Manager, Cybersecurity Policy, Risk & Governance
$110k - $130kHowmet Corporation
- Job Identification
116015 - Job Category
Information Technology - Posting Date
05/05/2026, 02:09 PM - Locations 201 Isabella Street, Pittsburgh, PA, 15212, US (Hybrid)
- Job Schedule
Full time - Remote Work Schedule Availability?
Partially Remote - LinkedIn Recruiter Tag
#LI-MC1 - Export-Controlled Data
No
Responsibilities
Howmet Aerospace Inc. has an exciting opportunity to join our dynamic Cybersecurity team as a Manager, Cybersecurity Policy, Risk & Governance . This position will report directly to the Chief Information Security Officer (CISO). This strategic role is responsible for leading the development, implementation, and oversight of our Cyber Policy, Risk & Governance strategy related to evolving cyber regulations and laws.
This role requires deep technical expertise, strong leadership, and the ability to translate complex regulatory and security requirements into scalable, business-friendly solutions. As a subject matter expert in Cyber Policy, Risk & Governance, you will play a pivotal role in ensuring that cybersecurity controls are effectively designed, implemented, and communicated across the organization to protect Howmet Aerospace's global information assets.
Major activities/key challenges:
This position does the following in accordance with all applicable International, Federal, State and local laws/regulations and the Company's policies, procedures and guidelines:
-
Align cybersecurity governance strategy with Howmet's strategic priorities, business strategies, and standard processes.
Partner with Global Information Services (GIS) directors/teams and functional groups (HR, Legal, Privacy, Trade Compliance, EHS, etc.) to standardize and evolve cybersecurity posture.
Consult with Business Unit (BU) and Functional Area Leaders to assess governance and risk needs, delivering impactful programs in policy development, training, mentorship, and risk management.
Lead the global governance and risk management process to support cybersecurity maturity and performance alignment.
Build, lead, and mentor a high-performing cyber governance & risk team, fostering innovation and accountability.
Design and deliver training, communications, and tools to support cybersecurity initiatives across GIS and BU teams.
Develop and implement change management strategies to support adoption of new cybersecurity policies and practices.
Provide organizational maturity assessments and interventions to enhance cybersecurity capabilities.
Monitor industry trends, conduct benchmarking, and recommend solutions aligned with Howmet's cybersecurity strategy.
Collaborate with CIS teams to align business processes and technology platforms for optimal governance and risk outcomes.
Support the CISO in strategic planning, compliance certifications (e.g., CMMC, ISO 27001), and regulatory interpretation (e.g., NIST 800-171, NIS2, UK Cyber Essentials).
Create and manage procedures, work instructions, and contribute to corporate cybersecurity policies and standards.
Track and report performance metrics to guide program investments and continuous improvement.
Oversee internal teams and external vendors to meet governance and risk objectives within budget and timelines.
Represent CIS in cross-business planning initiatives and support CISO in governance-related audits, customer inquiries, and leadership engagements.
Serve as a leadership proxy for the CISO when required.
Essential knowledge, skills, and abilities:
Proficiency in Microsoft Office Suite (Word, Excel, PowerPoint, Visio, Project, Outlook, SharePoint).
Expertise in designing and delivering GRC programs and cybersecurity governance frameworks.
Strong understanding of global cybersecurity laws, regulations, and standards (e.g., NIST CSF & RMF, ISO 27001, TISAX, AirCyber).
Ability to interpret and apply regulatory requirements to policy development and risk mitigation strategies.
Skilled in risk tracking and analysis using tools such as risk registers.
Strong analytical and decision-making capabilities based on data and cybersecurity trends.
Experience in incident response planning and governance issue resolution.
Exceptional communication and presentation skills for both technical and non-technical audiences.
Proven ability to influence and collaborate across all organizational levels without direct authority.
Experience presenting to executive leadership and boards.
Deep understanding of IT systems, infrastructure, and cybersecurity technologies.
Demonstrated leadership, problem-solving, and change management skills in a global, decentralized environment.
Qualifications
Basic Qualifications:
Bachelor's degree in business administration, Cybersecurity, Management of Information Systems (MIS), or a related field from an accredited institution.
At least 5 years of experience leading cybersecurity programs, including 2+ years in cyber
governance and risk management in a global organization.
At least one Industry certifications such as CISSP, ISO 27001, CMMC CCP or equivalent.
Hands on experience implementing successful ISO27001 certifications
-
Must be legally authorized to work in the United States without sponsorship.
Preferred Qualifications:
Juris Doctor (JD) in Cyber Law, Intellectual Property Law, or related governance field.
Advanced certifications: CMMC CCA, CISM, ISO 27001 Lead Implementer, ITIL, CRISC, GRC, or CISO-level credentials.
Experience leading global cyber governance programs in a complex enterprise environment; preferably in a manufacturing environment
Work Location & Travel Requirements
This position follows a hybrid or remote work model based on the candidate's proximity to a Howmet Aerospace facility:
- Candidates located within 65 miles of a Howmet facility will be expected to work a hybrid schedule aligned with local site expectations.
- Candidates located outside of a commuting distance may be eligible for remote work, with predetermined travel to the Pittsburgh Howmet Corporate Center (typically one week per month or as business needs require).
- Outside of remote and hybrid location travel schedules, additional travel up to 25% may be required.
Howmet Aerospace reserves the right to modify work location expectations based on evolving business needs
Salary Range: $110k - $130k/year approximation (actual compensation is subject to variation due to factors such as education, experience, skillset, and/org. location).
,About Us
Howmet Aerospace Inc. (NYSE: HWM), headquartered in Pittsburgh, Pennsylvania, is a leading global provider of advanced engineered solutions for the aerospace and transportation industries. Our primary businesses focus on jet engine components, aerospace fastening systems, titanium structural parts and forged wheels. With $8.3 Billion in revenue in 2025, our products play a crucial role in enabling fuel efficiency and lightweighting, contributing to our customers' success and making a positive impact on the world. To learn more about the way Howmet Aerospace Inc. is advancing the sustainability of our customers, markets, and communities where we operate, review the 2025 Environmental Social and Governance report at Follow: LinkedIn, Twitter, Instagram, Facebook, and YouTube.
Equal Opportunity Employer:
Howmet is proud to be an Equal Employment Opportunity employer. We are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or other applicable legally protected characteristics.
If you need assistance to complete your application due to a disability, please email View email address on click.appcast.io
$110k - $130k
...Howmet Aerospace Inc. has an exciting opportunity to join our dynamic Cybersecurity team as a Manager, Cybersecurity Policy, Risk & Governance. This position will report directly to the Chief Information Security Officer (CISO). This strategic role is responsible for...PolicyRiskWork at officeLocal areaRemote work- ...be considered.** Position Title: Manager of IT Governance Business Unit: Technology Reports... .... The position develops and maintains policies and procedures to support the business... ...and the accountability to serve as risk managers for their businesses by understanding...PolicyRiskWork at officeLocal areaRelocation
$110k - $130k
...Position Title: Manager of IT Governance Business Unit: Technology Reports to:... .... The position develops and maintains policies and procedures to support the business... ...responsibility and the accountability to serve as risk managers for their businesses by...PolicyRiskFull timeWork at officeRelocation package- ...Citizen(No third party involvement) Must-Haves : GRC, security data governance - hands-on knowledge of COBIT, ITIL, or ISO 27001 security governance policies and procedures conducting security risk assessments or compliance audits experience working with regulatory...PolicyRiskWork visa
$112k
...Sr Manager, InfoSec Governance Risk and Compliance (GRC)(Pittsburgh, Pennsylvania, US) Founded in 2000, Ivalua is a leading global provider of cloud... ...chain risks. Develop, maintain, and enforce InfoSec policies, standards, and plans. YOUR PROFILE If you have the...PolicyRiskWork at officeWorldwide- ...into coordinated plans, clear governance, and measurable results. The... ...priorities and will report to the Managing Director, Enterprise Clinical... ..., schedule, dependencies, risks, decisions, outcomes, and... ...Cigna Group has a tobacco-free policy and reserves the right not to...PolicyRiskWork at officeLocal areaWork from home
- ...Compliance Program. These activities include policy and procedure governance, regulatory and legislative research... ...maintenance, tracking, and records management. Monitor Regulatory Activity... ...and containing compliance risks and proactively fostering a compliance...PolicyRisk
- ...enterprise standards for vSAN storage policies, service tiers, workload placement, capacity governance, and performance baselines.... ...recoverability, including management, networking, observability, and... ...goals. Review and approve high-risk technical changes impacting storage...PolicyRiskMonday to FridayShift work
- ...business strategy, data strategy, cybersecurity, and digital transformation... ...4 capabilities are: Management Consulting – Business... ...security awareness and proactive risk management. Acting as a... ...engagements, including governance, risk management, stakeholder...RiskFull timeWork at officeLocal areaWorldwideWork visa
$142.6k - $261.5k
...- Blackline Implementation - Manager - Tech Consulting You will... ...Automation, Controls & Governance agenda by supporting business... ...with an emphasis on quality and risk management. Your ability to engage... ...complex problems Modify policies and establish procedures...PolicyRiskWork experience placementSummer holidayFlexible hoursShift work- ...team leverages methodologies, governance and systems that are... ...You will be responsible for managing, coordinating and administering... ...cost, schedule and commercial risks and implement measures to mitigate... ...Manager Review insurance policies provided by Clients for compliance...PolicyRiskContract workFor subcontractorLocal areaFlexible hours
$154k - $225k
...Senior Manager Product Cybersecurity COE Eaton's Corporate Sector division is currently seeking a Senior Manager Product Cybersecurity... ...strategy by embedding cybersecurity requirements, risk management, and governance across the full product lifecycle. The role partners...RiskRelocationVisa sponsorship- ...Job Title: Senior Manager Product Cybersecurity COE Location: Pittsburgh, PA (Hybrid - 3 Days Onsite / 2 Days Remote) Employment... ...Secure by Design methodologies Cybersecurity governance Risk management frameworks Product lifecycle security...RiskFull timeRemote work
- ...Role Summary The General Manager of Economic Development is a... ...CrossFunctional Execution & Governance Partner closely with... ...development pipeline Strategic risks and tradeoffs Alignment... ...Economics, Engineering, Public Policy, or related field. ~10+...PolicyRiskLocal area
- ...specializes in the care and management of patients receiving treatment... .... In support of the shared governance model present at Forbes Regional... ...creating a culture in which risk taking is not only safe but... ...physician, nurse and hospital policy including patient and family....PolicyRiskFor contractorsLocal areaShift work
$154k - $225k
...environment through the use of power management technologies and services. We... ...: Lead and develop a global cybersecurity organization supporting company... ...identify and mitigate risk. Establish and maintain cybersecurity governance, operating models, and metrics...RiskFull timeRelocation package- ...individual will focus on software process governance, quality analysis, and audit readiness,... ...change control Identify process gaps, risks, and nonconformances and drive corrective... ...review Insight Global's Workforce Privacy Policy: Required Skills & Experience...PolicyRisk
- ...team leverages methodologies, governance and systems that are... ...Construction Coordinator / Construction Manager to join our Project Delivery... ...procedures within corporate policies and procedures as... ...of commercial contracts and risk Ability to operate independently...PolicyRiskFor contractorsWork at officeLocal areaRelocationFlexible hours
- ...KPMG is currently seeking a Manager, Microsoft Purview Ops Lead to... ...efficiently to provide data governance, protection, and compliance services... ..., labeling, and sensitivity policies to ensure compliance with... ...effectively to manage data risk, discover and classify sensitive...PolicyRiskH1bLocal area
$64.97k - $149.88k
...Senior Data / Governance Analyst We currently have a career opportunity... ...in data lineage, metadata management, and data quality controls.... ...with business, technology, and risk teams to uplift end-to-end... ...company has facilities. This policy applies to all terms and conditions...PolicyRiskFull timeWork at officeLocal area- ...and its subsidiaries controls and governance processes, as designed and operated by management, are adequate and functioning.... ...managerial processes to identify risks, areas for improvement, and to... ...processes by reviewing manuals, policies, reports, financial statements,...PolicyRiskFor contractorsWork at officeLocal area
$55k - $134.55k
...Owner II PNC's Enterprise Data Governance organization, you will be... ...and stakeholders across Data, Risk, Technology, and Governance to... ...governance, and business needs. • Manage and prioritize the product... ..., IT Standards, Procedures & Policies, Managing Multiple Priorities...PolicyRiskFull timeTemporary workPart timeWork experience placementWork at officeShift work- ...meaningful interaction at all levels of management. This is an excellent opportunity for... ...a strong foundation in internal audit, risk management, and SOX compliance while contributing... ..., internal controls, compliance, and governance processes. The Internal Audit &...RiskInternshipWork at officeLocal area
- ...impact in the following ways: Support Wealth Management Tax and frontoffice team members with tax-... ...accuracy across tax-related processes Manage risk by ensuring compliance with internal procedures and policies Identify and recommend process improvements to...PolicyRisk
- ...Compliance & Control to join our Risk & Compliance team. This role... ...in the following ways: Manages compliance efforts for the... ...relate to complex regulatory and policy requirements, program and... ...contact with outside regulators, government officials, and senior...PolicyRisk
- ...Senior Vice President, Technology Third Party Governance We're seeking a future team member for... ...and vendors across Treasury and CIO Manage strategic vendor relationships, including platforms supporting portfolio, risk, and balance sheet management (e.g., Aladdin...Risk
- ...and for your future. Position Title:Manager of Enterprise Risk Systems Business Unit:Risk - Operational... ...for the corporation's Enterprise Governance, Risk, and Compliance platform, delivering... ...Indicators, Monitoring and Testing, Policy Management, Exam Management, and Risk...PolicyRiskContract workWork at office
- ...into operational controls Managing audit ready evidence, and partnering... ...with business, legal, and risk teams to ensure sustained... ...implement, and maintain internal policies, procedures, and... ...security, particularly within government contracting or financial industry...PolicyRiskContract workFor subcontractor
- ...Cybersecurity Information System Security Officer (ISSO)... ...The following reflects management's definition of essential... ...Support Risk Management Framework (... ...artifacts Support governance, risk, and compliance... ...with DoD cloud security policies and FedRAMP requirements...PolicyRisk
$90k
...Job Title: Risk Management Specialist Location: Pittsburgh, PA Salary: Up to $90,000 annually depending on experience Benefits... ...carrier partners to analyze exposures, prepare renewals, manage policy administration, and ensure a high level of service throughout...PolicyRisk
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Manager, Cybersecurity Policy, Risk & Governance. Be the first to apply!
- risk management specialist Pittsburgh, PA
- risk management associate Pittsburgh, PA
- director credit risk Pittsburgh, PA
- risk management manager Pittsburgh, PA
- head of risk management Pittsburgh, PA
- operational risk manager Pittsburgh, PA
- director of risk management Pittsburgh, PA
- public policy Pittsburgh, PA
- environmental policy intern Pittsburgh, PA
- vice president public policy Pittsburgh, PA


