We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Senior Engineer, Global Cybersecurity Governance, Risk and Compliance

Donaldson Company
$86,200-111,000
parental leave, 401(k), retirement plan
Jul 29, 2026

Donaldson is committed to solving the world's most complex filtration challenges. Together, we make cool things. As an established technology and innovation leader, we are continuously evolving to meet the filtration needs of our changing world. Join a culture of collaboration and innovation that matters and a chance to learn, effect change, and make meaningful contributions at work and in communities.

The Senior Engineer, Global Governance, Risk & Compliance (GRC) is responsible for executing and advancing enterprise risk management and compliance assessment capabilities across global operations. This role leads risk tracking, assessment, and reporting processes to ensure consistent identification, prioritization, and communication of cybersecurity and regulatory risks.

Job Description

The position supports global initiatives related to IT and Information Security governance, risk, and compliance. This role is responsible for driving risk assessment execution, enhancing process maturity, and improving visibility of enterprise risk to leadership. The Senior Engineer partners with IT, Privacy, Legal, Procurement, and business stakeholders to ensure alignment with internal policies, industry standards, and global regulatory requirements.

Key Responsibilities

  • Lead and maintain the enterprise GRC risk tracking framework
  • Coordinate global risk review meetings with IT, business, and operational stakeholders
  • Assess, rate, and prioritize security risks against internal criteria, industry standards, and regulatory requirements
  • Compile and communicate risk posture to executive leadership and IT owners, ensuring appropriate awareness and accountability
  • Manage and facilitate risk assessments for new technologies, processes, and acquisitions
  • Improve risk assessment processes through alignment with IT architecture and Privacy
  • Lead compliance assessments against internal policies, standards, and procedures
  • Perform vendor and supplier security reviews, including execution of third-party risk assessments
  • Review third-party attestations (e.g., SOC2), support contract security provisions with Legal, and enhance vendor risk management processes and reporting

Minimum Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or related field and/or corresponding experience in the necessary knowledge and skills of the position
  • Minimum 5 years of professional-level IT and information security experience, with a focus on IT controls, risk management, data protection, and technology compliance
  • Experience conducting risk assessments and evaluating controls against frameworks such as ISO 27001, NIST, or SOC2
  • Communication skills (in English) in describing technical risks and issues to business and operational individuals
  • Strong understanding of third-party risk management and regulatory compliance requirements
  • Demonstrated ability to communicate technical risks to business and executive stakeholders
  • At least one relevant, current industry certification, such asCISSP, CISM, CRISC, or CISA, etc.

Preferred Qualifications

  • Experience in global or multi-regional organizations with diverse regulatory requirements
  • Familiarity with some of the following: SOX 404, PCI DSS, NIST 800-171, ISO 27001, MLPS, Oracle security, IT policies, and procedures
  • IT Audit/Consulting experience
  • Familiarity with GRC platforms (e.g., ServiceNow, Archer or equivalent)
  • Experience supporting audits, regulatory inquiries, or certification programs (e.g., ISO, TISAX, CMMC)
  • Any additional current industry certification(s), such as CISSP, CISM, CRISC, or CISA, etc.

Annual Salary Range: $86,200-111,000.Actual salaries will vary based on several factors including, but not limited to applicable work experience, training, education, performance.

Employee benefits are part of the competitive total rewards package that Donaldson Company, Inc. provides to you. Our comprehensive benefits program includes health benefits, retirement plan (401k), paid time away, paid leaves (including paid parental leave) and more.

Employment opportunities for positions in the United States may require use of information which is subject to the export control regulations of the United States. Hiring decisions for such positions are required by law to be made in compliance with these regulations. Applicants for employment opportunities in other countries must be able to meet the comparable export control requirements of that country and of the United States.

Donaldson Company has been made aware that there are several recruiting scams that are targeting job seekers. These scams have attempted to solicit money for job applications and/or collect confidential information, Donaldson will never solicit money during the application or recruiting process. Donaldson only accepts online applications through our Careers | Donaldson Company, Inc. website and any communication from a Donaldson recruiter would be sent using a donaldson.com email address. If you have any questions about the legitimacy of an employment opportunity, please reach out to talentacquisition@donaldson.com to verify that the communication is from Donaldson.

Our policy is to provide equal employment opportunities to all qualified persons without regard to race, gender, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity and/or expression, or other status protected by law.

Applied = 0

(web-77cf7d65c7-jdxdg)