We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Cyber Manager - Governance, Risk and Compliance

Steelcase
United States, Michigan, Grand Rapids
901 44th Street Southeast (Show on map)
Sep 23, 2026
Company DescriptionJob Description

Who you are:

You believe governance, risk, and compliance should make a company safer and faster, not slower. You have seen GRC done as spreadsheets, checklists, and annual fire drills, and you want to build something better.

You are a builder and a people leader. You enjoy growing a team, designing programs from first principles, and turning evidence collection, control testing, and risk assessment into continuous, largely automated work, with AI increasingly handling the tedious parts so your team can focus on judgment.

You are comfortable in the room with executives, auditors, engineers, and business partners, translating between them and helping leaders make risk decisions with clear information rather than fear.

Helping You Thrive By:

  • Offering competitive wages and benefits, that support your life both in and out of work
  • Providing a flexible hybrid work schedule, meaning we expect the office to be your primary place of work, balanced with choice and control.
  • Creating continuous learning opportunities to help you grow and upskill.
  • Fostering a culture of inclusion where employees feel seen, heard and valued - and living it out every day.
  • Empowering you to make a meaningful impact on people and the planet through your work and Steelcase's ongoing commitment.

You'll Support Meaningful Work By:

  • Leading and growing the Governance, Risk & Compliance team, setting direction, coaching, and creating the conditions for people to do their best work.
  • Owning the enterprise cybersecurity risk program: identifying, quantifying, and communicating risk so the CISO and business leaders can prioritize with confidence.
  • Reimagining compliance as a continuous, evidence-driven capability rather than an annual event, using automation and AI to gather evidence, test controls, and surface gaps in near real time across frameworks such as SOX ITGC, NIST CSF, and the CIS Controls.
  • Running a third-party risk program that scales with the business, applying AI to assess vendor questionnaires, contracts, and external risk signals so your team spends its time on decisions rather than paperwork.
  • Writing and maintaining security policies and standards that people actually read and follow, and retiring the ones that no longer serve a purpose.
  • Serving as the primary security partner to Internal Audit, external auditors, Legal, and Privacy, and making audit season uneventful.
  • Helping shape how Steelcase governs its own use of AI, partnering across the company on responsible AI practices, controls, and risk assessment as new capabilities are adopted.
  • Building metrics and reporting that tell an honest story about our risk posture to the CISO, executive leadership, and the Board.
Qualifications

Minimum Qualifications

  • Three or more years of formal people leadership, managing a governance, risk, and compliance team or an equivalent security, audit, or risk function, with direct responsibility for hiring, coaching, and developing the people on it.
  • Hands-on background in governance, risk, compliance, or security audit work in an enterprise environment.
  • Working knowledge of at least one major security or compliance framework (for example NIST CSF, the CIS Controls, SOX ITGC, or COBIT) and how controls map across frameworks.
  • Ability to assess risk and communicate it clearly to technical and non-technical audiences, including senior leaders.
  • A track record of improving processes, not just running them.
  • Bachelor's degree in a related field, or equivalent experience.

Desired Skills and Experience

  • Certifications such as CISA, CRISC, CISM, CISSP, or CGEIT.
  • Experience with GRC or privacy platforms such as OneTrust, and with security ratings services such as Bitsight.
  • Experience building or maturing a third-party risk management program.
  • Hands-on experience using AI tools or automation to streamline evidence collection, control testing, or risk analysis, or a strong appetite to learn.
  • Familiarity with emerging AI governance frameworks such as the NIST AI RMF or the EU AI Act.
  • Experience in a global manufacturing or multi-entity organization.

Qualified applicants must be authorized to work in the United States on a full-time basis. Steelcase will not provide support for or sponsor work authorization and/or visas for this role.

Additional Information

#mid_senior_level

#LI-Onsite

#Information_Technology

#Management

#Consulting

#LI-EW1

At Steelcase, we put people at the center of everything we do. We understand the role of work and believe that it can bring meaning and purpose to the lives of our customers and our employees. We prioritize supporting our employees both in and out of work, in all aspects of their lives. When we bring our talents together, we make a positive lasting impact through our work and communities.

Steelcase provides employment opportunities to all qualified employees and applicants without regard to race, color, creed, genetic information, religion, national origin, gender, sexual orientation, gender identity and expression, age, disability, or veteran status and bases all employment decisions only on valid job requirements. If we can make the application process easier through accommodation, please email us at myhr@steelcase.com.

Applied = 0

(web-9db6c7984-zd648)