This senior individual contributor position is responsible for scaling Valmont Industries' Governance, Risk & Compliance (GRC) program through engineered automation, advanced AI tooling, and data-driven risk visibility. The role bridges deep GRC subject matter expertise with hands-on engineering capability. It is designed to build and own end-to-end automated processes including evidence pipelines, real-time control checks, automated workflows, risk data pipelines, and operational dashboards, leveraging AI-enabled tools to drive efficiency, accuracy, and scalability across the GRC function. The role also serves as the primary program lead for AI security and risk management at Valmont, integrating AI governance controls into enterprise GRC processes and partnering with Legal, Internal Audit, and business unit stakeholders to confirm requirements and create scalable, independently operable systems that improve control coverage, audit readiness, and risk posture across all IT disciplines including OT environments.
Job Description
Primary Responsibilities:
- Maintain the IT risk inventory to track identified issues and risks, including risk acceptances and remediation plans; provide governance, oversight, and reporting on issues and risks.
- Lead the planning, scoping, execution, and documentation of risk management activities associated with technology and technology-related risks including cybersecurity and OT environments.
- Identify, validate, and assess security risks; develop, socialize, and guide engineering and business teams through risk treatment plans.
- Design and build automation for GRC processes including evidence collection, control validations, real-time control effectiveness checks, and broader GRC workflows such as risk register, Third Party Risk assessments, and enterprise systems controls definition.
- Design data pipelines that aggregate and normalize risk-relevant data across enterprise systems to support KRIs, control-maturity insights, and risk dashboards.
- Automate repeatable GRC processes including compliance monitoring, reporting, and evidence loading across multiple data inputs and information systems; set up control attestation and evidence automation workflows and build KRI/KPI scorecards across business units.
- Lead collaboration efforts with IT value stream owners to define and implement effective control activities, processes, and standards and document supporting policies and procedures.
- Consult and assist IT Risk and Control Owners in the planning, design, implementation, operation, maintenance, and remediation of control activities and supporting requirements such as policies, standards, processes, and system configurations.
- Support incident response from a compliance perspective, contributing to analysis, containment, and mitigation strategies; coordinate with Legal on breach notification and regulatory reporting requirements.
Additional Responsibilities:
- Lead security reviews for proposed AI technologies, evaluating risks related to data handling, model behavior, and system integration, aligned to NIST AI RMF and ISO 42001.
- Integrate AI-specific security controls into enterprise governance processes such as procurement, vendor risk management, and software change control.
- Establish measurable indicators of AI risk posture and effectiveness of AI security controls.
- Build dashboards and operational views that present risk trends, control-maturity indicators, and audit-readiness status.
- Serve as the automation SME for troubleshooting, system design, and expanding capabilities; partner with GRC team members to validate expected behavior and troubleshoot gaps.
- Develop and maintain repeatable automation patterns to support consistent vendor onboarding and third-party risk assessments across the organization.
- Contribute to the development and publication of information security policies, standards, and guidelines related to AI and emerging technologies.
Required Qualifications of Every Candidate (Education, Experience, Knowledge, Skills and Abilities):
- Minimum 5 years of experience in information security, risk management, or GRC, with at least 2 years of hands-on experience in security engineering, automation development, AI security, or data security.
- Working knowledge of GRC and cybersecurity frameworks including SOC 2, NIST CSF 2.0, CIS Controls v8, and ISO 27001; familiarity with AI governance frameworks such as NIST AI RMF and ISO 42001; and practical understanding of the Three Lines of Defense model as applied to IT control ownership and risk accountability.
- Experience performing cybersecurity risk assessments, business impact analysis, planning, and reporting; foundational understanding of Risk Management concepts and principles.
- Demonstrated data and automation skills including experience with Power BI, SQL, or Python for data preparation, transformation, and analytics.
- Hands-on experience with one or more GRC automation platforms such as Vanta, Anecdotes, 6clicks, or AuditBoard, including configuring questionnaires, workflows, object models, APIs, and role-based dashboards; experience with ServiceNow IRM/GRC, Jira, and cloud platforms such as Azure or GCP is strongly preferred.
- Must be available for U.S. time zone meetings; flexible/hybrid schedule with ability to work in the office on a regular basis.
- High level of initiative and self-motivation; self-driven and capable of managing priorities independently while maintaining clear communication and alignment.
- Excellent written and verbal communication skills; able to convey complex topics to diverse audiences including executives.
- Problem-solving, critical thinking, and analytical ability; comfortable working in evolving environments and bringing structure to new or ambiguous domains.
- Ability to work independently and as part of a team in a fast-paced, dynamic environment.