Are you someone who is passionate, motivated, and driven to make a difference? If so, MSA Safety is the perfect fit for your career.
At MSA, SAFETY is who we are AND it is what we do. We are a purpose-driven company committed to deploying innovation and technology to deliver on our Mission to help protect people and assets all around the world. We continue to be relentless in our pursuit of solving our customers greatest problems so they can go home safe each and every day.
Are you in? Read on for more details about this particular role.
Responsibilities:
ISMS Ownership & ISO 27001
Own and maintain the Information Security Management System (ISMS), ensuring alignment with ISO 27001:2022 requirements and organizational objectives
Lead and coordinate internal and external ISO 27001:2022 audits, including audit planning, execution, and follow-up
Conduct gap analyses, risk assessments, and risk treatment planning in line with ISO 27001 Annex A controls
Develop, review, and maintain information security policies, standards, and procedures
Multi-Framework Compliance
Drive and coordinate compliance activities across SOC 2 Type II, including control documentation, evidence collection, and readiness reviews in preparation for external assessments
Support CMMC 2.0 Level 2 readiness and compliance, including control implementation guidance aligned with NIST SP 800-171 and coordination for third-party assessment organization (C3PAO) engagements
Maintain working knowledge of NIST SP 800-171 requirements and their relationship to CMMC, supporting Controlled Unclassified Information (CUI) scoping and handling requirements
Ensure compliance activities reflect applicable regional data protection obligations, including GDPR and other jurisdiction-specific requirements relevant to global operations
Maintain a cross-framework control mapping to identify overlaps, reduce duplication of effort, and ensure consistent control coverage across ISO 27001, SOC 2, CMMC, and NIST
Global Governance & Stakeholder Engagement
Serve as a key point of contact for external certification bodies, auditors, and regulatory inquiries
Report on the state of the ISMS, compliance posture, and key risk indicators to senior management across global business units
Contribute to security awareness programs and training initiatives, adapting content for regional and cultural relevance where needed
Collaborate with cross-functional and geographically distributed stakeholders to embed security and compliance requirements into business processes
Third-Party & Engineering Collaboration
Support and collaborate with the Third-Party Risk Management (TPRM) function, providing GRC expertise on vendor risk assessments and due diligence processes
Work closely with the software development function to integrate compliance requirements into the Secure Software Development Lifecycle (SSDLC)
Qualifications:
Required Skills / Knowledge / Abilities
Deep understanding of ISO 27001:2022 and associated standards (e.g., ISO 27002), including practical ISMS management experience
Solid grasp of GRC methodologies, control frameworks, and structured risk assessment practices
Working knowledge of SOC 2 (Trust Services Criteria) and readiness or audit support experience
Working knowledge of CMMC 2.0 and/or NIST SP 800-171, including their application to CUI environments and U.S. federal compliance obligations
Familiarity with GDPR or equivalent data protection regulations as they apply to global enterprise operations
Experience with cross-framework control mapping across two or more of the above frameworks
Excellent written and verbal communication skills — ability to translate complex compliance topics for both technical and non-technical audiences across different cultural and organizational contexts
Proven ability to work independently and drive compliance initiatives with minimal supervision in a globally distributed team environment
Preferred Skills
Hands-on experience with SOC 2 Type II audit support and evidence collection
Direct involvement in CMMC readiness activities or C3PAO-facilitated assessments
Knowledge of cloud security controls, particularly in AWS and Office 365 environments
Familiarity with AI-enhanced GRC tooling and compliance automation approaches
Understanding of TPRM frameworks, vendor risk methodologies, and associated tooling
Familiarity with SSDLC principles and their integration with compliance requirements
Experience working across multiple time zones and jurisdictions in a multinational organization
Education & Experience
Required
Bachelor's degree in Computer Science, Information Security, or a relevant field
Demonstrated experience leading or supporting ISO 27001 certification or re-certification audits
Experience developing and implementing security policies and controls across multiple frameworks
Experience conducting structured risk assessments and managing risk treatment plans in complex, multi-jurisdictional environments
Preferred
ISO 27001 Lead Auditor or Lead Implementer certification (e.g., PECB, BSI, or equivalent)
Master's degree in Computer Science, Information Security, or a relevant field
Additional certifications such as CISM, CISA, CISSP, or ISO 27005 Risk Manager
Certifications or formal training in CMMC, NIST, or SOC 2 methodologies
Experience working in or supporting regulated industries subject to U.S. government compliance requirements
#LI-KH2
#LI-HYBRID
Numbers & Facts
Location
Cranberry Township, Pennsylvania
Skills
Amazon Web Services (AWS)unmatched
Artificial Intelligence (AI)unmatched
Auditingunmatched
Automationunmatched
British Standards Institute (BSI)unmatched
Business Processesunmatched
CISA - Certified Information Systems Auditorunmatched
CISM - Certified Information Security Managerunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Computer Scienceunmatched
Cross-Functionalunmatched
Document Managementunmatched
Due Diligenceunmatched
Gap Analysisunmatched
Government Requirementsunmatched
ISO (International Organization for Standardization)unmatched
Information Technology & Information Systemsunmatched
Information/Data Security (InfoSec)unmatched
International Businessunmatched
International Operationsunmatched
Leadershipunmatched
Machine Toolunmatched
Maintain Complianceunmatched
Policy Implementationunmatched
Presentation/Verbal Skillsunmatched
Regulationsunmatched
Regulatory Complianceunmatched
Resolve Customer Issuesunmatched
Riskunmatched
Risk Analysisunmatched
Risk Managementunmatched
Security Monitoringunmatched
Software Developmentunmatched
Software Development Lifecycle (SDLC)unmatched
Technical Deliveryunmatched
Treatment Planunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
Writing Skillsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.