Donaldson Company, Inc. logo

Senior Engineer, Global Cybersecurity Governance, Risk and Compliance

Donaldson Company, Inc.

Bloomington, MNFull-time$86–111K/yrTracked 3w agoSeen in employer's feed 5 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$86–111K/yr
Location
Bloomington, MN
Schedule
Full-time
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

CISSPCISMCRISCCISABachelor's degree

Job overview

Donaldson Company, Inc. is hiring a Senior Engineer, Global Cybersecurity Governance, Risk and Compliance. The Senior Engineer, Global Governance, Risk & Compliance (GRC) executes and advances enterprise risk management and compliance assessment capabilities across global operations. This role leads risk tracking, assessment, and reporting processes to ensure consistent identification, prioritization, and communication of cybersecurity and regulatory risks. The Senior Engineer partners with IT, Privacy, Legal, Procurement, and business stakeholders to ensure alignment with internal policies, industry standards, and global regulatory requirements.

Key focus areas include Lead and maintain the enterprise GRC risk tracking framework, Coordinate global risk review meetings with IT, business, and operational stakeholders, and Assess, rate, and prioritize security risks against internal criteria, industry standards, and regulatory requirements.

Successful candidates bring Bachelor's In Cybersecurity, Information Technology, Risk Management, Or Related Field, 5+ Years IT And Information Security Experience, and English Communication Skills. Important skills include Enterprise GRC Risk Tracking Framework, Risk Assessment, Evaluating Controls, ISO 27001, NIST, and SOC 2. Preferred (not required): SOX 404, PCI DSS, MLPS, and Oracle Security.

Skills & qualifications

RequiredNice to have

Skills

Enterprise GRC Risk Tracking FrameworkRisk AssessmentEvaluating ControlsISO 27001NISTSOC 2CommunicationThird-Party Risk ManagementRegulatory ComplianceSOX 404PCI DSSMLPSOracle SecurityIT Policies and ProceduresIT AuditConsultingServiceNowArcherSupporting AuditsRegulatory InquiriesCertification ProgramsTISAXCMMC

Qualifications

Bachelor's in Cybersecurity, Information Technology, Risk Management, or Related Field5+ Years IT and Information Security ExperienceEnglish Communication SkillsCISSPCISMCRISCCISAGlobal or Multi-Regional Organizations Experience

Benefits

Medical Insurance
401(k) Match
Parental Leave

Full job description

Job Duties

Donaldson is committed to solving the world's most complex filtration challenges. Together, we make cool things. As an established technology and innovation leader, we are continuously evolving to meet the filtration needs of our changing world. Join a culture of collaboration and innovation that matters and a chance to learn, effect change, and make meaningful contributions at work and in communities.

The Senior Engineer, Global Governance, Risk & Compliance (GRC) is responsible for executing and advancing enterprise risk management and compliance assessment capabilities across global operations. This role leads risk tracking, assessment, and reporting processes to ensure consistent identification, prioritization, and communication of cybersecurity and regulatory risks.

Job Description

The position supports global initiatives related to IT and Information Security governance, risk, and compliance. This role is responsible for driving risk assessment execution, enhancing process maturity, and improving visibility of enterprise risk to leadership. The Senior Engineer partners with IT, Privacy, Legal, Procurement, and business stakeholders to ensure alignment with internal policies, industry standards, and global regulatory requirements.

Key Responsibilities

Lead and maintain the enterprise GRC risk tracking framework

Coordinate global risk review meetings with IT, business, and operational stakeholders

Assess, rate, and prioritize security risks against internal criteria, industry standards, and regulatory requirements

Compile and communicate risk posture to executive leadership and IT owners, ensuring appropriate awareness and accountability

Manage and facilitate risk assessments for new technologies, processes, and acquisitions

Improve risk assessment processes through alignment with IT architecture and Privacy

Lead compliance assessments against internal policies, standards, and procedures

Perform vendor and supplier security reviews, including execution of third-party risk assessments

Review third-party attestations (e.g., SOC2), support contract security provisions with Legal, and enhance vendor risk management processes and reporting

Minimum Qualifications

Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or related field and/or corresponding experience in the necessary knowledge and skills of the position

Minimum 5 years of professional-level IT and information security experience, with a focus on IT controls, risk management, data protection, and technology compliance

Experience conducting risk assessments and evaluating controls against frameworks such as ISO 27001, NIST, or SOC2

Communication skills (in English) in describing technical risks and issues to business and operational individuals

Strong understanding of third-party risk management and regulatory compliance requirements

Demonstrated ability to communicate technical risks to business and executive stakeholders

At least one relevant, current industry certification, such asCISSP, CISM, CRISC, or CISA, etc.

Preferred Qualifications

Experience in global or multi-regional organizations with diverse regulatory requirements

Familiarity with some of the following: SOX 404, PCI DSS, NIST 800-171, ISO 27001, MLPS, Oracle security, IT policies, and procedures

IT Audit/Consulting experience

Familiarity with GRC platforms (e.g., ServiceNow, Archer or equivalent)

Experience supporting audits, regulatory inquiries, or certification programs (e.g., ISO, TISAX, CMMC)

Any additional current industry certification(s), such as CISSP, CISM, CRISC, or CISA, etc.

Annual Salary Range: $86,200-111,000.Actual salaries will vary based on several factors including, but not limited to applicable work experience, training, education, performance.

Employee benefits are part of the competitive total rewards package that Donaldson Company, Inc. provides to you. Our comprehensive benefits program includes health benefits, retirement plan (401k), paid time away, paid leaves (including paid parental leave) and more.

Employment opportunities for positions in the United States may require use of information which is subject to the export control regulations of the United States. Hiring decisions for such positions are required by law to be made in compliance with these regulations. Applicants for employment opportunities in other countries must be able to meet the comparable export control requirements of that country and of the United States.

Donaldson Company has been made aware that there are several recruiting scams that are targeting job seekers. These scams have attempted to solicit money for job applications and/or collect confidential information, Donaldson will never solicit money during the application or recruiting process. Donaldson only accepts online applications through our Careers | Donaldson Company, Inc. website and any communication from a Donaldson recruiter would be sent using a donaldson.com email address. If you have any questions about the legitimacy of an employment opportunity, please reach out to [email protected] to verify that the communication is from Donaldson.

Our policy is to provide equal employment opportunities to all qualified persons without regard to race, gender, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity and/or expression, or other status protected by law.

Donaldson is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, age, gender, religion, national origin, genetic information, protected veterans status, sex, sexual orientation, gender identity, disability status, or any other status protected under federal, state or local laws.

Minimum Education Required

Bachelor Degree

Minimum Experience Required

5 - 20 years

Shift

First (Day)

Number of Openings

1

Public Transportation Accessible

Yes

Veterans Encouraged to Apply

No

Physical Required

Yes

Drug Test Required

Yes

Compensation

$86,200.00 - $111,000.00 / Annually

Postal Code

55431

Job Type

Full Time

Place of Work

On-site

Requisition ID

JR-27269

Job Benefits

Not specified

You've read the whole posting — now see how you match it.