Global IT Security Operations & Exposure Management Lead (Remote)

Barnes Aerospace

Northern (KY)

Hybrid

USD 150,000 - 190,000

Full time

43 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Barnes Aerospace is seeking a Global IT Security Operations & Exposure Management Lead to own and scale a global security operations function remotely. You will oversee monitoring, incident response, threat detection, and remediation across cloud, on‑prem, and manufacturing environments, reporting to the CISO.

The role requires hands‑on leadership, cross‑functional collaboration with IT, engineering, and manufacturing, and the ability to translate complex security risks into clear actions.

Qualifications

  • 7+ years of progressive information security experience, including hands-on security operations, incident response, detection engineering, or exposure management.
  • Demonstrated experience leading a SOC, MDR/MSSP, or comparable global security operations.
  • Strong applied AI acumen to improve security ops, automate tasks, and reduce false positives.
  • Experience developing analysts/engineers and building operating models.
  • Practical experience with SIEM, EDR/XDR, SOAR, vulnerability management workflows, and cloud logging.
  • Experience in defense, aerospace, manufacturing, or hybrid environments preferred.
  • CISSP, CISM, CCSP, OSCP, or GIAC certifications preferred.

Responsibilities

  • Own daily security operations service delivery including ticket intake, triage, prioritization, escalation, and closure.
  • Manage performance of third-party security services and define expectations.
  • Establish severity definitions, investigation standards, and escalation paths.
  • Report health and risk metrics to the CISO with clear coverage and remediation progress.
  • Build a scalable operating model and talent roadmap for global security operations.
  • Lead incident response and post‑incident reviews; coordinate with cross‑functional teams.

Skills

Security operations
Incident response
Detection engineering
Exposure management
AI in security
Team leadership
Communication

Education

Bachelor's degree in CS/IS

Tools

SIEM
EDR/XDR
SOAR
Vulnerability management
IAM telemetry
Cloud logging

Job description

Global IT Security Operations & Exposure Management Lead (Remote)

Job Category: Information Technology

Requisition Number: GLOBA006921

  • Full-Time
  • Remote
Locations

Remote

Description

The IT Global Security Operations & Exposure Management Lead is a hands-on operational leader responsible for building and running a scalable global security operations capability. Reporting to the CISO, this role owns the effectiveness of security monitoring, incident response, security ticket operations, detection engineering, third‑party security service delivery, and the operating cadence that drives exposure to closure. The role will lead and develop internal staff as the function grows; partner closely with IT, engineering, manufacturing, and business service owners; and strengthen protection of intellectual property, manufacturing uptime, and digital modernization across legacy, cloud, and operational environments.

Core Responsibilities
  • Own daily security operations service delivery, including security ticket intake, triage, prioritization, escalation, case quality, and closure discipline
  • Manage the performance of managed security service providers and other third‑party security services, defining expectations, reviewing metrics, challenging quality, and driving corrective actions
  • Establish and maintain severity definitions, investigation standards, escalation paths, response playbooks, and executive notification criteria
  • Report operational health and risk to the CISO using clear measures of coverage, detection quality, response performance, backlog, and remediation progress
  • Build the operating model and talent roadmap for a scalable global security operations function
  • Promote a supportive, performance‑oriented culture of velocity, integrity, and teamwork
Security Operations, Incident Response, and Cyber Resilience
  • Lead enterprise‑wide security operations and incident response, including detection, triage, containment coordination, eradication support, coordination of root‑cause analysis, and post‑incident review
  • Own incident lifecycle discipline: case documentation, evidence preservation, lessons learned, corrective actions, and closure validation
  • Lead incident tabletop exercises and coordinate security participation in recovery readiness for manufacturing, engineering, and corporate environments
  • Partner with accountable IT, engineering, manufacturing, and business service owners to ensure timely remediation; infrastructure and business service owners retain accountability for recovery implementation
Exposure Management & Remediation
  • Establish the operational cadence that converts vulnerability, asset, identity, cloud, and threat findings into prioritized remediation actions
  • Partner with team members on asset coverage, vulnerability intelligence, OT/IT segmentation, and technical risk analysis, maintaining clear boundaries for analysis and operational activities
  • Track remediation commitments, challenge overdue high‑risk items, and elevate unresolved exposure to the appropriate leaders
  • Ensure security monitoring and response requirements are incorporated into major IT, cloud, engineering, and manufacturing initiatives
Detection Engineering & Platform Maturity
  • Translate CISO strategy into operational capability: telemetry standards, coverage models, automation pipelines
  • Define and continuously improve detection use cases based on threats, business‑critical services, and available telemetry
  • Improve detection fidelity through tuning, enrichment, automation, and documented use‑case lifecycle management
  • Leverage approved AI‑enabled capabilities and automation to improve detection quality, reduce false positives, accelerate investigation and response, strengthen case documentation, and identify meaningful opportunities to mature security operations using appropriate human validation, access controls, and data handling safeguards
  • Define monitoring and logging requirements for new applications, cloud services, identity platforms, and production‑connected systems; partner with accountable owners to close coverage gaps
Threat Intelligence & Countermeasures
  • Translate threat intelligence relevant to aerospace IP, supplier ecosystems, and manufacturing environments into prioritized detections, hunts, response playbooks, and countermeasures
  • Collaborate with vulnerability management, risk, and red teams to reduce attack surface
  • Understand and respond to IOCs, TTPs, ransomware and supply‑chain threats
Qualifications
  • 7+ years of progressive information security experience, including substantial hands‑on experience in security operations, incident response, detection engineering, or exposure management
  • Demonstrated experience leading a SOC, MDR/MSSP service, incident response function, or comparable global security operations capability
  • Strong applied AI acumen, with the ability to effectively evaluate and leverage generative AI, security platform AI capabilities, and automation to improve security operations, accelerate analysis and investigation, automate knowledge work, and identify high‑value opportunities for AI adoption
  • Experience managing and developing analysts/engineers is preferred; being able to build an operating model and lead through influence is essential
  • Strong practical experience with SIEM, EDR/XDR, SOAR or case management, vulnerability management workflows, IAM telemetry, cloud logging, and incident response processes
  • Experience supporting defense, aerospace, manufacturing, or similar complex hybrid environments preferred
  • Familiarity with OT/industrial security concepts and the operational constraints of production environments preferred
  • Exceptional communication skills with the ability to translate technical risk to the business
  • CISSP, CISM, CCSP, OSCP, or related GIAC certification preferred
Education Requirements
  • Bachelor's degree from an accredited college/university or equivalent experience.
Export Control

This job position may include access to controlled information or technology subject to U.S. export control laws. If an applicant does not meet the definition of a “U.S. Person” (which includes U.S. citizens, U.S. lawful permanent residents, and those granted U.S. asylum or refugee status), the Company may be required to obtain an export control license. If the position for which you applied involves access to controlled information or technology subject to U.S. export control laws, then any offer is also contingent on verification of appropriate documentation for the Company to assess whether an export license will be required to employ you in that role, and if it is determined that an export license is required, the offer is also contingent on the Company’s determination, in its sole discretion, whether a license application and ongoing administration is prudent under the project’s contract parameters and whether an export license can be successfully obtained before you can start in that role. Export license applications may take several weeks to be processed.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Global Security Governance, Risk & Compliance Manager (Remote)
Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Aerospace • United States

Remote
USD 140,000 - 190,000
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Information Technology
Information Technology

Copley Controls • Salem (NH)

Hybrid
USD 130,000 - 185,000
9/80 schedule
Flexible vacation policy
Comprehensive benefits package
+4
Lead, Cybersecurity Architecture & Operations
Lead, Cybersecurity Architecture & Operations

Culligan International • Northern (KY)

Hybrid
USD 140,000 - 180,000
Executive, Global Security Operations Center (GSOC)
Executive, Global Security Operations Center (GSOC)

GE Aerospace • Cincinnati (OH)

On-site
USD 300,000 - 520,000
Relocation assistance
Information Security Engineer
Information Security Engineer

Default Brand • Herndon (VA)

On-site
USD 100,000 - 150,000
Comprehensive benefits
Flexible time off plans
Employee development opportunities
Cyber Security Engineer
Cyber Security Engineer

Global Ordnance LLC • Sarasota (FL)

On-site
USD 90,000 - 120,000
Company-paid medical and dental for员工及
Global Cybersecurity Engineer
Global Cybersecurity Engineer

Ledgent Technology • Manassas (VA)

Hybrid
USD 140,000 - 145,000
Medical insurance
Dental insurance
Vision insurance
+5
Director, Cyber Engineering and Operations
Director, Cyber Engineering and Operations

AMETEK • Berwyn (PA)

On-site
USD 180,000 - 225,000
Security Engineer
Security Engineer

Gravity IT Resources • Salt Lake City (UT)

On-site
USD 120,000 - 160,000