Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Group

United States

Remote

USD 140,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Barnes Group is seeking a Global Security GRC Manager to lead governance, risk, and compliance across engineering, manufacturing, and corporate functions. Reporting to the CISO, you will build and mentor a GRC team, drive cross-functional initiatives, and embed controls across sites and supply chains to sustain production uptime and customer confidence.

You will oversee audits, leverage AI to streamline evidence operations, and promote a culture of accountability and velocity.

Qualifications

  • Minimum 7 years of IT GRC or regulated compliance experience, with optional 2+ years leading a geographically diverse team.
  • Demonstrated ability to use generative AI and automation to improve analysis, evidence ops, knowledge mgmt, and workflow efficiency; AI governance experience is a plus.
  • Defense industry experience strongly preferred.
  • Experience with CMMC, NIST SP 800-171, and/or DFARS readiness and audit execution.
  • Excellent oral and written communication; ability to lead cultural changes and provide strategic direction.
  • Demonstrated problem solving and organizational skills; capable of handling multiple programs simultaneously.
  • CISSP / CISM / CRISC / CGEIT / GRCP / CGRC / GSLC / PMP or other relevant certification preferred.

Responsibilities

  • Lead enterprise-wide IT execution of CMMC and other compliance lifecycles, including scope, SSP/POA&M, evidence quality, assessor coordination, corrective action closure, and site readiness.
  • Directly manage and develop a GRC team while coordinating control owners through a global matrix model.
  • Translate policy and strategic objectives into repeatable, standardized processes across plants, engineering teams, and corporate functions.
  • Drive remediation programs and create transparency into readiness, progress, and risk.
  • Mentor, prioritize workload, develop capability, and foster global collaboration.
  • Promote a performance-oriented culture of velocity, integrity, and teamwork.
  • Own preparation and participation in customer and third-party audits and security questionnaires.
  • Leverage AI technologies to reduce manual effort required to sustain the GRC program.
  • Maintain a business-impact view of risk, track remediation commitments, and elevate gaps to leadership.
  • Coordinate evidence, drive findings closure, establish sustainable corrective action plans.
  • Champion a global security culture with accountability and risk ownership.
  • Translate complex regulatory topics into clear employee expectations.
  • Partner with HR to deliver targeted training, awareness, and role-based education.
  • Manage end-to-end vendor security risk lifecycle: assessments, remediation, and monitoring.
  • Operate supplier security expectations with key stakeholders.
  • Escalate systemic vendor risk trends and advise leadership on course corrections.
  • Govern data protection requirements for IP, manufacturing data, export-controlled data, and cloud workloads.
  • Validate classification, DLP, access control, and retention standards.
  • Govern BC/DR readiness across manufacturing, engineering, and corporate environments.
  • Define resilience-control requirements; ensure recovery playbooks and evidence meet regulatory, customer, and risk obligations.
  • Work with technology and business service owners to close identified gaps.

Skills

7+ years IT GRC / regulated compliance
AI & automation usage
Defense experience
Strong communication
Problem solving

Education

Bachelor's degree

Job description

The Global Security GRC Manager is a senior program leader responsible for driving and sustaining governance, risk, and compliance across engineering, manufacturing, and corporate environments. Reporting to the CISO, this role leads a team of GRC professionals and owns the execution of major cross-functional initiatives like CMMC maturity, vendor risk, data protection, business continuity, and security culture. This leader operationalizes GRC strategy, ensuring controls are embedded across sites and supply chains in a manner that enables production uptime, engineering velocity, and customer confidence.

Core Responsibilities

Program Ownership & Leadership

  • Lead enterprise-wide IT execution of CMMC and other compliance program lifecycles, including scope definition, SSP/POA&M, evidence quality and refresh cadence, assessor coordination, corrective action closure, and site-level readiness
  • Directly manage and develop a GRC team while coordinating control owners through a global matrix model
  • Translate policy and strategic objectives into repeatable, standardized processes across plants, engineering teams, and corporate functions
  • Drive remediation programs and create transparency into readiness, progress, and risk
  • Mentor, prioritize workload, develop capability, and foster global collaboration
  • Promote a supportive, performance-oriented culture of velocity, integrity, and teamwork
  • Own preparation and participation in customer and third-party audits and security questionnaires
  • Leverage AI technologies to reduce manual effort required to sustain the GRC program
  • Maintain a business-impact view of risk, track remediation commitments, and elevate gaps to leadership
  • Coordinate evidence, drive findings closure, establish sustainable corrective action plans

Security Culture

  • Champion a global security culture in which we foster accountability and risk ownership
  • Translate complex regulatory topics into clear expectations for employees
  • Partner with HR and related stakeholders to deliver targeted training, awareness, and role-based education

Global Vendor Risk Management

  • Manage the end-to-end vendor security risk lifecycle: assessments, risk treatment, remediation, and ongoing monitoring
  • Operate supplier security expectations in partnership with key stakeholders
  • Escalate systemic vendor risk trends and recommend course corrections to leadership

Data Protection

  • Govern data protection requirements for IP, manufacturing processes, export-controlled data, and cloud workloads
  • Validate consistent application of classification, DLP, access control, and retention standards

Business Continuity & Resilience

  • Govern security and compliance aspects of BC/DR readiness across manufacturing, engineering, and corporate environments
  • Define resilience-control requirements; validate that recovery playbooks, exercises, and evidence meet applicable regulatory, customer, and risk management obligations
  • Partner with accountable technology and business service owners to verify timely closure of identified gaps
Qualifications
  • Minimum of 7 years of IT GRC, information security, or regulated compliance experience, preferably with 2 years managing a geographically diverse team
  • Demonstrated ability to use generative AI and automation responsibly to improve analysis, evidence operations, knowledge management, and workflow efficiency; experience evaluating AI risk and governance preferred
  • Defense experience strongly preferred
  • Demonstrated experience with CMMC, NIST SP 800-171, and/or DFARS readiness and audit execution
  • Strong oral and written communicator who can lead cultural changes, influence people and provide technical strategic direction
  • Demonstrated problem solving and organizational skills; ability to work multiple programs at one time
  • CISSP, CISM, CRISC, CGEIT, GRCP, CGRC, GSLC, PMP or other relevant certification preferred
Education Requirements
  • Bachelor's degree from an accredited college/university or equivalent experience

This job position may include access to controlled information or technology subject to U.S. export control laws. If an applicant does not meet the definition of a "U.S. Person" (which includes U.S. citizens, U.S. lawful permanent residents, and those granted U.S. asylum or refugee status), the Company may be required to obtain an export control license. If the position for which you applied involves access to controlled information or technology subject to U.S. export control laws, then any offer is also contingent on verification of appropriate documentation for the Company to assess whether an export license will be required to employ you in that role, and if it is determined that an export license is required, the offer is also contingent on the Company’s determination, in its sole discretion, whether a license application and ongoing administration is prudent under the project’s contract parameters and whether an export license can be successfully obtained before you can start in that role. Export license applications may take several weeks to be processed.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Global Security Governance, Risk & Compliance Manager (Remote)
Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Aerospace • United States

Remote
USD 140,000 - 190,000
Manager, IT Risk & Compliance 2
Manager, IT Risk & Compliance 2

Celestica • United States

On-site
USD 107,000 - 147,000
Manager, Information Security Governance, Risk & Compliance (GRC)
Manager, Information Security Governance, Risk & Compliance (GRC)

Burtch Works • United States

Remote
USD 140,000 - 170,000
Health and wellness benefits
Remote, US-based work
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • North Stonington (CT)

On-site
USD 90,000 - 110,000
Employee-owned company
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
USD 86,450 - 113,750
Employee-owned
Equal opportunity employer
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
GRC Lead
GRC Lead

Jobtailor • Houston (TX)

On-site
USD 120,000 - 180,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000