Tareas
Job Summary
The Manager of Manufacturing Compliance & Cybersecurity Maturity Model Certification (CMMC) / Canadian Program for Cyber Security Certification CPCSC) is responsible for developing, implementing, and sustaining regulatory compliance programs across Manufacturing, Distribution, and Value Add operations throughout the United States and Canada.This role serves as the organization's operational compliance subject matter expert, translating complex regulatory requirements into practical business processes, standard work, training, and day-to-day operational practices. The position bridges the gap between regulatory language and business execution by ensuring compliance requirements are understood, implemented, and consistently followed throughout the organization.
Working cross-functionally with Operations, Engineering, Facilities, Human Resources, Trade Compliance, Information Technology, and Quality, this individual develops compliance programs, prepares facilities for certification and customer audits, conducts internal compliance audits, and drives continuous compliance readiness.
This role focuses on operational compliance and implementation rather than technical cybersecurity infrastructure or Quality Management System ownership.
Job Description
Key Accountabilities:
Compliance Program Management
Lead the development, implementation, and continuous improvement of enterprise compliance programs.
Translate complex regulatory requirements into practical business processes and operational procedures.
Develop implementation roadmaps and ensure consistent deployment across all manufacturing, distribution, and value-added facilities.
Serve as the primary business resource for interpreting compliance requirements and their application to daily operations.
Monitor changes to applicable regulations and implement required business process updates.
CMMC / CPCSP Program Management
Lead operational implementation and sustainment of the organization's CMMC/CPCSP compliance program.
Coordinate certification readiness activities for U.S. and Canadian facilities.
Prepare sites for C3PAO assessments and customer audits.
Develop implementation plans and monitor overall compliance readiness.
Partner with Information Technology on technical cybersecurity controls while owning the operational and facility-level implementation.
Track certification milestones and ensure ongoing compliance.
ITAR / CPG / EAR Operational Compliance
Develop and implement operational processes supporting compliance with:
ITAR (International Traffic in Arms Regulations)
CPG (Controlled Products/Compliance Program Governance, as applicable)
EAR (Export Administration Regulations)
Controlled Unclassified Information (CUI) handling requirements
Ensure employees understand and properly apply export control and controlled information requirements.
Develop business procedures supporting secure handling of regulated information throughout manufacturing operations.
Physical Security Controls
Develop and maintain operational standards for:
Facility access controls:
Physical protection of Controlled Unclassified Information
Physical document security
Visitor management:
Media protection and secure storage
Employee handling of regulated information
Restricted production areas:
Document retention and destruction
Facility compliance walkthroughs and operational assessments
Compliance Internal Audit Program
Develop and manage the enterprise compliance audit program.
Conduct internal audits supporting CMMC/CPCSP, ITAR, EAR, and other regulatory requirements.
Track audit findings through corrective action and verification of effectiveness.
Coordinate certification readiness assessments.
Develop audit schedules and compliance metrics.
Support external regulatory and customer audits.
ISO 9001 / AS9100 Internal Audit Support
Partner with the Quality organization to support ISO 9001 and AS9100 internal audit activities.
Provide regulatory compliance expertise during integrated audits.
Assist in identifying opportunities to align compliance requirements with existing operational processes.
Support audit preparation and corrective action activities related to regulatory compliance.
Compliance Training & Organizational Readiness
Develop and deliver compliance training programs for employees, supervisors, and leadership.
Translate regulatory language into practical, easy-to-understand training materials.
Develop work instructions, visual standards, job aids, and awareness materials.
Coach site compliance champions and functional leaders.
Promote a culture of compliance through communication and employee engagement.
Ensure compliance training remains current with evolving regulatory requirements.
Leadership & Communication
Communicate compliance status, risks, and readiness to executive leadership.
Develop compliance dashboards and executive reporting.
Coordinate enterprise compliance initiatives across multiple business functions.
Build strong partnerships with Operations, Engineering, Facilities, Trade Compliance, Human Resources, Information Technology, and Quality.
Meets TKMNA Employee Attributes / Competencies
The above is intended to describe the general content of and requirement for the performance of this job. It is not to be construed as an exhaustive statement of duties, responsibilities or requirements.
Qualifications:
Minimum Requirements:
Bachelor's degree in Business, Manufacturing, Engineering, Operations, Compliance, or a related field.
7+ years of experience in regulatory compliance, manufacturing operations, auditing, or regulated industries.
Experience implementing and managing enterprise compliance programs.
Knowledge of CMMC/CPCSP, NIST SP 800-171, ITAR, EAR, and Controlled Unclassified Information (CUI) requirements.
Experience conducting internal compliance audits.
Demonstrated ability to interpret regulatory requirements and translate them into practical business processes.
Experience developing procedures, work instructions, and employee training programs.
Excellent project management, organizational, and communication skills.
Experience managing controlled documentation (SharePoint or similar).
Ability to travel approximately 30–40% throughout the United States and Canada.
Preferred Requirements
CMMC Certified Professional (CCP)
Experience supporting defense, aerospace, or government-contract manufacturing.
ISO 9001 or AS9100 Internal or Lead Auditor certification.
Experience leading multi-site compliance programs.
Knowledge of Canadian Controlled Goods Program (CGP), if applicable to your operations.
Job Compensation
$100k-$150k
Benefits Overview
We offer competitive company benefits to eligible positions, such as:
- Medical, Dental, Vision Insurance
- Life Insurance and Disability
- Voluntary Wellness Programs
- 401(k) or RRSP programs with Company Match
- Paid Vacation and Holidays
- Tuition Reimbursement
- And more!
Benefits may vary based on job, country, union role, and/or company segment. Please work with your recruiter or tk representative for applicable benefits information.
Disclaimer
This is to notify the general public that some individuals/entities are using the thyssenkrupp (“TK”) name, trademark, domain name, and logo without authorization. They are posing as employees, representatives, or agents of TK and its associated/group companies. These individuals/entities are fraudulently offering jobs online through texts, websites, telephone calls, emails, or by issuing fake offer letters. They are also soliciting jobseekers to deposit money in certain bank accounts or providing jobseekers with fraudulent checks to obtain banking information.
TK does not ask, solicit, or accept any monies in any form from candidates, job applicants, or potential jobseekers, who have applied to or wish to apply to TK, whether online or otherwise as a pre-employment requirement. TK bears no responsibility for money being deposited/withdrawn therefrom in response to such fake offers.
Equal opportunity employer, including people with disabilities and veterans.
Applicants with disabilities may be entitled to reasonable accommodation under the Americans with Disabilities Act and certain state or local laws. For those requiring assistance completing the application or the application process and request information relating to the need for accommodation, please contact reasonableaccommodation@thyssenkrupp.com.
TK does not:
1. Send job offers from free email services like Gmail, Rediffmail, Yahoo mail, etc.;
2. Request payment of any kind from prospective jobseekers or candidates for employment;
3. Authorize anyone to collect money or agree to any monetary arrangement in return for a job at TK;
4. Send checks to job seekers; or
5. Make job offers through third parties. In the event TK uses professional recruitment services through a third party, offers are always made directly by TK and not by any third parties.
PLEASE NOTE:
1. TK strongly recommends that potential jobseekers do not respond to such fake solicitations, in any manner;
2. TK will not be responsible to anyone acting on an employment offer that is not directly made by TK;
3. Anyone making an employment offer in return for money is not authorized by TK; and
4. TK reserves the right to take legal action, including criminal action, against such individuals/entities.
TK follows a formal recruitment process through its own HR department and applications are evaluated by its HR department through pre-defined processes. Please visit our official careers website at https://jobs.thyssenkrupp.com/en to view authentic job openings at TK.
If you receive any unauthorized, suspicious, or fraudulent offers or interview calls, please email us at tkmna.employee.care@thyssenkrupp-materials.com.














