**** IN OFFICE ONLY - NO RELOCATION - NO EXCEPTIONS ****
Information Security and Compliance Manager
Department
Information Technology
Reports To
Director of IT
Classification
Exempt / Full-Time
Location
Elkhart, IN
Frameworks
CMMC Level 2 (C3PAO), TISAX Level 3, SOX ITGCs, PCI-DSS, ISO 9001
Position Summary
This is a founding security role — our first dedicated information security hire, functioning as a de facto individual-contributor CISO. Reporting to the Director of IT, you will design, implement, and own the company's information security program and serve as the hands-on accountable owner across a portfolio of regulatory frameworks for a modest-sized discrete manufacturer as an internationally operating Business Unit of a larger conglomerate. You will do the work directly: writing policy, managing audits, maintaining evidence, and tracking compliance obligations — while communicating clearly with leadership and external auditors.
Key Responsibilities
Security Program
- Build and maintain the company ISMS: policies, standards, risk register, and control framework.
- Own the vulnerability management program, security architecture reviews, and Incident Response plan.
- Manage the vendor/third-party risk program, including security requirements in supplier contracts.
- Administer annual security awareness training and phishing simulation program.
- Report program status, open risks, and compliance calendar to the Director of IT.
CMMC Level 2 (C3PAO)
- Own the System Security Plan (SSP), POA&M, and CUI environment boundary documentation.
- Serve as primary contact for C3PAO assessments; maintain audit-ready posture year-round.
- Manage DFARS 252.204-7021 obligations and any subcontractor security flow-down requirements.
TISAX Level 3
- Own the full TISAX assessment lifecycle: scoping, VDA ISA gap analysis, remediation, and ENX audit coordination.
- Maintain the TISAX label and manage exchange requests; support OEM/Tier-1 customer verification requirements.
SOX IT General Controls
- Own ITGC design and evidence across logical access, change management, and computer operations.
- Serve as primary liaison to external financial auditors for ITGC walkthroughs and evidence delivery.
- Manage access certifications, privileged access reviews, and separation of duties controls.
PCI-DSS
- Own CDE scope, network segmentation documentation, and annual ROC/SAQ process with QSA.
- Maintain ASV scanning and penetration testing schedules; drive remediation of findings.
Contract Compliance Requirements Tracking (ISO 9001 Support)
- Maintain a contract requirements register capturing security, data handling, and compliance obligations from customer and supplier contracts — supporting the company's ISO 9001 QMS.
- Review incoming contracts for security and IT compliance obligations; communicate requirements to relevant teams and track fulfillment.
- Partner with the Quality Manager on internal audits where contract requirements intersect with IT controls.
Qualifications
Required
- 5+ years in information security and/or IT compliance.
- Experience as the primary security owner or sole practitioner — comfortable building, not just inheriting.
- Experience as an auditor or managed third-party auditors directly (C3PAO, QSA, or external financial auditors).
- Reviewed contracts for security/compliance obligations and translated them into actionable IT requirements.
- Proficiency with vulnerability management, SIEM, IAM/MFA, and endpoint protection tooling.
- Strong written communication: policy writing, SSPs, control narratives, and executive summaries.
Preferred
- Direct, hands-on experience managing preparation for at least two of: CMMC/NIST 800-171, TISAX, SOX ITGCs, PCI-DSS.
- Background in defense manufacturing, automotive supply chain, or regulated SME manufacturing.
- CISSP, CISM, CISA, or equivalent certification (or active pursuit within 12 months).
- CMMC Registered Practitioner (RP) or Certified Professional (CP).
- PCI-ISA or QSA credential.
- Experience with Microsoft 365 / Entra ID in a compliance-scoped environment.
- Familiarity with GRC platforms (Drata, Vanta, Archer, or similar).
- Exposure to ITAR/EAR requirements as they intersect with information security.
Who You Are
- Ownership mentality — you build the program, not just maintain a checklist.
- Practitioner first — comfortable writing the SSP and presenting to the CFO in the same week.
- Multi-framework fluency — you hold CMMC, TISAX, SOX, and PCI context simultaneously.
- Collaborative — you get compliance outcomes by working with operations, not around them.
- Detail-oriented — audit-ready records are your professional standard, not a pre-audit sprint andyou read agreements for business obligations as a matter of routine.
- Right-sized mindset — you know how to apply enterprise-grade thinking pragmatically in a SME.
Work Location: In person