- Salary
- $87k – $166k
- Location
- Dearborn, MI,US, US
- Type
- Full-time
- Department
- IT
- Education
- Bachelor
- Visa
- Not sponsored
- Source
- Eightfold
Description
The Enterprise Cyber GRC (Governance, Risk, and Compliance) team functions as a second line of defense, supporting the development and maintenance of Enterprise Technology (ET) risk management and compliance activities. This Analyst role supports the Cyber GRC Compliance & Certification Service Manager in executing day-to-day compliance, certification, and risk management activities across global and regional (EU/Germany) frameworks, including ISO 27001, SOC 2, NIST CSF, GDPR, and other automotive-industry-specific standards.
This is a hands-on execution role, ideal for someone building foundational GRC expertise while contributing to certification lifecycle management, evidence collection, control monitoring, and regulatory reporting support.
- Support the Service Manager in maintaining relationships with OGC, the application teams and other across the shared services teams, by preparing documentation, tracking action items, and coordinating meeting logistics.
- Coordinate responses to compliance inquiries using GRC tooling, working with SMEs to obtain accurate and complete information in advance of compliance due dates.
- Assist in the collection, organization, and validation of evidence artifacts, metrics, and control documentation required for the maintenance of cyber certification and regulatory compliance.
- Facilitate detailed risk assessments as part of the risk management program, using GRC software and statistical methods to quantitify risk at the IT asset level.
- Help monitor information security controls on an ongoing basis and flag deviations, gaps, or emerging risks to the Service Manager for escalation to the global GRC team.
- Coordinate the bi-annual maturity assessment process for selected applications by gathering data, coordinating stakeholder input, and drafting supporting documentation.
- Contribute to the preparation of annual reports and governance materials, including drafting content and compiling data for C-level presentations.
- Assist in disseminating GRC training materials and coordinating regional awareness sessions, including scheduling, content adaptation, and tracking participation.
- Maintain and update trackers/logs of newly identified IT risks and compliance gaps, ensuring accurate documentation before escalation to the global GRC team.
- Support certification lifecycle activities (e.g., audit scheduling, evidence readiness checks, tracking remediation actions) for relevant frameworks.
- Conduct research on regional regulatory requirements and summarize findings to support the Service Manager's representation of regional needs within the global team.
- Assist with ad hoc reporting, data analysis, and documentation requests from internal stakeholders, auditors, or the global GRC team.
- Assist in preparing and updating of procedural documentation around compliance inquiry management and evidence collection processes.
- Bachelor's degree in IT, Cybersecurity, or a relevant business discipline.
- 2–4 years of relevant IT, security, or compliance experience.
- Exposure to security frameworks such as NIST CSF or ISO 27001 preferred.
- Experience supporting audits, assessments, or compliance projects is a plus.
- Familiarity with GDPR or other EU regulatory requirements is advantageous but not required.
- Strong Excel/PowerPoint skills for reporting and documentation support.
You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Ford Motor Company, we encourage you to apply!
As an established global company, we offer the benefit of choice. You can choose what your Ford future will look like: will your story span the globe, or keep you close to home? Will your career be a deep dive into what you love, or a series of new teams and new skills? Will you be a leader, a changemaker, a technical expert, a culture builder…or all of the above? No matter what you choose, we offer a work life that works for you, including:
- Immediate medical, dental, vision and prescription drug coverage
- Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
- Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
- Vehicle discount program for employees and family members and management leases
- Tuition assistance
- Established and active employee resource groups
- Paid time off for individual and team community service
- A generous schedule of paid holidays, including the week between Christmas and New Year’s Day
- Paid time off and the option to purchase additional vacation time.
This position is a salary grade 7-8 and ranges from $86,600-$166,200.
Final determination of salary grade will be based on candidate's skills and experience, and base salary will be set within the applicable range according to job scope, responsibility and competitive market value.
For more information on salary and benefits, click here: https://fordcareers.co/GSR
Visa sponsorship is not available for this position.
Candidates for positions with Ford Motor Company must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire.
We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status. In the United States, if you need a reasonable accommodation for the online application process due to a disability, please call 1-888-336-0660.
This position is hybrid with a requirement to be onsite four or more days per week.
#LI-Hybrid
#LI-GR1