About this role
About the Role KES is looking for a Cybersecurity GRC Manager to join our global IT capability in Wichita, KS. This role will help strengthen how KES manages cybersecurity risk, compliance obligations, and governance practices to support operational resilience, customer trust, and business decision-making. This role may require domestic and international travel up to 10% and is not eligible for visa sponsorship. What You'll Do
- Own and mature the KES cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across KES businesses.
- Represent KES cybersecurity in internal meetings, review boards, and cross-functional forums, including coordination with the Koch cybersecurity organization.
- Build and manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance.
- Manage cybersecurity compliance obligations across regulatory, contractual, and customer requirements, including NIS2, China MLPS, NERC CIP, and other applicable cybersecurity standards and frameworks.
- Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, commercial teams, IT, and business leaders.
- Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services.
- Coordinate the KES cybersecurity awareness program in partnership with the Koch cybersecurity organization, tailoring content, driving participation, and tracking effectiveness.
- Monitor emerging cybersecurity risks, regulatory changes, technology trends, and program metrics to improve visibility, inform risk decisions, support executive reporting, and strengthen program effectiveness. What We're Looking For
- Experience in cybersecurity governance, risk, and compliance program management, including risk registers, remediation tracking, and compliance obligations.
- Experience inter