Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Aerospace

United States

Remote

USD 140,000 - 190,000

Full time

12 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Barnes Aerospace is seeking a Global Security Governance, Risk & Compliance Manager to lead GRC across engineering, manufacturing, and corporate environments. This remote role reports to the CISO and directs a global team to drive CMMC maturity, vendor risk, data protection, and business continuity while maintaining production uptime and customer trust.

The ideal candidate has 7+ years in IT GRC or regulated compliance, strong leadership, and experience with AI-assisted governance.

Qualifications

  • Minimum of 7 years of IT GRC, information security, or regulated compliance experience.
  • Experience leading a geographically diverse team.
  • Ability to apply AI responsibly to governance and evidence operations.
  • Defense experience and familiarity with CMMC/NIST DFARS preferred.
  • Excellent written and verbal communication with stakeholder influence.

Responsibilities

  • Lead enterprise-wide IT execution of GRC programs including CMMC readiness and audits.
  • Directly manage a GRC team and coordinate across a global matrix.
  • Translate policy into repeatable processes across plants and functions.
  • Drive remediation programs and provide transparency on risk and progress.
  • Mentor teams, foster collaboration, and drive a high-velocity culture.
  • Prepare for customer and third-party audits and security questionnaires.
  • Leverage AI to reduce manual effort in GRC operations.

Skills

IT GRC
Information Security
Regulatory Compliance
AI and Automation
Communication
Leadership
Problem Solving

Education

Bachelor's degree

Job description

Global Security Governance, Risk & Compliance Manager (Remote)

Job Category: Information Technology

Requisition Number: GLOBA006920

  • Full-Time
  • Remote
Locations

Showing 1 location

Remote

Description

The Global Security GRC Manager is a senior program leader responsible for driving and sustaining governance, risk, and compliance across engineering, manufacturing, and corporate environments. Reporting to the CISO, this role leads a team of GRC professionals and owns the execution of major cross-functional initiatives like CMMC maturity, vendor risk, data protection, business continuity, and security culture. This leader operationalizes GRC strategy, ensuring controls are embedded across sites and supply chains in a manner that enables production uptime, engineering velocity, and customer confidence.

Core Responsibilities:

  • Lead enterprise-wide IT execution of CMMC and other compliance program lifecycles, including scope definition, SSP/POA&M, evidence quality and refresh cadence, assessor coordination, corrective action closure, and site-level readiness
  • Directly manage and develop a GRC team while coordinating control owners through a global matrix model
  • Translate policy and strategic objectives into repeatable, standardized processes across plants, engineering teams, and corporate functions
  • Drive remediation programs and create transparency into readiness, progress, and risk
  • Mentor, prioritize workload, develop capability, and foster global collaboration
  • Promote a supportive, performance-oriented culture of velocity, integrity, and teamwork
  • Own preparation and participation in customer and third-party audits and security questionnaires
  • Leverage AI technologies to reduce manual effort required to sustain the GRC program
  • Maintain a business-impact view of risk, track remediation commitments, and elevate gaps to leadership

Security Culture

  • Champion a global security culture in which we foster accountability and risk ownership
  • Translate complex regulatory topics into clear expectations for employees
  • Partner with HR and related stakeholders to deliver targeted training, awareness, and role-based education
  • Manage the end-to-end vendor security risk lifecycle: assessments, risk treatment, remediation, and ongoing monitoring
  • Operate supplier security expectations in partnership with key stakeholders
  • Escalate systemic vendor risk trends and recommend course corrections to leadership

Data Protection

  • Govern data protection requirements for IP, manufacturing processes, export-controlled data, and cloud workloads
  • Validate consistent application of classification, DLP, access control, and retention standards

Business Continuity & Resilience

  • Govern security and compliance aspects of BC/DR readiness across manufacturing, engineering, and corporate environments
  • Define resilience-control requirements; validate that recovery playbooks, exercises, and evidence meet applicable regulatory, customer, and risk management obligations
  • Partner with accountable technology and business service owners to verify timely closure of identified gaps

Qualifications:

  • Minimum of 7 years of IT GRC, information security, or regulated compliance experience, preferably with 2 years managing a geographically diverse team
  • Demonstrated ability to use generative AI and automation responsibly to improve analysis, evidence operations, knowledge management, and workflow efficiency; experience evaluating AI risk and governance preferred
  • Defense experience strongly preferred
  • Demonstrated experience with CMMC, NIST SP 800-171, and/or DFARS readiness and audit execution
  • Strong oral and written communicator who can lead cultural changes, influence people and provide technical strategic direction
  • Demonstrated problem solving and organizational skills; ability to work multiple programs at one time
  • CISSP, CISM, CRISC, CGEIT, GRCP, CGRC, GSLC, PMP or other relevant certification preferred

Education Requirements:

  • Bachelor's degree from an accredited college/university or equivalent experience

This job position may include access to controlled information or technology subject to U.S. export control laws. If an applicant does not meet the definition of a “U.S. Person” (which includes U.S. citizens, U.S. lawful permanent residents, and those granted U.S. asylum or refugee status), the Company may be required to obtain an export control license. If the position for which you applied involves access to controlled information or technology subject to U.S. export control laws, then any offer is also contingent on verification of appropriate documentation for the Company to assess whether an export license will be required to employ you in that role, and if it is determined that an export license is required, the offer is also contingent on the Company’s determination, in its sole discretion, whether a license application and ongoing administration is prudent under the project’s contract parameters and whether an export license can be successfully obtained before you can start in that role. Export license applications may take several weeks to be processed.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, IT Risk & Compliance 2
Manager, IT Risk & Compliance 2

Celestica • United States

On-site
USD 107,000 - 147,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • North Stonington (CT)

On-site
USD 90,000 - 110,000
Employee-owned company
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Global IT Security Operations & Exposure Management Lead (Remote)
Global IT Security Operations & Exposure Management Lead (Remote)

Barnes Aerospace • Northern (KY)

Hybrid
USD 150,000 - 190,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
Employee-owned
Equal opportunity employer
GRC Analyst II
GRC Analyst II

Frontgrade Technologies • Colorado Springs (CO)

On-site
USD 70,000 - 90,000
Immediate Medical, Dental, and Vision
401K Match with 100% immediate vesting
Tuition Reimbursement/Student Loan Repayment
+2
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus Corp. • Neenah (WI)

On-site
USD 112,600 - 169,000
Sr Manager - IT Governance, Risk and Compliance
Sr Manager - IT Governance, Risk and Compliance

Plexus Corp • Neenah (WI)

On-site
USD 130,000 - 194,000
Medical insurance
Dental insurance
Vision insurance
+3
Manager, IT Security, Governance, Risk and Compliance
Manager, IT Security, Governance, Risk and Compliance

Burlington Stores, Inc. • Beverly (NJ)

Hybrid
USD 115,000 - 150,000
Medical, dental, and vision coverage
Paid time off and holidays
401(k) plan