Date: Aug 10, 2026 Location: Work Location Type: Remote Description: Why Valvoline Global Operations? At Valvoline Global Operations , we’re proud to be The Original Motor Oil , but we’ve never rested on being first. Founded in 1866, we introduced the world’s first branded motor oil, staking our claim as a pioneer in the automotive and industrial solutions industry. Today, as an affiliate of Aramco , one of the world’s largest integrated energy and chemicals companies, we are driven by innovation and committed to creating sustainable solutions for a better future. With a global presence, we develop future-ready products and provide best-in-class services for our partners around the world. For us, originality isn’t just about where we began; it’s about where we’re headed and how we’ll lead the way. We are originality in motion. Our corporate values— Care, Integrity, Passion, Unity, and Excellence —are at the heart of everything we do. These values define how we operate, how we treat one another, and how we engage with our partners, customers, and the communities we serve. At Valvoline Global, we are united in our commitment to: • Treating everyone with care. • Acting with unwavering integrity. • Striving for excellence in all endeavors. • Delivering on our commitments with passion. • Collaborating as one unified team. When you join Valvoline Global , you’ll become part of a culture that celebrates creativity, innovation, and excellence. Together, we’re shaping the future of automotive and industrial solutions. Job Purpose The Manager, IT Governance, Risk, and Compliance (IT GRC) is responsible for leading the organization's information security governance, risk management, compliance, and assurance programs. This role provides leadership for enterprise governance initiatives that strengthen the organization's security posture, ensure compliance with legal, regulatory, and contractual obligations, and support informed risk-based decision making across the enterprise. The Manager is responsible for the organization's Information Security Governance Framework, including governance policies, standards, procedures, compliance oversight, exception management, security awareness, privacy governance, third-party risk management, IT general controls, customer assurance activities, and continuous improvement initiatives. This role also serves as the primary leader for the organization's IT/OT cybersecurity maturity program, driving cross-functional collaboration, executive reporting, and ongoing improvement of the organization's security capabilities. As a strategic partner to Information Technology, Legal, Internal Audit, Enterprise Architecture, Privacy, and business leadership, the Manager ensures that governance processes are practical, measurable, and aligned with organizational objectives. The role leads customer assurance activities, including responses to customer security questionnaires, contractual security requirements, customer attestations, security assessments, and external assurance programs. The Manager also serves as the primary liaison with internal and external auditors, ensuring governance processes and controls effectively support regulatory, contractual, and business requirements. Success in this role requires a leader who can influence across organizational boundaries, communicate effectively with executive leadership, independently drive complex programs to completion, and balance business objectives with sound information security governance and risk management practices. How You Make an Impact (Job Accountabilities) • Governance Leadership and Program Management (30%) – Provide strategic leadership for the IT Governance, Risk, and Compliance (IT GRC) function, ensuring governance activities align with business objectives and the organization's information security strategy. Lead the IT/OT cybersecurity maturity program, including executive reporting, Steering Committee governance, Aramco reporting, and cross-functional coordination to drive continuous improvement across the enterprise. • Compliance, Audit, and Risk Management (20%) – Direct the organization's information security compliance, enterprise IT risk management, privacy governance, and IT general controls programs. Serve as the primary liaison with Internal Audit and external auditors, coordinating audits, managing remediation activities, maintaining the cyber risk register, and ensuring regulatory, contractual, and internal control requirements are effectively addressed. • Customer Assurance and Third-Party Risk (20%) – Lead customer assurance and third-party risk management activities by overseeing customer security questionnaires, contractual security requirements, customer attestations, security assessments, and third-party security reviews. Partner with Legal, Procurement, Sales, Privacy, and business stakeholders to ensure customer and supplier security requirements are evaluated, communicated, and managed through consistent governance processes. • Information Security Governance Framework (20%) – Own the organization's Information Security Governance Framework, including governance policies, standards, procedures, exception management, security awareness governance, compliance monitoring, and governance metrics. Ensure governance documentation remains aligned with regulatory requirements, industry frameworks, and evolving business objectives while driving continuous improvement across the governance program. • Team Leadership and Continuous Improvement (10%) – Lead, develop, and mentor the IT GRC team by establishing clear priorities, promoting professional growth, and fostering a culture of accountability, collaboration, and continuous improvement. Build strong relationships across Information Technology and business functions while driving operational excellence throughout the GRC organization. What You Bring to the Role (Job Qualifications / Education / Skills / Requirements / Capabilities) Education: o Minimum Required: Bachelor's degree in Information Security, Cybersecurity, Information Technology, Computer Science, Information Systems, Business Administration, Accounting, Finance, Engineering, or a related field. o Preferred: Master's degree in Business Administration (MBA), Information Security, Cybersecurity, Information Systems, or a related discipline. Work Experience: o Minimum of 8 – 10 years of progressively responsible experience in information security governance, risk management, compliance, information security, internal audit, enterprise risk management, or related disciplines. o Minimum of 3 – 5 years of experience leading teams, large cross-functional programs, or enterprise governance initiatives with accountability for strategic planning, execution, and stakeholder management. o Demonstrated experience developing, implementing, and maintaining enterprise governance, risk, and compliance programs within a global organization. o Experience managing information security governance, regulatory compliance, internal and external audits, IT general controls (ITGCs), risk assessments, and third-party risk management activities. o Experience partnering with Legal, Internal Audit, Information Technology, Enterprise Architecture, and business stakeholders to implement governance and compliance initiatives. o Experience supporting customer security questionnaires, contractual security requirements, customer audits, or other customer assurance activities is preferred. o Experience working with governance, risk, and compliance platforms such as ServiceNow GRC, OneTrust, Archer, MetricStream, or similar solutions is preferred. Licenses and Certifications – Professional certifications such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Data Privacy Solutions Engineer (CDPSE), or Certified Information Privacy Professional (CIPP) are preferred. Project Management Professional (PMP) or equivalent program management certification is also desirable. Competencies Desired • Comprehensive knowledge of information security governance, risk management, compliance, and industry frameworks, including NIST Cybersecurity Framework (CSF), ISO 27001, COBIT, and related best practices. • Strong understanding of regulatory, contractual, and customer information security requirements, including privacy, third-party risk, IT general controls (ITGCs), and audit practices. • Demonstrated ability to develop, implement, and continuously improve enterprise governance programs, policies, standards, and procedures. • Exceptional written and verbal communication skills, including the ability to communicate complex information clearly and effectively to executive leadership, auditors, customers, and non-technical stakeholders. • Proven ability to influence cross-functional teams, build consensus, and lead enterprise initiatives without direct authority. • Strong program and project management skills, with the ability to coordinate multiple initiatives, manage competing priorities, and deliver results in a dynamic environment. • Excellent analytical, critical thinking, and risk-based decision-making skills, with the ability to identify dependencies, assess business impact, and develop practical, well-supported recommendations. • Demonstrated initiative, accountability, and ownership, with the ability to independently drive work to completion, proactively communicate risks and issues, and follow through on commitments. • Strong leadership and people development skills, including coaching, mentoring, performance management, and fostering a culture of continuous improvement. • Experience with governance, risk, and compliance technologies, workflow automation, and metrics-driven program management. • Ability to build and maintain effective working relationships with internal stakeholders, customers, auditors, regulators, vendors, and other external partners. • Ability to balance business objectives with sound information security governance and risk management practices while maintaining a customer-focused mindset. Working Conditions / Physical Requirements / Travel Requirements • Working Conditions / Physical Requirements: Remote/Office Setting • Travel Requirements: Up to 10% Valvoline Global is an equal opportunity employer . We are dedicated to fostering an environment where every individual feels valued, respected, and empowered to contribute their unique perspectives and skills. We strictly prohibit discrimination and harassment of any kind, regardless of race, color, religion, age, sex, national origin, disability, genetics, veteran status, sexual orientation, gender identity, or any other legally protected characteristic. We are committed to ensuring accessibility throughout our recruitment process. If you require a reasonable accommodation to participate in any stage of the recruitment or selection process, please contact us at:. • Email : [email protected] This contact information is solely for accommodation requests. For inquiries about application status, please use the appropriate channels listed in your application materials. Are You Ready to Make an Impact? At Valvoline Global, we’re looking for passionate and talented individuals to join our journey of innovation and excellence. Are you ready to shape the future with us? Apply today. Requisition ID: 2551
Compliance Quality Assurance Manager (US)
Td
Manager - Compliance
American Express
Regional Safety, Compliance, and Loss Prevention Manager
Stord
Environmental Compliance Project Manager
WM
Compliance Manager – Power Markets (Landfill Gas Generation)
WM
Security Compliance Program Manager (Contract)
Kaizen Labs