Senior Cybersecurity Risk & Compliance Associate Job at Wind River, Boston, MA

VUIrTlQ4NUpodzZpV0FqcUJUcVNWaHlVVXc9PQ==
  • Wind River
  • Boston, MA

Job Description

Description

Position at Wind River

 

ABOUT WIND RIVER 

Wind River is a global leader in delivering software for mission-critical intelligent systems. For more than four decades, the company has been an innovator and pioneer, powering billions of systems that require the highest levels of security, safety, and reliability. 

We help customers across automotive, aerospace, defense, industrial, medical, and telecommunications industries solve complex technology challenges on their journey toward the new intelligent machine economy. The company’s software powers generation after generation of the safest, most secure systems in the world.  Examples include playing a key role in NASA space missionssuch as Artemis I, the James Webb Space Telescope, and multiple Mars rovers. We’ve achieved recent 5G milestonesincluding the world’s first successful 5G data sessionwith Verizon and  building one of the largest Open RAN networksin the world with Vodafone. 

for its technology innovation and leadership, and for its workplace culture, including global Great Place to Work certification and being named a “Top Workplace” for ten consecutive years. If you want to be part of a unique culture where experience is based on our cultural attributes of growth mindset, customer-focus, and diversity, equity, inclusion & belonging, come join us & help advance the future software defined world. 

ABOUT THE OPPORTUNITY  

We are hiring a professional to support and help lead the Wind River Risk & Compliance function, with a primary focus on maintaining our ISO 27001 certification and supporting our obligations on NIST 800-171. The right candidate will support the Wind River Risk and Compliance program, which includes Governance Risk and Compliance (GRC), and Third Party Risk Management (TPRM), bring structure to our processes, and help stabilize and scale the function.

KEY RESPONSIBILITIES

Regulatory & Standards Support:

  • Contribute to all ISO 27001 activities, including internal audit readiness, external recertification, and ongoing control maintenance.
  • Support NIST 800-171 compliance efforts, including maintenance of System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and gap assessments.
  • Have working knowledge and able support GDPR, NIST CSF, CMMC, TISAX, ITAR, and AI related compliance as well as the ability to gain knowledge on future certification and regulation requirements.
  • Assist in engagement with government compliance stakeholders and maintain awareness of requirements.

Risk & Compliance Operations Governance Risk and Compliance (GRC) and Third-Party Risk Management (TPRM):

  • Maintain the Wind River Risk Register and track mitigation progress across all functional areas.
  • Coordinate the Security Exception process, ensuring proper documentation, approvals, and governance.
  • Including vendor assessments, reviews, remediation follow-up, and monitoring.
  • Write and update policy and standards and provide governance, oversight, and assurance.
  • Administer GRC/TPRM tooling (ZenGRC) and ensure evidence management and workflows are maintained and audit-ready. Have an understanding or ability to use ServiceNow and AuditBoard risk management products.

Audit & Customer Response:

  • Prepare audit documentation and assist with responses for internal and external audits.
  • Draft and maintain clear, consistent, and audit-ready documentation, including policies, control responses, and program updates.
  • Support customer assurance efforts related to ISO, NIST, and general cyber compliance.
  • Lead internal audits and assessments against Wind River.

Program Execution & Scalability:

  • Help implement scalable, repeatable governance processes for policy and standard creation and lifecycle management.
  • Assist in developing compliance procedures, checklists, and review frameworks.
  • Support workflows for User Access Reviews (UAR), TPRM, and continuous monitoring.

Collaboration:

  • Work cross-functionally with Aptiv Cybersecurity, IT, Legal, HR, and Engineering, across Aptiv, HellermannTyton, Winchester, and Intercable.
  • Support communication and coordination with external auditors and internal stakeholders (including Primary Security Officer, Aptiv Legal, WR and Aptiv leadership).
  • Support Cybersecurity Training at Wind River.

REQUIRED QUALIFICATIONS

  • 5+ years of cybersecurity, compliance, or GRC experience
  • Familiarity with ISO 27001, NIST 800-171, and enterprise GRC operations
  • Strong writing skills, with experience contributing to SSPs and POA&Ms
  • Working knowledge of ZenGRC or similar tools
  • Demonstrated ability to work across matrixed teams
  • Experience with customer audit responses and regulatory compliance
  • U.S. citizenship required due to regulatory requirements
  • Must be a local resident (or willing to relocate to) Alameda, CA or Boston, MA and agree to being on site three days per week in the office.

PREFERRED QUALIFICATIONS

  • Experience supporting government-mandated compliance frameworks
  • Involvement in ISO 27001 recertification efforts or similar standards
  • Experience with third-party risk tools (e.g., BlueVoyant, BitSight)
  • Familiarity with Wind River or embedded systems companies is a plus

Why This Role Matters:

Wind River's ability to operate in national security and critical infrastructure markets depends on strong cybersecurity governance. This role helps ensure we maintain our certifications, deliver on regulatory and contractual obligations, and support internal and external stakeholders with confidence. It also supports balancing workloads currently spread across teams and positions the function for long-term stability.

Join us at Wind River, where we're not just shaping technology; we're shaping the future of a safer, more connected world. Your journey to make a meaningful impact begins here.

APPLICANT PRIVACY NOTICE:

Your privacy is of the utmost importance to us. At Wind River, we strictly adhere to all applicable data privacy laws. Please review Wind River's Applicant Privacy Notice, which can be found here.

Wind River is an Equal Opportunity Employer with a commitment to diversity. We prohibit discrimination based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.

 

BENEFITS  

  • Hybrid work model for workplace flexibility 
  • Comprehensive health, dental, and life insurance 
  • Short and long-term disability coverage 
  • RRSP matching for financial security 
  • Flexible time-off policies for work-life balance 
  • Learning benefits, including a LinkedIn Learning subscription and seminars 

Join us at Wind River, where we're not just shaping technology; we're shaping the future of a safer, more connected world. Your journey to make a meaningful impact begins here. 

 

APPLICANT PRIVACY NOTICE:   

Your privacy is of the utmost importance to us. At Wind River, we strictly adhere to all applicable data privacy laws. Please review Wind River's Applicant Privacy Notice, which can be found here.   

Wind River is an Equal Opportunity Employer with a commitment to diversity. We prohibit discrimination based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.

SECURITY CLEARANCE REQUIREMENTS 

Successful candidates must engage in a security clearance process in regard to their citizenship in order to perform fundamental job duties, as per applicable law. In particular, candidates with certain citizenship may not be able to perform such fundamental job duties. Currently, this includes citizens of the following countries: Belarus; Burma; China; Cuba; Iran; North Korea; Syria; Venezuela; Afghanistan; Cambodia; Central African Republic; Cyprus; Democratic Republic of Congo; Ethiopia; Eritrea; Haiti; Iraq; Lebanon; Libya; Russia; Somalia; South Sudan; Sudan; Zimbabwe. The security clearance process may take a significant amount of time to complete, and any offer of employment will be contingent on the candidate's legal ability to perform the fundamental job duties. Wind River is committed to meeting its obligations to candidates under applicable human rights law and privacy law in this regard.

COMPENSATION:

The annual base salary range for this role’s listed grade level is currently $100,000 to $130,00 plus a bonus for Boston, MA residents, and $110,000 to $140,000 plus a bonus for SF Bay Area residents. Salary ranges are determined through interviews and a review of the education, experience, knowledge, skills, location, and abilities of the applicant, and equity with other team members. Employees in this role are also eligible for the following benefits in accordance with the terms of the Company's plans: health, dental, vision insurance, life insurance, flex time off, eligibility to enroll in 401k, and 12 paid holidays.

 

#LI-JP1

 

Job Tags

Temporary work, Flexible hours,

Similar Jobs

Vensure Employer Solutions

Division Vice President of Nursing Informatics - TX Job at Vensure Employer Solutions

 ...healthcare system is seeking a Division Vice President of Nursing Informatics to join its executive team. This role provides strategic and...  ...Support compliance with federal and state electronic health record (EHR) requirements, including meaningful use standards... 

ROMAN EMPIRE ABA SERVICES

Registered Behavior Technician/RBT Job at ROMAN EMPIRE ABA SERVICES

 ...About us Roman Empire ABA Services, Inc. provides Applied Behavior Analysis to clients with developmental disabilities. Roman Empire ABA Services is seeking energetic Registered Behavior Technicians (RBT) amp; Paraprofessional Teachers and we want YOU to join our... 

Safran

Key Account Manager- US Military & Defense Job at Safran

Key Account Manager- US Military & Defense**Job details****General information****Entity**Safran is an international high-technology...  ...teams to ensure unified customer engagement.Commercial & Contract Execution:- Participate in the preparation and presentation of... 

Memco

Bulk operator Job at Memco

 ...working outside year roundEspecially the heat - No previous experience required -Lift at least 50 pounds -Going up/down ladders and...  ...-Loading/Unloading trucks -Unload railcars -Gauge and take temp on tanks -Pull samples from tanks/railcars -Line up piping... 

SSP America

Barista Job at SSP America

 ...Airport . Ourportfolioincludes local favorites like Fir & Pine , Riverside Cafe, and Peet's Coffee. At SSP America, our Baristas have the important role of preparing, serving, and selling wonderful beverages for our guests. If youve been to an airport, you...