US Jobs US Jobs     UK Jobs UK Jobs     EU Jobs EU Jobs


Global Senior Manager, Cybersecurity

POSITION PURPOSE

The Global Senior Manager, Cybersecurity leads the Baltimore Aircoil Company, Inc.

(hereby known as “BAC”)’s day-to-day security program inclusive of protecting corporate IT, the products the company builds, and the AI capabilities now being introduced across the business.  This role covers the full traditional security mandate (operations, architecture, identity, vulnerability management, incident response, compliance) plus product security for the company's engineered products, and AI security for the growing footprint of AI and self-service data tools.  BAC operates globally, including in complex regions such as China, and this role is expected to bring a seasoned perspective about running a security program in those environments.  This is a hands-on
leadership role reporting into the Infrastructure, Operations and Security organization, balancing strategic program ownership with execution, partnering with peers across the team to plan and implement actions to
progress the company’s cybersecurity posture and compliance.  This role is expected to collaborate directly with the Amsted group Security Operations Center (SOC) and other Amsted entity security leaders to define and execute the multi-year security roadmap.

PRINCIPAL ACCOUNTABILITIES
Core Cybersecurity:
• Security Operations: in collaboration with the Amsted SOC, owns BAC’s security monitoring, detection, and response across the enterprise and the tools that support it (SIEM, EDR, XDR).
• Incident Response: owns creation and execution of the incident response program (i.e., plans, playbooks, tabletop exercises, and live response); leads incident response readiness, security incident investigations, crisis coordination, and executive communications in partnership with legal, compliance, and business stakeholders.
• Vulnerability & Threat Management: in collaboration with the Amsted SOC, runs the enterprise
vulnerability management program, including scanning, patch prioritization, penetration testing, and
red/purple team exercises, with clear metrics on time-to-remediate.
• Identity & Access Security: in collaboration with the Amsted SOC and Amsted security council,
design and implement a comprehensive security program spanning identity and access management
(IAM), endpoint protection, data loss prevention (DLP), and threat intelligence.

Application-level
governance, including SAP roles, profiles, and segregation of duties, is owned the by the Digital Applications & Product Delivery team.
• Security Architecture: partner with Enterprise Architecture and Infrastructure to embed security requirements into network, cloud, and application architecture decisions.
• Governance, Risk, and Compliance: owns the security policy framework and leads the enterprise through relevant audits and certifications (e.g., SOC 2, ISO 27001, NIST CSF) and supports customer and regulatory security questionnaires.
• Security Awareness: runs the company's security...




Share Job