Director Governance, Risk, and Compliance
Westminster, CO, US, 80021
At Ball, integrity and trust are the foundation of who we are. Guided by our core values—"We Care. We Work. We Win.”—we create a culture where every voice matters and every idea drives progress.
Together with our global employees, customers, and partners, we’re turning bold sustainability goals into reality and shaping a future we can all be proud of.
Create a new future. Apply Today.
The Director of Cybersecurity Governance, Risk, and Compliance (GRC) is accountable for enterprise‑wide cyber risk governance, regulatory compliance strategy, and board‑level risk reporting for Ball Corporation’s global manufacturing and supply‑chain‑driven business. This role sets the enterprise cyber risk posture, translates business risk appetite into enforceable governance mechanisms, and ensures cybersecurity risk is measured, reported, and managed as a business risk and not a purely technical concern. The Director serves as Ball’s primary authority on cybersecurity risk governance, regulatory alignment, and assurance, and acts as a trusted advisor to the CISO, executive leadership, Legal, Internal Audit, and the Board.
The role owns and governs all Security GRC sub‑capabilities: 1) Security Governance & Program Management, 2) Security Risk Management, 3) Security Assessments & Compliance Management, 4) Cyber‑Supply Chain Risk Management, 5) Business Continuity Planning (cyber integration), 6) Security Training & Awareness, 7) Cyber Metrics and Reporting.
Essential Responsible Areas:
- Establish and maintain the enterprise cybersecurity governance framework, including policies, standards, risk taxonomy, and accountability models.
- Define and operationalize the enterprise cyber risk management program, including risk identification, assessment, prioritization, escalation, and reporting.
- Own executive‑ and Board‑level cybersecurity risk & metrics reporting, ensuring alignment to business impact, materiality, and risk tolerance.
- Lead the global cybersecurity compliance strategy, ensuring alignment with applicable regulatory, legal, and contractual requirements.
- Provide senior oversight of cybersecurity audits, assessments, and assurance activities; ensure consistent and defensible outcomes.
- Govern cyber supply‑chain and third‑party risk management, embedding security risk considerations into vendor lifecycle processes.
- Ensure cybersecurity risk is integrated into business continuity, crisis management, and enterprise resilience planning.
- Lead, develop, and mentor the Security GRC leadership team and establish clear interfaces with other cybersecurity and business functions.
- Ensure cybersecurity governance and compliance requirements are appropriately tailored to regional regulatory, legal, and operational realities while maintaining global consistency.
- Partner with regional business and technology leaders to address localized cyber risk scenarios, including manufacturing, operational technology (OT), and supply‑chain considerations.
- Oversee regional regulatory compliance obligations (e.g., data protection, critical infrastructure, export controls) and support regulatory inquiries or audits as required.
- Enable effective risk communication and escalation between regions and corporate leadership, ensuring timely visibility of material risks.
Professional & Education Qualification
- Bachelor’s degree in Information Security, Computer Science, Risk Management, Business Administration, or a related discipline required. Master’s degree (e.g., MBA, MS in Information Security or Risk Management) strongly preferred.
- Minimum of 15 years of progressive experience in cybersecurity, technology risk, or enterprise risk management, including 7+ years leading enterprise‑scale GRC, risk, or compliance functions within complex, global organizations.
- Demonstrated experience operating in regulated, asset‑intensive, or manufacturing‑centric environments.
- CISSP or CISM certification required. CRISC, CGEIT, or equivalent risk‑focused certification strongly preferred
Skills
- Executive‑level communication skills with the ability to translate complex cybersecurity risk into clear business and financial impact.
- Strong leadership and people‑management capabilities, with experience building and scaling governance or risk teams.
- Proven ability to influence without authority and drive alignment across technology, legal, finance, operations, and executive stakeholders.
- Analytical and strategic thinking skills, with the ability to prioritize risk based on probability, impact, and business criticality.
- Sound judgment under pressure, particularly in high‑visibility risk, audit, or incident scenarios.
- Ability to balance regulatory rigor with business enablement and operational practicality.
Knowledge
- Deep knowledge of cybersecurity governance, risk, and compliance frameworks and practices (e.g., NIST CSF, ISO 27001/31000, SOX ITGC, data protection regulations).
- Strong understanding of cybersecurity risks impacting global manufacturing, operational technology, and supply‑chain ecosystems.
- Familiarity with regulatory expectations related to cybersecurity disclosures, audits, and assurance.
- Working knowledge of incident response, business continuity, and crisis management from a governance and oversight perspective.
- Understanding of how cybersecurity risk intersects with safety, operational resilience, financial performance, and brand trust.
Compensation & Benefits:
- Expected Hiring Salary Range: $143,000, - $209,060 (Salary to be determined by the applicant’s education, experience, knowledge, skills, and abilities, as well as internal equity and alignment with market data.)
- This role will be eligible to participate in the annual incentive compensation plan.
- Please visit our "Total Rewards" page to learn more about Ball’s comprehensive benefits structure.
- Onsite Work Environment: This position is based in [add the location here] and requires regular in-person engagement by working on-site. Travel and local commute between Ball locations and other possible non-Ball locations may be required.
- Hybrid On-Site Work Environment: Based in Colorado, this position requires regular in-person engagement by working on-site for { DIRECTOR & ABOVE: four (4) or more days } { BELOW DIRECTOR three (3) or more work days} per work week (with core collaboration days of Tuesday, Wednesday, and Thursday). [Travel and local commute between Ball locations and other possible non-Ball locations may be required.]
When submitting your application to Ball, we encourage you to emphasize your skills, experience, and qualifications that align with the role.
Ball Corporation is proud to be an Equal Opportunity Employer. We actively encourage applications from everybody. All qualified job applicants will receive consideration without regard to race, color, religion, creed, national origin, aboriginality, genetic information, ancestry, marital status, sex, sexual orientation, gender identity or expression, physical or mental disability, pregnancy, veteran status, age, political affiliation or any other non-merit characteristic.
Please note the advertised job title might vary from the job title on the contract due to local job title structure and global HR systems.
- Under Colorado, California, Connecticut, Minnesota, and Pennsylvania law, you have the right to exclude or redact age-related details—such as your date of birth, school attendance dates, or graduation dates—from your resume, cover letter, CV, or other supporting documents (e.g., transcripts, certificates).
- Legal authorization to work in the U.S. We will not sponsor individuals for employment visa, now or in the future, for this job opening.
* This position will be posted internally for a minimum of 5 days and will remain open until filled or adjusted based on the volume of applicants.
No agencies please.
Global Grade 14A
Nearest Major Market: Denver