT... ...Contract: No Overtime Pay Basis Remote (within USA - W/ On-Site... ...a a department within the US Department of Energy [The Loan...Remote workFull timeContract workTemporary workFor contractorsWork at officeFlexible hours
$162k - $185k
...Director & Actuary (Charlotte, NC (Hybrid) or Remote) Where you’ll work: Our flexible, hybrid... ...Strong interpersonal and project/people management skills. Experience in valuation, pricing,... ...team building. We’d love for you to join us during those company‑wide and department‑...Remote workTemporary workWork at officeFlexible hours- ...innovators, and dreamers — and help us connect people and build... ...About the Team and RoleeBay’s Risk function fosters a marketplace... ...from fraud and abuse.Our team manages the strategy and foundational... ...performance, and market factors.Remote roles are not eligible for U.S...Remote workImmediate startVisa sponsorship
$61.9k - $141k
Cybersecurity Compliance and Risk ManagerThe Opportunity: The Cybersecurity Compliance and Risk Manager is a hybrid technical and compliance-focused... ...team members.Join us. The world can’t wait.You Have... ...cameras on during meetings.Remote: If this position is listed...Remote workFull timeContract workPart timeWork at officeLocal area$147.75k - $236k
...Job Summary As Director and Actuary within the Enterprise Risk Management (ERM) and Governance team in Corporate Actuarial and... ...objectives. Constantly pursue exceptional results that take us "next level." #LI-Remote Why Join The Standard? We have built an enduring legacy...Remote workLocal areaImmediate start$120k - $150k
...Risk Manager / Senior Risk Analyst Location: Atlanta, Orlando or Tampa (Hybrid) — Remote flexibility available for the right candidate Division : Dealer General Warranty... ...in a high-growth environment. Why Join Us? ~ Growth Path: Direct upward mobility into...Remote workContract work$165k - $275k
Executive Director - Market Risk Manager, Head of XVA Coverage, USFirm Risk Management - Market Risk DepartmentFirm Risk Management Firm Risk... ...adjustments. The team lead of the market risk XVA team in the US is accountable for setting risk direction, influencing business...Temporary work$146.4k - $235.38k
...intelligent agreement management, Docusign unleashes business... ...for a Senior Security Risk Manager to join our... ...Security Governance, Risk & Compliance (GRC) team. In this... ...between in-office and remote work. Access to an office... ...work. You can count on us to listen, be honest,...Remote workContract workWork at officeLocal area2 days per week$92.1k - $115k
...to apply for the Enterprise Risk Manager role at Subaru of America Continue... ...with Risk Management, Compliance, Information Security, Legal,... ...Area (Philly) Hybrid Role - Remote work 2 days per week (after 9... ...Internal Job Grade: M1) WHY JOIN US? In addition to competitive...Remote workFull timeWork at office2 days per week- ...You will apply your financial management and data analytics expertise to... ...actuarial, financial, and/or risk solutions Provides consulting... ..."hybrid" style, with a mix of remote, in-person and in-office... ...Tower, Southfield, MI, 48076, US Job Schedule Full time...Remote workFull timeTemporary workWork at officeLocal areaVisa sponsorshipWork visaFlexible hours
$115k - $160k
...portfolio of small clients or manages FAA resources on more complex... ...Guides teams on cost avoidance, risk and funding strategies and... ..."hybrid" style, with a mix of remote, in-person and in-office interactions... ...Avenue, Cleveland, OH, 44114, US Job Schedule Full time...Remote workFull timeTemporary workWork at officeLocal areaVisa sponsorshipWork visaFlexible hours$59.8k - $114.5k
...enhance our services. Join us at Crowe and embark on... ...client outcomes. In management at Crowe, you play a... ...confidence. The Third Party Risk Manager position will... ...security controls for compliance with applicable... ...preferred Open to remote work arrangements...Remote workLocal areaWorldwide$115k - $160k
...benefits ecosystem, have a strong project management background and be able to manage multiple... ...work in a "hybrid" style, with a mix of remote, in-person and in-office interactions dependent... ...One World Financial Center, New York, NY, 10281, US Job Schedule Full time...Remote workFull timeTemporary workWork at officeLocal areaVisa sponsorshipWork visaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Compliance and Risk Manager - US Remote. Be the first to apply!
- manager regulatory affairs Columbus, OH
- regulatory manager Columbus, OH
- compliance manager Columbus, OH
- compliance director Columbus, OH
- regulatory & compliance manager Columbus, OH
- regulatory affairs director Columbus, OH
- head compliance Columbus, OH
- operational risk manager Columbus, OH
- risk management manager Columbus, OH
- director credit risk Columbus, OH

