Director IT/Cyber Policy & Governance Management
3M
Job Description:
Director IT/Cyber Policy & Governance Management
Collaborate with Innovative 3Mers Around the World
Choosing where to start and grow your career has a major impact on your professional and personal life, so it’s equally important you know that the company that you choose to work at, and its leaders, will support and guide you. With a diversity of people, global locations, technologies and products, 3M is a place where you can collaborate with other curious, creative 3Mers.
This position provides an opportunity to transition from other private, public, government or military experience to a 3M career.
The Impact You’ll Make in this Role
The Director of IT/Cyber Policy & Governance Management is responsible for both the strategic development and operational execution of the organization’s IT/Cyber Policy & Governance Management Program. The Director of IT/Cyber Policy & Governance Management provides strategic leadership over the creation, implementation, and oversight of IT policies and governance frameworks. that the IT Policy Group is responsible for. This role ensures IT policies are aligned with business objectives, regulatory requirements, and best practices for IT governance. A critical aspect of this role includes managing the policy exceptions process, ensuring all deviations from standard policies are documented, reviewed, and approved in a controlled manner and support the negotiation of client and supplier contracts to ensure adherence to 3Ms cybersecurity requirement. This role will lead Client Inquiry Process for Cybersecurity Requirements the contracting process Here, you will make an impact by:
Program Development and Management:
+ Policy Development and Implementation:
+ Develop, review, and update IT/Cyber policies, standards, and procedures to ensure they align with industry standards and organizational goals.
+ Ensure that IT policies are well-documented, communicated, and enforced across the organization.
+ Ensure all cybersecurity policies align with industry regulations (e.g., GDPR, ISO 27001, SOC 2, PCI-DSS), frameworks (e.g., NIST CSF, COBIT), and best practices.
+ Collaborate with key stakeholders across IT, legal, HR, and business units to ensure policies meet business needs and regulatory requirements and address new policy creation through an IT Policy Board.
+ Governance Frameworks:
+ Design and establish IT/Cyber governance frameworks that incorporate best practices and support the organization's strategic objectives.
+ Ensure that governance frameworks are effectively implemented and maintained.
+ Policy Exceptions/Issue Management:
+ Develop and manage a process for handling policy exceptions, including the evaluation, approval, and documentation of exceptions.
+ Work with stakeholders to assess the impact of policy exceptions and ensure that appropriate risk mitigation measures are in place
+ Stakeholder Collaboration:
+ Work closely with business units, IT/Cyber teams, and senior management to ensure IT/Cyber policies and governance frameworks align with business objectives.
+ Facilitate communication and collaboration between IT/Cyber and other departments to ensure a cohesive approach to IT governance through IT Policy Board.
+ Respond to Client Cybersecurity Inquiries
+ Collaborate and support Legal and Procurement teams to integrate 3M’s cybersecurity requirements into contract terms and conditions for client and supplier contracts
+ Performance Monitoring and Reporting:
+ Develop and monitor key performance indicators (KPIs) to measure the effectiveness of IT/Cyber policy governance.
+ Prepare and present regular reports on IT/Cyber policy adherence, governance activities, efforts to senior management.
+ Continuous Improvement:
+ Stay current with industry trends and regulatory changes, emerging technologies, and best practices in IT/Cyber policy governance.
+ Identify opportunities for process improvements and implement changes to enhance the effectiveness of IT/Cyber policy governance.
Your Skills and Expertise:
To set you up for success in this role from day one, 3M requires (at a minimum) the following qualifications:
+ Bachelor’s degree or higher (completed and verified prior to start)
+ Ten (10) years of experience in Cybersecurity in a private, public, government or military environment
+ Five (5) years of management and/or supervisor experience
+ CISSP certification or one of the following certifications such as SANS, ISACA (CGEIT, CISA, CISM, ISO 31000 CRISC, ISO 27001 Lead Auditor)
+ Multiple certifications from the list above are preferred
Additional qualifications that could help you succeed even further in this role include:
+ Master’s degree in computer engineering, computer systems or information technology field from an accredited institution
+ Minimum of 8-10 years of experience in cybersecurity/risk management, with at least 5 years in a leadership role focused on IT/Cyber Policy Management.
+ Strong knowledge of cybersecurity frameworks and standards (e.g., NIST, ISO 27001, CIS).
+ Other technology certifications e.g., ITIL, COBIT.
+ Excellent communication, negotiation, and relationship-building skills.
+ Strong analytical and problem-solving skills
+ Ability to work collaboratively with internal teams and external vendors.
Work location:
Work Your Way Eligible (hybrid) – Minneapolis & Austin
Travel: In-Office Tuesday/Wednesday/Thursday
Relocation Assistance: May be Authorized
Must be legally authorized to work in country of employment without sponsorship for employment visa status (e.g., H1B status).
Supporting Your Well-being
3M offers many programs to help you live your best life – both physically and financially. To ensure competitive pay and benefits, 3M regularly benchmarks with other companies that are comparable in size and scope.
Chat with Max
For assistance with searching through our current job openings or for more information about all things 3M, visit Max, our virtual recruiting assistant on 3M.com/careers.
Applicable to US Applicants Only:The expected compensation range for this position is $222,044 - $271,387, which includes base pay plus variable incentive pay, if eligible. This range represents a good faith estimate for this position. The specific compensation offered to a candidate may vary based on factors including, but not limited to, the candidate’s relevant knowledge, training, skills, work location, and/or experience. In addition, this position may be eligible for a range of benefits (e.g., Medical, Dental & Vision, Health Savings Accounts, Health Care & Dependent Care Flexible Spending Accounts, Disability Benefits, Life Insurance, Voluntary Benefits, Paid Absences and Retirement Benefits, etc.). Additional information is available at: https://www.3m.com/3M/en\_US/careers-us/working-at-3m/benefits/.
Good Faith Posting Date Range 02/12/2025 To 03/14/2025 Or until filled
All US-based 3M full time employees will need to sign an employee agreement as a condition of employment with 3M. This agreement lays out key terms on using 3M Confidential Information and Trade Secrets. It also has provisions discussing conflicts of interest and how inventions are assigned. Employees that are Job Grade 7 or equivalent and above may also have obligations to not compete against 3M or solicit its employees or customers, both during their employment, and for a period after they leave 3M.
Learn more about 3M’s creative solutions to the world’s problems at www.3M.com or on Instagram, Facebook, and LinkedIn @3M.
Responsibilities of this position include that corporate policies, procedures and security standards are complied with while performing assigned duties.
Pay & Benefits Overview: https://www.3m.com/3M/en\_US/careers-us/working-at-3m/benefits/
3M is an equal opportunity employer. 3M will not discriminate against any applicant for employment on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status.
Please note: your application may not be considered if you do not provide your education and work history, either by: 1) uploading a resume, or 2) entering the information into the application fields directly.
3M Global Terms of Use and Privacy Statement
Carefully read these Terms of Use before using this website. Your access to and use of this website and application for a job at 3M are conditioned on your acceptance and compliance with these terms.
Please access the linked document by clicking here (http://multimedia.3m.com/mws/media/1274940O/3m-jobs-country-data-privacy-statements-external.pdf) , select the country where you are applying for employment, and review. Before submitting your application, you will be asked to confirm your agreement with the terms.
Confirm your E-mail: Send Email
All Jobs from 3M