Information Security Program Lead

MSA, The Safety Company$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Deep understanding of ISO 27001:2022 and related standards, with practical ISMS management experience
  • Solid grasp of governance, risk management, and compliance (GRC) methodologies and structured risk assessments
  • Experience with SOC 2 standards and audit support activities
  • Familiarity with CMMC 2.0 and NIST SP 800-171, especially in CUI environments
  • Knowledge of GDPR and data protection laws relevant to global operations
  • Excellent written and verbal communication skills for diverse audiences
  • Proven capability to independently drive compliance initiatives in a global team environment

Responsibilities

  • Own and maintain the ISMS in line with ISO 27001:2022 requirements
  • Lead internal and external ISO 27001 audits, including planning and execution
  • Conduct gap analyses and risk assessments related to ISO 27001 controls
  • Coordinate SOC 2 compliance activities and external readiness reviews
  • Support CMMC 2.0 readiness and compliance activities
  • Report compliance posture and key risks to senior management
  • Collaborate with stakeholders to integrate security and compliance into business processes

Benefits

  • Hybrid work environment
  • Opportunities for professional development and training
  • Access to innovative tools and technology
  • Engagement in meaningful and purpose-driven work
Full Job Description
Overview

Are you someone who is passionate, motivated, and driven to make a difference? If so, MSA Safety is the perfect fit for your career.

At MSA, SAFETY is who we are AND it is what we do. We are a purpose-driven company committed to deploying innovation and technology to deliver on our Mission to help protect people and assets all around the world. We continue to be relentless in our pursuit of solving our customers greatest problems so they can go home safe each and every day.

Are you in? Read on for more details about this particular role.

Responsibilities

ISMS Ownership & ISO 27001
  • Own and maintain the Information Security Management System (ISMS), ensuring alignment with ISO 27001:2022 requirements and organizational objectives
  • Lead and coordinate internal and external ISO 27001:2022 audits, including audit planning, execution, and follow-up
  • Conduct gap analyses, risk assessments, and risk treatment planning in line with ISO 27001 Annex A controls
  • Develop, review, and maintain information security policies, standards, and procedures

Multi-Framework Compliance
  • Drive and coordinate compliance activities across SOC 2 Type II, including control documentation, evidence collection, and readiness reviews in preparation for external assessments
  • Support CMMC 2.0 Level 2 readiness and compliance, including control implementation guidance aligned with NIST SP 800-171 and coordination for third-party assessment organization (C3PAO) engagements
  • Maintain working knowledge of NIST SP 800-171 requirements and their relationship to CMMC, supporting Controlled Unclassified Information (CUI) scoping and handling requirements
  • Ensure compliance activities reflect applicable regional data protection obligations, including GDPR and other jurisdiction-specific requirements relevant to global operations
  • Maintain a cross-framework control mapping to identify overlaps, reduce duplication of effort, and ensure consistent control coverage across ISO 27001, SOC 2, CMMC, and NIST

Global Governance & Stakeholder Engagement
  • Serve as a key point of contact for external certification bodies, auditors, and regulatory inquiries
  • Report on the state of the ISMS, compliance posture, and key risk indicators to senior management across global business units
  • Contribute to security awareness programs and training initiatives, adapting content for regional and cultural relevance where needed
  • Collaborate with cross-functional and geographically distributed stakeholders to embed security and compliance requirements into business processes

Third-Party & Engineering Collaboration
  • Support and collaborate with the Third-Party Risk Management (TPRM) function, providing GRC expertise on vendor risk assessments and due diligence processes
  • Work closely with the software development function to integrate compliance requirements into the Secure Software Development Lifecycle (SSDLC)

Qualifications

Required Skills / Knowledge / Abilities
  • Deep understanding of ISO 27001:2022 and associated standards (e.g., ISO 27002), including practical ISMS management experience
  • Solid grasp of GRC methodologies, control frameworks, and structured risk assessment practices
  • Working knowledge of SOC 2 (Trust Services Criteria) and readiness or audit support experience
  • Working knowledge of CMMC 2.0 and/or NIST SP 800-171, including their application to CUI environments and U.S. federal compliance obligations
  • Familiarity with GDPR or equivalent data protection regulations as they apply to global enterprise operations
  • Experience with cross-framework control mapping across two or more of the above frameworks
  • Excellent written and verbal communication skills - ability to translate complex compliance topics for both technical and non-technical audiences across different cultural and organizational contexts
  • Proven ability to work independently and drive compliance initiatives with minimal supervision in a globally distributed team environment

Preferred Skills
  • Hands-on experience with SOC 2 Type II audit support and evidence collection
  • Direct involvement in CMMC readiness activities or C3PAO-facilitated assessments
  • Knowledge of cloud security controls, particularly in AWS and Office 365 environments
  • Familiarity with AI-enhanced GRC tooling and compliance automation approaches
  • Understanding of TPRM frameworks, vendor risk methodologies, and associated tooling
  • Familiarity with SSDLC principles and their integration with compliance requirements
  • Experience working across multiple time zones and jurisdictions in a multinational organization

Education & Experience

Required
  • Bachelor's degree in Computer Science, Information Security, or a relevant field
  • Demonstrated experience leading or supporting ISO 27001 certification or re-certification audits
  • Experience developing and implementing security policies and controls across multiple frameworks
  • Experience conducting structured risk assessments and managing risk treatment plans in complex, multi-jurisdictional environments

Preferred
  • ISO 27001 Lead Auditor or Lead Implementer certification (e.g., PECB, BSI, or equivalent)
  • Master's degree in Computer Science, Information Security, or a relevant field
  • Additional certifications such as CISM, CISA, CISSP, or ISO 27005 Risk Manager
  • Certifications or formal training in CMMC, NIST, or SOC 2 methodologies
  • Experience working in or supporting regulated industries subject to U.S. government compliance requirements


#LI-KH2

#LI-HYBRID

About MSA, The Safety Company

MSA, The Safety Company Careers

Join the dedicated team at MSA, The Safety Company, a global leader in the development, manufacture, and supply of safety products that protect people and facility infrastructures. MSA is recognized for its commitment to innovation, quality, and service.

Explore Job Opportunities

MSA, The Safety Company offers a variety of job opportunities that cater to a range of skills and professional interests. Each position at MSA is designed to contribute significantly to the safety and protection of lives at work and beyond.

Professional Growth and Employment Benefits

MSA, The Safety Company is committed to the professional growth of its team members. The company supports career advancement through leadership training programs, diversity initiatives, and continuous learning opportunities. Employment at MSA comes with competitive benefits, fostering a culture that values health, well-being, and job satisfaction.

Internship Programs

For those starting their careers, internships at MSA provide invaluable industry experience and a chance to develop essential skills in a real-world setting. Interns at MSA, The Safety Company work on projects that matter, gaining knowledge and expertise that are crucial for future employment.

Innovation and Leadership

At MSA, innovation is at the core of everything they do. The team is encouraged to lead with creativity and embrace new ideas that drive the industry forward. MSA’s leadership is deeply involved in ensuring that every team member has the resources and support needed to innovate.

Culture of Diversity and Inclusion

The culture at MSA, The Safety Company is built on a foundation of diversity and inclusion. Every team member’s unique background and perspective are valued, contributing to a richer, more creative, and productive work environment.

Networking and Career Development

MSA, The Safety Company encourages its employees to engage in professional networking and career development activities. These opportunities enhance their skills and connect them with professionals across the industry, opening doors to new career possibilities.

Hiring Process

The hiring process at MSA, The Safety Company is thorough, ensuring that both the company and its potential employees are a perfect match. Candidates who submit their resume and pass the initial screening will be invited for an interview to discuss their experiences and career aspirations.

Join the Team

MSA, The Safety Company is looking for passionate, curious, and innovative individuals to join their team. Explore open positions that match your skills and interests on the MSA Careers page. Discover how your expertise can contribute to a safer world.

Stay Connected

Keep up to date with the latest career tips, industry insights, and job alerts personalized to your preferences from MSA, The Safety Company. See what exciting and rewarding opportunities await in the field of safety and protection.

SEARCH MSA JOBS

READ CAREERS BLOG

JOB ALERT EMAILS

Join MSA, The Safety Company, and be part of a team that’s dedicated to creating a safer future.
Learn more about MSA, The Safety Company

Similar Jobs

More Jobs at MSA, The Safety Company

More Information Technology Jobs

Find similar Information Security Program Lead jobs: