Global IT Security Operations & Exposure Management Lead (Remote)

Barnes Aerospace
United States
25 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cyber Security Identity and Access Management Intrusion Detection and Prevention Cloud Services Security Information and Event Management Software Vulnerability Management Data Logging Data Processing Delivery Pipeline

Job description

  • Own daily security operations service delivery, including security ticket intake, triage, prioritization, escalation, case quality, and closure discipline
  • Manage the performance of managed security service providers and other third-party security services, defining expectations, reviewing metrics, challenging quality, and driving corrective actions
  • Establish and maintain severity definitions, investigation standards, escalation paths, response playbooks, and executive notification criteria
  • Report operational health and risk to the CISO using clear measures of coverage, detection quality, response performance, backlog, and remediation progress
  • Build the operating model and talent roadmap for a scalable global security operations function
  • Promote a supportive, performance-oriented culture of velocity, integrity, and teamwork

Security Operations, Incident Response, and Cyber Resilience

  • Lead enterprise-wide security operations and incident response, including detection, triage, containment coordination, eradication support, coordination of root-cause analysis, and post-incident review
  • Own incident lifecycle discipline: case documentation, evidence preservation, lessons learned, corrective actions, and closure validation
  • Lead incident tabletop exercises and coordinate security participation in recovery readiness for manufacturing, engineering, and corporate environments
  • Partner with accountable IT, engineering, manufacturing, and business service owners to ensure timely remediation; infrastructure and business service owners retain accountability for recovery implementation

Exposure Management & Remediation

  • Establish the operational cadence that converts vulnerability, asset, identity, cloud, and threat findings into prioritized remediation actions
  • Partner with team members on asset coverage, vulnerability intelligence, OT/IT segmentation, and technical risk analysis, maintaining clear boundaries for analysis and operational activities
  • Track remediation commitments, challenge overdue high-risk items, and escalate unresolved exposure to the appropriate leaders
  • Ensure security monitoring and response requirements are incorporated into major IT, cloud, engineering, and manufacturing initiatives

Detection Engineering & Platform Maturity

  • Translate CISO strategy into operational capability: telemetry standards, coverage models, automation pipelines
  • Define and continuously improve detection use cases based on threats, business-critical services, and available telemetry
  • Improve detection fidelity through tuning, enrichment, automation, and documented use-case lifecycle management
  • Leverage approved AI-enabled capabilities and automation to improve detection quality, reduce false positives, accelerate investigation and response, strengthen case documentation, and identify meaningful opportunities to mature security operations using appropriate human validation, access controls, and data handling safeguards
  • Define monitoring and logging requirements for new applications, cloud services, identity platforms, and production-connected systems; partner with accountable owners to close coverage gaps

Threat Intelligence & Countermeasures

  • Translate threat intelligence relevant to aerospace IP, supplier ecosystems, and manufacturing environments into prioritized detections, hunts, response playbooks, and countermeasures
  • Collaborate with vulnerability management, risk, and red teams to reduce attack surface
  • Understand and respond to IOCs, TTPs, ransomware and supply-chain threats

Requirements

  • 7+ years of progressive information security experience, including substantial hands-on experience in security operations, incident response, detection engineering, or exposure management
  • Demonstrated experience leading a SOC, MDR/MSSP service, incident response function, or comparable global security operations capability
  • Strong applied AI acumen, with the ability to effectively evaluate and leverage generative AI, security platform AI capabilities, and automation to improve security operations, accelerate analysis and investigation, automate knowledge work, and identify high-value opportunities for AI adoption
  • Experience managing and developing analysts/engineers is preferred; being able to build an operating model and lead through influence is essential
  • Strong practical experience with SIEM, EDR/XDR, SOAR or case management, vulnerability management workflows, IAM telemetry, cloud logging, and incident response processes
  • Experience supporting defense, aerospace, manufacturing, or similar complex hybrid environments preferred
  • Familiarity with OT/industrial security concepts and the operational constraints of production environments preferred
  • Exceptional communication skills with the ability to translate technical risk to the business
  • CISSP, CISM, CCSP, OSCP, or related GIAC certification preferred

Education Requirements:

  • Bachelor’s degree from an accredited college/university or equivalent experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Loading talks and stories from around this role…