Compliance & Risk Management Specialist
Location
Dearborn, Michigan (Local Candidates Only)
Schedule
Monday – Friday | Standard Business Hours
Type
Contract | W2 Only
Pay Rate
$48.00 – $52.00/hour W2
Work Authorization
Must be able to work on a W2 basis. No C2C, or third-party vendors.
Relocation
Relocation assistance is not available. Local candidates only.
Duration
12 Month Long Contract (Open-ended)
Summary
We are seeking a Compliance & Risk Management Specialist to support cybersecurity governance, cryptographic key management, supplier compliance, and risk management initiatives within a complex automotive environment. This role serves as a key liaison between cybersecurity, engineering, manufacturing, procurement, suppliers, and infrastructure teams to ensure cybersecurity requirements are implemented and maintained throughout the vehicle development and manufacturing lifecycle.
The ideal candidate will have a strong background in cybersecurity compliance, PKI, key management systems, supplier audits, risk management, and security governance. Experience supporting embedded systems, connected products, or automotive cybersecurity programs is highly preferred.
Key Responsibilities
- Define cybersecurity and cryptographic requirements for vehicle electronic control units (ECUs) and connected systems.
- Establish and manage security controls including encryption standards, key lengths, certificate policies, rotation schedules, expiration requirements, and access controls.
- Support and manage Public Key Infrastructure (PKI) and Key Management Systems (KMS) environments.
- Ensure secure generation, distribution, storage, and lifecycle management of cryptographic keys and certificates.
- Partner with engineering teams to integrate cybersecurity controls into products and manufacturing processes.
- Conduct supplier cybersecurity audits and assessments to verify compliance with organizational security requirements.
- Identify security gaps, document findings, and drive corrective action plans with suppliers and internal stakeholders.
- Track supplier compliance metrics and escalate risks, issues, and non-compliance items as necessary.
- Develop, maintain, and improve cybersecurity governance policies, standards, procedures, and controls.
- Monitor compliance risks, cybersecurity vulnerabilities, and third-party security exposures.
- Support third-party cybersecurity risk management programs and supplier security reviews.
- Troubleshoot issues involving PKI, certificate management, key deployment, and manufacturing integrations.
- Collaborate with cybersecurity, embedded software, vehicle program teams, manufacturing, procurement, suppliers, and IT infrastructure teams.
- Maintain audit documentation, compliance records, and reporting materials for leadership and regulatory reviews.
- Support continuous improvement initiatives related to security governance, compliance, and risk management frameworks.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Security, Computer Engineering, Electrical Engineering, Computer Science, or related field.
- 3+ years of experience in cybersecurity, compliance, governance, risk management, or information security.
- Experience with Public Key Infrastructure (PKI) and certificate lifecycle management.
- Experience working with Key Management Systems (KMS).
- Knowledge of cryptographic technologies, encryption standards, and key management principles.
- Experience conducting security assessments, supplier audits, or compliance reviews.
- Strong understanding of cybersecurity governance, risk management, and security control frameworks.
- Experience identifying, documenting, and remediating security and compliance risks.
- Strong communication and stakeholder management skills.
- Ability to work cross-functionally with engineering, cybersecurity, manufacturing, procurement, and supplier organizations.
- Experience creating policies, procedures, standards, and audit documentation.
Preferred Qualifications
- Experience supporting automotive, manufacturing, embedded systems, IoT, or connected product environments.
- Knowledge of automotive cybersecurity standards such as ISO 21434 and UNECE R155.
- Experience with security frameworks including NIST, ISO 27001, or similar standards.
- Familiarity with cryptographic platforms and tools such as Thales, Entrust, HashiCorp Vault, AWS KMS, or equivalent technologies.
- Experience supporting supplier cybersecurity programs and third-party risk management initiatives.
- Background in embedded software, electronic control units (ECUs), or vehicle security architectures.
- Relevant certifications such as CISSP, CISM, CRISC, Security+, or similar cybersecurity credentials.
#INDOEM
#LI-JC1
