About the Role
The Manager of Manufacturing Compliance & Cybersecurity Maturity Model Certification (CMMC) / Canadian Program for Cyber Security Certification (CPCSC) develops, implements, and sustains regulatory compliance programs across Manufacturing, Distribution, and Value Add operations in the United States and Canada. This role acts as the operational compliance subject matter expert, translating complex regulatory requirements into practical business processes, standard work, training, and daily operational practices. It bridges the gap between regulatory language and business execution, ensuring compliance is understood, implemented, and consistently followed. The role collaborates with Operations, Engineering, Facilities, Human Resources, Trade Compliance, Information Technology, and Quality to develop compliance programs, prepare facilities for audits, conduct internal audits, and drive continuous compliance readiness. This position focuses on operational compliance and implementation, not technical cybersecurity infrastructure or Quality Management System ownership.
Responsibilities
- Lead the development, implementation, and continuous improvement of enterprise compliance programs.
- Translate complex regulatory requirements into practical business processes and operational procedures.
- Develop implementation roadmaps and ensure consistent deployment across all manufacturing, distribution, and value-added facilities.
- Serve as the primary business resource for interpreting compliance requirements and their application to daily operations.
- Monitor changes to applicable regulations and implement required business process updates.
- Lead operational implementation and sustainment of the organization's CMMC/CPCSP compliance program.
- Coordinate certification readiness activities for U.S. and Canadian facilities.
- Prepare sites for C3PAO assessments and customer audits.
- Develop implementation plans and monitor overall compliance readiness.
- Partner with Information Technology on technical cybersecurity controls while owning the operational and facility-level implementation.
- Track certification milestones and ensure ongoing compliance.
- Develop and implement operational processes supporting compliance with ITAR, CPG, EAR, and Controlled Unclassified Information (CUI) handling requirements.
- Ensure employees understand and properly apply export control and controlled information requirements.
- Develop business procedures supporting secure handling of regulated information throughout manufacturing operations.
- Develop and maintain operational standards for facility access controls, physical protection of Controlled Unclassified Information, physical document security, visitor management, media protection and secure storage, employee handling of regulated information, restricted production areas, document retention and destruction.
- Conduct facility compliance walkthroughs and operational assessments.
- Develop and manage the enterprise compliance audit program.
- Conduct internal audits supporting CMMC/CPCSP, ITAR, EAR, and other regulatory requirements.
- Track audit findings through corrective action and verification of effectiveness.
- Coordinate certification readiness assessments.
- Develop audit schedules and compliance metrics.
- Support external regulatory and customer audits.
- Partner with the Quality organization to support ISO 9001 and AS9100 internal audit activities.
- Provide regulatory compliance expertise during integrated audits.
- Assist in identifying opportunities to align compliance requirements with existing operational processes.
- Support audit preparation and corrective action activities related to regulatory compliance.
- Develop and deliver compliance training programs for employees, supervisors, and leadership.
- Translate regulatory language into practical, easy-to-understand training materials.
- Develop work instructions, visual standards, job aids, and awareness materials.
- Coach site compliance champions and functional leaders.
- Promote a culture of compliance through communication and employee engagement.
- Ensure compliance training remains current with evolving regulatory requirements.
- Communicate compliance status, risks, and readiness to executive leadership.
- Develop compliance dashboards and executive reporting.
- Coordinate enterprise compliance initiatives across multiple business functions.
- Build strong partnerships with Operations, Engineering, Facilities, Trade Compliance, Human Resources, Information Technology, and Quality.
Requirements
- Bachelor's degree in Business, Manufacturing, Engineering, Operations, Compliance, or a related field.
- 7+ years of experience in regulatory compliance, manufacturing operations, auditing, or regulated industries.
- Experience implementing and managing enterprise compliance programs.
- Experience conducting internal compliance audits.
- Demonstrated ability to interpret regulatory requirements and translate them into practical business processes.
- Experience developing procedures, work instructions, and employee training programs.
- Excellent project management, organizational, and communication skills.
- Experience managing controlled documentation (SharePoint or similar).
- Ability to travel approximately 30–40% throughout the United States and Canada.
Skills
- CMMC/CPCSP
- NIST SP 800-171
- ITAR
- EAR
- Controlled Unclassified Information (CUI) requirements
- SharePoint
- Canadian Controlled Goods Program (CGP)
Location
- United States
- Canada
Work Type
- Full-time
Experience Level
- Manager
- 7+ years
Education Level
- Bachelor's degree
Salary/Compensations
- $100k-$150k
Benefits
- Medical, Dental, Vision Insurance
- Life Insurance and Disability
- Voluntary Wellness Programs
- 401(k) or RRSP programs with Company Match
- Paid Vacation and Holidays
- Tuition Reimbursement
About the Company
- thyssenkrupp (“TK”)
Equal Opportunity
- Equal opportunity employer, including people with disabilities and veterans.
- Applicants with disabilities may be entitled to reasonable accommodation under the Americans with Disabilities Act and certain state or local laws.
- TK does not ask, solicit, or accept any monies in any form from candidates, job applicants, or potential jobseekers, who have applied to or wish to apply to TK, whether online or otherwise as a pre-employment requirement.
- TK does not send job offers from free email services like Gmail, Rediffmail, Yahoo mail, etc.
- TK does not request payment of any kind from prospective jobseekers or candidates for employment.
- TK does not authorize anyone to collect money or agree to any monetary arrangement in return for a job at TK.
- TK does not send checks to job seekers.
- TK does not make job offers through third parties. In the event TK uses professional recruitment services through a third party, offers are always made directly by TK and not by any third parties.
