Donaldson is committed to solving the world’s most complex filtration challenges. Together, we make cool things. As an established technology and innovation leader, we are continuously evolving to meet the filtration needs of our changing world. Join a culture of collaboration and innovation that matters and a chance to learn, effect change, and make meaningful contributions at work and in communities.
The Senior Engineer, Global Governance, Risk & Compliance (GRC) is responsible for executing and advancing enterprise risk management and compliance assessment capabilities across global operations. This role leads risk tracking, assessment, and reporting processes to ensure consistent identification, prioritization, and communication of cybersecurity and regulatory risks. Qualified candidates must be able to work a hybrid schedule at our Bloomington office/facility.
Job Description
The position supports global initiatives related to IT and Information Security governance, risk, and compliance. This role is responsible for driving risk assessment execution, enhancing process maturity, and improving visibility of enterprise risk to leadership. The Senior Engineer partners with IT, Privacy, Legal, Procurement, and business stakeholders to ensure alignment with internal policies, industry standards, and global regulatory requirements.
Key Responsibilities
- Lead and maintain the enterprise GRC risk tracking framework
- Coordinate global risk review meetings with IT, business, and operational stakeholders
- Assess, rate, and prioritize security risks against internal criteria, industry standards, and regulatory requirements
- Compile and communicate risk posture to executive leadership and IT owners, ensuring appropriate awareness and accountability
- Manage and facilitate risk assessments for new technologies, processes, and acquisitions
- Improve risk assessment processes through alignment with IT architecture and Privacy
- Lead compliance assessments against internal policies, standards, and procedures
- Perform vendor and supplier security reviews, including execution of third-party risk assessments
- Review third-party attestations (e.g., SOC2), support contract security provisions with Legal, and enhance vendor risk management processes and reporting
Minimum Qualifications
- Minimum 5 years of professional-level IT and information security experience, with a focus on IT controls, risk management, data protection, and technology compliance
- Experience conducting risk assessments and evaluating controls against frameworks such as ISO 27001, NIST, or SOC2
- Communication skills (in English) in describing technical risks and issues to business and operational individuals
- Strong understanding of third-party risk management and regulatory compliance requirements
- Demonstrated ability to communicate technical risks to business and executive stakeholders
- At least one relevant, current industry certification, such as CISSP, CISM, CRISC, or CISA, etc.
Preferred Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or related field and/or corresponding experience in the necessary knowledge and skills of the position
- Experience in global or multi-regional organizations with diverse regulatory requirements
- Familiarity with some of the following: SOX 404, PCI DSS, NIST 800-171, ISO 27001, MLPS, Oracle security, IT policies, and procedures
- IT Audit/Consulting experience
- Familiarity with GRC platforms (e.g., ServiceNow, Archer or equivalent)
- Experience supporting audits, regulatory inquiries, or certification programs (e.g., ISO, TISAX, CMMC)
- Any additional current industry certification(s), such as CISSP, CISM, CRISC, or CISA, etc.
Annual Salary Range: $86,200-111,000. Actual salaries will vary based on several factors including, but not limited to applicable work experience, training, education, performance.
Employee benefits are part of the competitive total rewards package that Donaldson Company, Inc. provides to you. Our comprehensive benefits program includes health benefits, retirement plan (401k), paid time away, paid leaves (including paid parental leave) and more.
Immigration Sponsorship Not Available:
- Applicants for this position must be currently and legally authorized to work in the United States without the need for current or future sponsorship (e.g., H-1B, J-1, F-1, CPT, OPT, etc.).
- Donaldson will not offer immigration sponsorship or assume sponsorship of an employment visa for this position.
- International relocation or remote work arrangements outside of the U.S. will not be considered.
Employment opportunities for positions in the United States may require use of information which is subject to the export control regulations of the United States. Hiring decisions for such positions are required by law to be made in compliance with these regulations. Applicants for employment opportunities in other countries must be able to meet the comparable export control requirements of that country and of the United States.
Donaldson Company has been made aware that there are several recruiting scams that are targeting job seekers. These scams have attempted to solicit money for job applications and/or collect confidential information, Donaldson will never solicit money during the application or recruiting process. Donaldson only accepts online applications through our Careers | Donaldson Company, Inc. website and any communication from a Donaldson recruiter would be sent using a donaldson.com email address. If you have any questions about the legitimacy of an employment opportunity, please reach out to [email protected] to verify that the communication is from Donaldson.
Our policy is to provide equal employment opportunities to all qualified persons without regard to race, gender, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity and/or expression, or other status protected by law.
Skills Required
- Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or related field and/or equivalent experience
- Minimum 5 years of professional IT and information security experience focused on IT controls, risk management, data protection, and technology compliance
- Experience conducting risk assessments and evaluating controls against frameworks such as ISO 27001, NIST, or SOC2
- Communication skills in English to describe technical risks to business and operational stakeholders
- Strong understanding of third-party risk management and regulatory compliance requirements
- Demonstrated ability to communicate technical risks to business and executive stakeholders
- At least one relevant, current industry certification (CISSP, CISM, CRISC, or CISA)
- Experience in global or multi-regional organizations with diverse regulatory requirements
- Familiarity with SOX 404, PCI DSS, NIST 800-171, ISO 27001, MLPS, Oracle security, IT policies and procedures
- IT Audit or Consulting experience
- Familiarity with GRC platforms (e.g., ServiceNow, Archer or equivalent)
- Experience supporting audits, regulatory inquiries, or certification programs (e.g., ISO, TISAX, CMMC)
- Additional current industry certifications (CISSP, CISM, CRISC, CISA)
Donaldson Company Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Donaldson Company and has not been reviewed or approved by Donaldson Company.
-
Retirement Support — Retirement programs like a 401(k) match, profit-sharing, and an employee stock purchase plan are positioned as meaningful components of total compensation. Company materials consistently frame retirement benefits within a broader Total Rewards offering.
-
Healthcare Strength — Medical, dental, vision, and a 24/7 Employee Assistance Program with mental‑health resources create a comprehensive health and wellbeing package. Healthcare is often characterized as decent and a core strength of the overall offering.
-
Leave & Time Off Breadth — Paid time off, holidays, and paid parental leave are explicitly included, alongside other company‑paid leaves such as bereavement, jury duty, and military leave. Some locations highlight multi‑week PTO from the first year, underscoring breadth of leave options.
Donaldson Company Insights
What We Do
Donaldson Company helps solve some of the world's most complex filtration and contamination control challenges, and is one of the largest global providers of unique filtration technologies and high-quality filters and parts. Our filtration technologies and products are used every day, in a variety of industries and environments, including aerospace, agriculture, construction, food and beverage, manufacturing, mining, power generation, transportation and many more. Key to our success, our 14,000 employees support customers at sales, manufacturing and distribution centers from over 140 locations on six continents. The filtration market continues to grow. Customers' needs for filtration solutions continue to evolve. And the opportunities for our products and our people continue to expand.
.png)








