Global Security Governance, Risk & Compliance Manager (Remote)
Barnes GroupThe Global Security GRC Manager is a senior program leader responsible for driving and sustaining governance, risk, and compliance across engineering, manufacturing, and corporate environments. Reporting to the CISO, this role leads a team of GRC professionals and owns the execution of major cross-functional initiatives like CMMC maturity, vendor risk, data protection, business continuity, and security culture. This leader operationalizes GRC strategy, ensuring controls are embedded across sites and supply chains in a manner that enables production uptime, engineering velocity, and customer confidence.
Core Responsibilities:
Program Ownership & Leadership
- Lead enterprise-wide IT execution of CMMC and other compliance program lifecycles, including scope definition, SSP/POA&M, evidence quality and refresh cadence, assessor coordination, corrective action closure, and site-level readiness
- Directly manage and develop a GRC team while coordinating control owners through a global matrix model
- Translate policy and strategic objectives into repeatable, standardized processes across plants, engineering teams, and corporate functions
- Drive remediation programs and create transparency into readiness, progress, and risk
- Mentor, prioritize workload, develop capability, and foster global collaboration
- Promote a supportive, performance-oriented culture of velocity, integrity, and teamwork
- Own preparation and participation in customer and third-party audits and security questionnaires
- Leverage AI technologies to reduce manual effort required to sustain the GRC program
- Maintain a business-impact view of risk, track remediation commitments, and escalate gaps to leadership
- Coordinate evidence, drive findings closure, establish sustainable corrective action plans
Security Culture
- Champion a global security culture in which we foster accountability and risk ownership
- Translate complex regulatory topics into clear expectations for employees
- Partner with HR and related stakeholders to deliver targeted training, awareness, and role-based education
Global Vendor Risk Management
- Manage the end-to-end vendor security risk lifecycle: assessments, risk treatment, remediation, and ongoing monitoring
- Operate supplier security expectations in partnership with key stakeholders
- Escalate systemic vendor risk trends and recommend course corrections to leadership
Data Protection
- Govern data protection requirements for IP, manufacturing processes, export-controlled data, and cloud workloads
- Validate consistent application of classification, DLP, access control, and retention standards
Business Continuity & Resilience
- Govern security and compliance aspects of BC/DR readiness across manufacturing, engineering, and corporate environments
- Define resilience-control requirements; validate that recovery playbooks, exercises, and evidence meet applicable regulatory, customer, and risk management obligations
- Partner with accountable technology and business service owners to verify timely closure of identified gaps
Qualifications:
- Minimum of 7 years of IT GRC, information security, or regulated compliance experience, preferably with 2 years managing a geographically diverse team
- Demonstrated ability to use generative AI and automation responsibly to improve analysis, evidence operations, knowledge management, and workflow efficiency; experience evaluating AI risk and governance preferred
- Defense experience strongly preferred
- Demonstrated experience with CMMC, NIST SP 800-171, and/or DFARS readiness and audit execution
- Strong oral and written communicator who can lead cultural changes, influence people and provide technical strategic direction
- Demonstrated problem solving and organizational skills; ability to work multiple programs at one time
- CISSP, CISM, CRISC, CGEIT, GRCP, CGRC, GSLC, PMP or other relevant certification preferred
Education Requirements:
- Bachelor's degree from an accredited college/university or equivalent experience