Celestica International LP logo
Celestica International LP

Celestica (NYSE, TSX: CLS) enables the world’s best brands. Through our recognized customer-centric approach, we partner with leading companies in Aerospace and Defense, Communications, Enterprise, HealthTech, Industrial, Capital Equipment and Energy to deliver solutions for their most complex challenges. Leader in design, manufacturing, hardware platform and supply chain solutions Global expertise and insight at every stage of product development Headquartered in Toronto, with talented teams spanning 40+ locations in 13 countries

Manager, IT Risk & Compliance

ComplianceComplianceFull TimeRemoteLeadTeam 10,001

Location

United States

Posted

39 days ago

Salary

$107K - $147K / year

Seniority

Lead

No structured requirement data.

Job Description

Manager, IT Risk & Compliance

Celestica International LP

Req ID: 135145 Region: Americas Country: USA State/Province: New Hampshire City: Remote Employee US Summary The Manager of IT Risk & Compliance is a strategic leader within the Global IT Security organization, responsible for driving the enterprise Governance, Risk, and Compliance (GRC) program. This role ensures that information systems align with global security strategies, regulatory requirements, and the IT roadmap. Acting as a key liaison between IT Security and business stakeholders, the Manager leads proactive, data-driven cybersecurity initiatives that strengthen enterprise resilience, reduce risk exposure, and support secure business growth. Detailed Description Performs tasks such as, but not limited to, the following: Regulatory & Compliance Leadership Lead enterprise-wide governance for frameworks and regulations including NIST 800-171, DFARS, and CMMC, ensuring consistent implementation and ongoing compliance. CMMC Program Execution Drive organizational readiness and successful execution of CMMC Level 2 assessments across Aerospace & Defense (A&D) sites. Audit & Assurance Management Oversee the full lifecycle of internal and external IT audits, including preparation, stakeholder coordination, and timely remediation of findings. GRC Program Management Implement and manage the enterprise GRC platform to centralize compliance tracking, POA&M management, and risk reporting. Identity & Access Governance Define and enforce access control standards, including compliance with complex global requirements such as ITAR and EAR. Security Documentation & Standards Direct the development and maintenance of System Security Plans (SSPs) and supporting security documentation. Risk Identification & Mitigation Partner with site-level IT teams to identify vulnerabilities and embed security controls into business processes. Program & Project Leadership Lead cross-functional security and compliance initiatives, managing scope, timelines, resources, and executive reporting. Knowledge/Skills/Competencies - Strong understanding of IT security frameworks and standards (e.g., NIST, ISO/IEC 27001, COBIT, ITIL) - Expertise in regulatory requirements including CMMC, DFARS, SOX, HIPAA, PCI DSS, and global compliance standards - Ability to translate complex security and risk concepts for both technical and non-technical audiences - Proven experience in risk management, internal controls, and audit processes - Strong project and program management capabilities - Advanced analytical and problem-solving skills - Effective communication, collaboration, and stakeholder management skills - Experience with enterprise GRC tools and platforms - Solid understanding of change management processes Typical Experience - 5–7+ years of experience in IT Security, Risk Management, or Compliance, preferably in manufacturing or defense environments - Strong working knowledge of NIST 800-171, CMMC, ITAR, and GDPR - Demonstrated ability to manage multiple complex initiatives in regulated environments Preferred Certifications: - CMMC Certified Professional (CCP) (highly preferred) - CMMC Certified Assessor (CCA) - CISSP, CISA, ISO/IEC 27001 Lead Auditor, or PMP Typical Education Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field. Salary The stated range includes Base Salary and target Short-Term Incentive (STI) compensation only. A comprehensive benefits package is offered in addition to this range. The range described in this posting is an estimate by the Company, and may change based on several factors, including but not limited to a change in the duties covered by the job posting, or the credentials, experience or geographic jurisdiction of the successful candidate. Salary Range: $107,000 - 147,000 USD Physical Demands Duties of this position are performed in a normal office environment. Duties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required. Notes This job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Celestica’s policy on equal employment opportunity prohibits discrimination based on race, color, creed, religion, national origin, gender, sexual orientation, gender identity, age, marital status, veteran or disability status, or other characteristics protected by law. This policy applies to hiring, promotion, discharge, pay, fringe benefits, job training, classification, referral and other aspects of employment and also states that retaliation against a person who files a charge of discrimination, participates in a discrimination proceeding, or otherwise opposes an unlawful employment practice will not be tolerated. All information will be kept confidential according to EEO guidelines. COMPANY OVERVIEW: Celestica (NYSE, TSX: CLS) enables the world’s best brands. Through our recognized customer-centric approach, we partner with leading companies in Aerospace and Defense, Communications, Enterprise, HealthTech, Industrial, Capital Equipment and Energy to deliver solutions for their most complex challenges. As a leader in design, manufacturing, hardware platform and supply chain solutions, Celestica brings global expertise and insight at every stage of product development – from drawing board to full-scale production and after-market services for products from advanced medical devices, to highly engineered aviation systems, to next-generation hardware platform solutions for the Cloud. Headquartered in Toronto, with talented teams spanning 40+ locations in 13 countries across the Americas, Europe and Asia, we imagine, develop and deliver a better future with our customers. Celestica would like to thank all applicants, however, only qualified applicants will be contacted. Celestica does not accept unsolicited resumes from recruitment agencies or fee based recruitment services.

Related Categories

Related Job Pages

More Compliance Jobs

Full TimeRemoteTeam 201-500H1B No Sponsor

• Assist investment advisers and other financial services firm customers with regulatory obligations. • File annual updating amendments and other-than-annual amendments for Form ADV. • Process applications for new representatives of investment adviser and broker-dealer firms, including Form U4. • Coordinate with state and SEC regulators to secure registration for customer firms. • Submit various SEC EDGAR filings, such as Form 13F, Form 13H, and Form ID. • Handle Form D and blue sky filings for private funds. • Complete Form PF for hedge fund, private equity, and venture capital advisers. • Review disciplinary matters affecting customers for proper DRP disclosure. • Coordinate with Comply’s internal compliance experts, client services representatives, and other departments. • Attend team meetings and provide regular reporting to supervisor. • Work with Comply’s proprietary software, including MyRIACompliance and ComplianceGuardian. • Support remote team by clarifying and helping resolve complicated customer matters. • Assist your Regulatory Filings team with various other tasks as assigned.

United States
$60K - $75K / year
Job Closed
Celestica logo

Manager, IT Risk & Compliance

Celestica

Celestica serves companies around the world with reliable, end-to-end design, manufacturing, and engineering solutions. The diversified company offers complex solutions and service

Compliance40 days ago

• Lead enterprise-wide governance for frameworks and regulations including NIST 800-171, DFARS, and CMMC. • Drive organizational readiness and successful execution of CMMC Level 2 assessments across Aerospace & Defense (A&D) sites. • Oversee the full lifecycle of internal and external IT audits. • Implement and manage the enterprise GRC platform to centralize compliance tracking, POA&M management, and risk reporting. • Define and enforce access control standards. • Direct the development and maintenance of System Security Plans (SSPs). • Partner with site-level IT teams to identify vulnerabilities and embed security controls into business processes. • Lead cross-functional security and compliance initiatives.

Minnesota
$107K - $147K / year
Job Closed
Sarah Cannon Research Institute logo

Regulatory Affairs Specialist I

Sarah Cannon Research Institute

Sarah Cannon Research Institute (SCRI) is one of the world’s leading oncology research organizations conducting community-based clinical trials. Focused on advancing therapies for patients over the last three decades, SCRI is a leader in drug development. In 2022, SCRI formed a joint venture with former US Oncology Research to expand clinical trial access across the country. It has conducted more than 750 first-in-human clinical trials since its inception and contributed to pivotal research that has led to the majority of new cancer therapies approved by the FDA today. SCRI’s research network brings together more than 1,300 physicians who are actively enrolling patients into clinical trials at more than 250 locations in 24 states across the U.S.

Compliance40 days ago
Full TimeRemoteTeam 501-1,000

It’s More Than a Career, It’s a Mission. Our people are the foundation of our success. By joining our growing team at Sarah Cannon Research Institute (SCRI), a subsidiary of McKesson, you will have the opportunity to become part of one of the largest community-based cancer programs to advance oncology treatments and improve outcomes for cancer patients across the globe. We look for mission-driven candidates who have a desire to advance the fight against cancer and make a difference in the lives of patients diagnosed with cancer every day. Our Mission People who live with cancer – those who work to prevent it, fight it, and survive it – are at the heart of every decision we make. Bringing the most innovative medical minds together with the most passionate caregivers in their communities, we are transforming care and personalizing treatment. Through clinical excellence and cutting-edge research, SCRI is redefining cancer care around the world. Our Clinical Regulatory Affairs Specialist I primary responsibilities include managing and planning regulatory affairs compliance for industry sponsors and/or sites in networks. This position will work closely with the regulatory affairs management, department director and/or primary investigators to ensure compliance, preparing for auditing activities while meeting strict deadlines. The Regulatory Affairs Specialist I will maintain a full study workload with minimal supervision. This position is a US-based, full time, fully remote position; relocation assistance and sponsorship are not available. Duties include and are not limited to: - Establishes and maintains a document management system for regulatory electronic files - Maintains FDA and GCP required regulatory documentation for individual sites, studies, sponsors and/or other networks. Ensures all regulatory documentation is compliant with local Standard Operating Procedures (SOPs) for format and content - Maintains critical documentation ensuring compliance - Modifies and/or develops informed consent forms and updates and manages protocol, investigator drug brochure and consent form modifications or amendments in compliance with IRB policy and HIPAA. This includes time sensitive correspondence with sponsors and other stakeholders. - Organizes and processes documentation for IRB submission for multiple trials - Processing of Protocol Deviations that meet the IRB reportable criteria - Submits urgent safety notifications to the IRB - Other duties as assigned Qualifications for success include: - Associate's Degree or higher is preferred, high school graduation diploma required - qualified experience may be substituted for education - 1+ year work experience in a clinical research, pharmaceutical, site management organization highly desired focused in required regulatory affairs - Knowledge of medical terminology, FDA, other regulatory processes highly preferred About Sarah Cannon Research Institute Sarah Cannon Research Institute (SCRI) is one of the world’s leading oncology research organizations conducting community-based clinical trials. Focused on advancing therapies for patients over the last three decades, SCRI is a leader in drug development. In 2022, SCRI formed a joint venture with former US Oncology Research to expand clinical trial access across the country. It has conducted more than 850 first-in-human clinical trials since its inception and contributed to pivotal research that has led to the majority of new cancer therapies approved by the FDA in the past decade. SCRI’s research network brings together more than 1,300 physicians who are enrolling patients into clinical trials at more than 200 locations in 20+ states across the U.S. Please click here to learn more about our research offerings. We care about the well-being of the patients and communities we serve, and that starts with caring for our people. That’s why we have a Total Rewards package that includes comprehensive benefits to support physical, mental, and financial well-being. Our Total Rewards offerings serve the different needs of our diverse colleague population and ensure they are the healthiest versions of themselves. For more information regarding benefits through our parent company, McKesson, please click here. As part of Total Rewards, we are proud to offer a competitive compensation package. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson’s (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind: McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application. McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates. McKesson job postings are posted on our career site: careers.mckesson.com. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

United States
Full TimeRemoteTeam 1,001-5,000Since 2018H1B No Sponsor

• Own day-to-day execution of trade compliance data governance across Quince’s product catalog, including product classification and customs data across multiple countries. • Manage classification workflows end-to-end, including intake, prioritization, review, issue resolution, and escalation handling. • Review, validate, and maintain product classifications and compliance data to ensure accuracy, consistency, and audit readiness. • Serve as the subject matter expert for complex classification determinations, including ambiguous or high-risk scenarios. • Ensure trade compliance data required for customs filings and regulatory declarations is accurately maintained in internal systems. • Apply and refine classification standards, business rules, and escalation processes to support scalable compliance execution. • Execute and strengthen internal controls across classification, customs valuation, and free trade agreement eligibility. • Conduct internal audits of product classifications, broker filings, and compliance records to identify risks and improve control effectiveness. • Partner with sourcing and merchandising teams on tariff engineering, FTA analysis, and upstream decisions impacting compliance outcomes. • Collaborate cross-functionally with operations, logistics, legal, and technology teams to resolve compliance issues and improve data quality. • Translate complex regulatory requirements into clear operational workflows, guidance, and system requirements. • Support the evolution of trade compliance systems, tooling, and data governance frameworks. • Identify process gaps and recurring issues, recommending improvements to enhance scalability, consistency, and compliance integrity.

United States
$100K - $250K / year