Barnes Group logo

Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Group
Posted 14 hours ago
United StatesRemoteLegal & Compliance
Is this job info correct?

The Global Security GRC Manager is a senior program leader responsible for driving and sustaining governance, risk, and compliance across engineering, manufacturing, and corporate environments. Reporting to the CISO, this role leads a team of GRC professionals and owns the execution of major cross-functional initiatives like CMMC maturity, vendor risk, data protection, business continuity, and security culture. This leader operationalizes GRC strategy, ensuring controls are embedded across sites and supply chains in a manner that enables production uptime, engineering velocity, and customer confidence.

Core Responsibilities:

Program Ownership & Leadership

  • Lead enterprise-wide IT execution of CMMC and other compliance program lifecycles, including scope definition, SSP/POA&M, evidence quality and refresh cadence, assessor coordination, corrective action closure, and site-level readiness
  • Directly manage and develop a GRC team while coordinating control owners through a global matrix model
  • Translate policy and strategic objectives into repeatable, standardized processes across plants, engineering teams, and corporate functions
  • Drive remediation programs and create transparency into readiness, progress, and risk
  • Mentor, prioritize workload, develop capability, and foster global collaboration
  • Promote a supportive, performance-oriented culture of velocity, integrity, and teamwork
  • Own preparation and participation in customer and third-party audits and security questionnaires
  • Leverage AI technologies to reduce manual effort required to sustain the GRC program
  • Maintain a business-impact view of risk, track remediation commitments, and escalate gaps to leadership
  • Coordinate evidence, drive findings closure, establish sustainable corrective action plans

Security Culture

  • Champion a global security culture in which we foster accountability and risk ownership
  • Translate complex regulatory topics into clear expectations for employees
  • Partner with HR and related stakeholders to deliver targeted training, awareness, and role-based education

Global Vendor Risk Management

  • Manage the end-to-end vendor security risk lifecycle: assessments, risk treatment, remediation, and ongoing monitoring
  • Operate supplier security expectations in partnership with key stakeholders
  • Escalate systemic vendor risk trends and recommend course corrections to leadership

Data Protection

  • Govern data protection requirements for IP, manufacturing processes, export-controlled data, and cloud workloads
  • Validate consistent application of classification, DLP, access control, and retention standards

Business Continuity & Resilience

  • Govern security and compliance aspects of BC/DR readiness across manufacturing, engineering, and corporate environments
  • Define resilience-control requirements; validate that recovery playbooks, exercises, and evidence meet applicable regulatory, customer, and risk management obligations
  • Partner with accountable technology and business service owners to verify timely closure of identified gaps

Qualifications:

  • Minimum of 7 years of IT GRC, information security, or regulated compliance experience, preferably with 2 years managing a geographically diverse team
  • Demonstrated ability to use generative AI and automation responsibly to improve analysis, evidence operations, knowledge management, and workflow efficiency; experience evaluating AI risk and governance preferred
  • Defense experience strongly preferred
  • Demonstrated experience with CMMC, NIST SP 800-171, and/or DFARS readiness and audit execution
  • Strong oral and written communicator who can lead cultural changes, influence people and provide technical strategic direction
  • Demonstrated problem solving and organizational skills; ability to work multiple programs at one time
  • CISSP, CISM, CRISC, CGEIT, GRCP, CGRC, GSLC, PMP or other relevant certification preferred

Education Requirements:

  • Bachelor's degree from an accredited college/university or equivalent experience

Similar jobs