Global Security Governance, Risk and Compliance Manager (Remote)

Barnes AerospaceRemoteFull-timeSenior, 5–8 yearsListed 3 days ago

Apply now

About this role

The Global Security GRC Manager is a senior program leader responsible for driving and sustaining governance, risk, and compliance across engineering, manufacturing, and corporate environments. Reporting to the CISO, this role leads a team of GRC professionals and owns the execution of major cross-functional initiatives like CMMC maturity, vendor risk, data protection, business continuity, and security culture. This leader operationalizes GRC strategy, ensuring controls are embedded across sites and supply chains in a manner that enables production uptime, engineering velocity, and customer confidence.

Core Responsibilities:

Program Ownership & Leadership

- Lead enterprise-wide IT execution of CMMC and other compliance program lifecycles, including scope definition, SSP/POA&M, evidence quality and refresh cadence, assessor coordination, corrective action closure, and site-level readiness

- Directly manage and develop a GRC team while coordinating control owners through a global matrix model

- Translate policy and strategic objectives into repeatable, standardized processes across plants, engineering teams, and corporate functions

- Drive remediation programs and create transparency into readiness, progress, and risk

- Mentor, prioritize workload, develop capability, and foster global collaboration

- Promote a supportive, performance-oriented culture of velocity, integrity, and teamwork

- Own preparation and participation in customer and third-party audits and security questionnaires

- Leverage AI technologies to reduce manual effort required to sustain the GRC program

- Maintain a business-impact view of risk, track remediation commitments, and escalate gaps to leadership

- Coordinate evidence, drive findings closure, establish sustainable corrective action plans

Security Culture

- Champion a global security culture in which we foster accountability and risk ownership

- Translate complex regulatory topics into clear expectations for employees

- Partner with HR and related stakeholders to deliver targeted training, awareness, and role-based education

Global Vendor Risk Management

- Manage the end-to-end vendor security risk lifecycle: assessments, risk treatment, remediation, and ongoing monitoring

- Operate supplier security expectations in partnership with key stakeholders

- Escalate systemic vendor risk trends and recommend course corrections to leadership

Data Protection

- Govern data protection requirements for IP, manufacturing processes, export-controlled data, and cloud workloads

- Validate consistent application of classification, DLP, access control, and retention standards

Business Continuity & Resilience

- Govern security and compliance aspects of BC/DR readiness across manufacturing, engineering, and corporate environments

- Define resilience-control requirements; validate that recovery playbooks, exercises, and evidence meet applicable regulatory, customer, and risk management obligations

- Partner with accountable technology and business service owners to verify timely closure of identified gaps

Qualifications:

- Minimum of 7 years of IT GRC, information security, or regulated compliance experience, preferably with 2 years managing a geographically diverse team

- Demonstrated ability to use generative AI and automation responsibly to improve analysis, evidence operations, knowledge management, and workflow efficiency; experience evaluating AI risk and governance preferred

- Defense experience strongly preferred

- Demonstrated experience with CMMC, NIST SP 800-171, and/or DFARS readiness and audit execution

- Strong oral and written communicator who can lead cultural changes, influence people and provide technical strategic direction

- Demonstrated problem solving and organizational skills; ability to work multiple programs at one time

- CISSP, CISM, CRISC, CGEIT, GRCP, CGRC, GSLC, PMP or other relevant certification preferred

Education Requirements:

- Bachelor's degree from an accredited college/university or equivalent experience