Plexus Corp. Logo

Plexus Corp.

Sr Manager - IT Governance, Risk, and Compliance

Posted One Month Ago
Be an Early Applicant
In-Office
Livingston, West Lothian, Scotland, GBR
Senior level
In-Office
Livingston, West Lothian, Scotland, GBR
Senior level
Leads the IT Governance, Risk, and Compliance team and oversees the cybersecurity GRC framework, policies, risk register, control effectiveness, audits, customer assessments, and third-party risk management. Owns the multi-year GRC roadmap, KPI/KRI reporting, continuous improvement, and control automation while developing team talent and strengthening the organization’s cybersecurity posture.
The summary above was generated by AI

About us

At Plexus, our vision is to help create the products that build a better world.  By embracing an innovative culture of excellence, we pride ourselves on designing, manufacturing and servicing some of the world’s most transformative products. From life-saving medical technology and mission-critical defense solutions to sophisticated industrial automation, we’re proud to partner with our customers to bring their complex ideas to market. 


Visit Plexus.com to learn more about our unwavering commitment to our vision. 


Living Our Values

With a vision rooted in the wellbeing and inclusive engagement of our team members, our customers, their end users and our communities, people are the heart of what we do and who we are. Our values unite and guide us in everything that we do. 


Our values include: Growing our People, Building Belonging, Innovating Responsibly, Delivering Excellence and Creating Customer Success. 


As part of our team, you’ll do impactful work within an inclusive environment where everyone works together to achieve extraordinary outcomes. You’ll be empowered to reach your full potential through managing your own personalised development plan and access to our learning and development programs.


Purpose Statement: Lead and manage the IT Governance, Risk, and Compliance (GRC) team, driving the development, maintenance, and execution of the GRC framework, ensuring compliance with global regulations and industry standards, and maturing the organization's overall cybersecurity posture.

Key Job Accountabilities:

  • IT Governance, Risk, and Compliance Program Leadership: 

    • Develop and maintain the Cybersecurity GRC framework, policies, standards, and procedures in alignment with regulatory requirements (e.g., ISO 27001, NIST CSF, Cyber Essentials +, SOC 2, GDPR, CMMC Level 2,3)

    • Develop, maintain, and socialize IT and cybersecurity policies, standards, and procedures across the organization. 

    • Oversee risk mitigation and the IT risk register, lead risk assessments.

    • Develop, and oversee IT control effectiveness. Experience with IT Control design review and validation.

    • Coordinate internal and external cybersecurity audits and assessments, tracking findings through remediation.

    • Oversee customer assessments and questionnaires.

    • Build, coordinate and oversee Third-Party risk management 

  • Strategic Program Management and Continuous Improvement: Lead the execution of the multi-year GRC Program roadmap, tracking and reporting on key performance indicators (KPIs) and key risk indicators (KRIs) to executive leadership. Drive continuous improvement in security controls and GRC processes by implementing best practices and automating controls where feasible.

  • Talent Management and Core Values: Responsible to exemplify and hold their team accountable to demonstrating the Plexus Core Values. Leader will focus on evaluating potential, driving succession planning, and ensuring their employees receive the development and coaching required to realize their full potential.

  • All GT leaders are accountable for upholding the organization's cybersecurity posture by adhering to security policies and procedures, actively participating in training, protecting data and systems, actively identifying and mitigating vulnerabilities, and promptly reporting any suspicious activity or potential security incidents.

Education/Experience Qualifications:

  • Bachelor’s Degree with 8 or more years of related experience is preferred. An equivalent combination of education and/or experience will be considered.

Other Qualifications:

  • Advanced leadership experience in dynamic, fast paced environments.

  • Advanced decision making, problem solving, and prioritization skills.

  • Advanced verbal and written communication skills.

  • Good interpersonal, communication and leadership skills; ability to motivate people and manage resources effectively and work with business partners to achieve goals.

  • Business acumen, knowledge and professionalism; understand how a business operates with the ability to develop and articulate the value proposition of a new process.

  • Functional knowledge in project management skills.

  • Must be self-motivated with the ability to work independently and in a team environment.

  • Knowledge of industry-standard security frameworks (e.g., NIST CSF, ISO 27001, CIS Controls) and regulatory requirements (e.g., SOX, SEC, GDPR, HIPAA, CMMC).

Preferred Qualifications:

  • Experience building an IT GRC function within a global organization.

  • Experience building an IT Third-Party Risk function within a global organization.

  • Industry recognized certifications such as the CRISC, CISA, CISSP, CISM, and/or CGEIT are preferred.

  • Experience in the use and administrative setup of GRC software platforms (e.g., Vanta, ServiceNow GRC).

Physical Requirements:

  • Professional office environment with suitable lighting, comfortable temperatures, and low noise level. May require prolonged periods of sitting at a desk, using a computer, and other office equipment. Minimal physical activity is generally involved, emphasizing the importance of good posture and ergonomic workplace arrangements.

Travel Requirements:

  • 5%

This document does not represent a contract of employment and is not intended to capture every possible assignment the incumbent could be asked to perform.


Your Rewards and Wellbeing

We believe in rewarding your contribution with a comprehensive package designed to support your life both inside and outside of work. 

  • Growth: Bespoke development plans and volunteer time off
  • Health: Private medical insurance, Employee Assistance Program and vision care
  • Wealth: Enhanced pension contributions, life assurance, and group income protection
  • Lifestyle: Electric Vehicle and Cycle to Work schemes, plus 33 days of annual leave

Application Process

At Plexus, we don't look for culture fit, we look for culture add. We value the unique perspectives you bring and review every candidate holistically, balancing professional experience, education and individual journey. 


Accessibility and Accommodations

As a Disability Confident employer, we recruit purely on the basis of skills and merit, ensuring an equitable process for everyone. We are committed to providing reasonable accommodations for individuals with disabilities or special requirements. If you require support during the application process, please contact us at [email protected] with your contact information and a description of your needs.


Note: This inbox is dedicated to accommodation requests; please note that application status updates cannot be provided via this address.


Similar Jobs

8 Hours Ago
In-Office
Entry level
Entry level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Plans and maintains E-7 aircraft maintenance forecasts and schedules in accordance with the Aircraft Maintenance Programme and operational needs. The role creates maintenance work packages, schedules parts and materials, coordinates recovery plans, supports continuing airworthiness processes, leads planning meetings, and manages stakeholder sign-off. It is embedded within a UK military CAMO team at RAF Lossiemouth and requires collaboration with maintenance organizations and the RAF.
Top Skills: GoldespGoldespMaintenance Planning SoftwareMS OfficeResolve
Yesterday
Easy Apply
Remote or Hybrid
United Kingdom
Easy Apply
Senior level
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Build and maintain Samsara's Cloud Governance Platform across AWS and GCP, focusing on cloud IAM guardrails, automated compliance controls, and software supply-chain security. Implement SAST/DAST and secure CI/CD patterns, design scalable, reliable systems, translate regulatory requirements into automated controls, collaborate cross-functionally, and own components end-to-end while mentoring teammates and shaping the roadmap.
Top Skills: AWSCi/CdCloud IamDastGCPGoPythonSastTerraform
Yesterday
Easy Apply
Remote or Hybrid
United Kingdom
Easy Apply
Senior level
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Lead go-to-market execution for Connected Equipment as an overlay specialist, partnering with Account Executives to generate pipeline, architect high-value enterprise deals, drive pilots/trials, inform product roadmap, build scalable sales frameworks, and travel to customer sites to advance solutions and close complex transactions.

What you need to know about the Edinburgh Tech Scene

From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account