We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
Remote New

Cybersecurity Lead Analyst

Chromalloy Gas Turbine, LLC
120,792 USD-158,540 USD
parental leave, paid time off, paid holidays, sick time, 401(k)
United States
Oct 10, 2025

Chromalloy is a global engineering & solutions company. We are a leadings provider of aftermarket parts, repairs, and solutions that safely & reliably extend the life of aircraft engines and gas turbines. We develop, manufacture and repair critical turbine components for a range of engine platforms. Our solutions support the engines running the aerospace, energy and defense industries around the world.


Video: What We Do


Why work at Chromalloy?


Chromalloy employees are proud, passionate problem-solvers who strive to live our values every day. A career with Chromalloy is an opportunity to learn from top industry experts, work with important technologies, and unlock a passion for innovation. Join our team of experts, innovators and problem-solvers delivering world-class solutions for our customers. As a global company, we are committed to creating an inclusive environment where all employees feel represented, heard, and able to bring their best selves to work every day. Be part of something bigger with Chromalloy!


Our Total Rewards Program is designed to support you today and in the future.



  • Comprehensive and flexible benefit options starting on day one, including medical, dental, vision, EAP, wellness incentives, and 401(k) with employer matching.
  • Development & progression opportunities for every employee - regular performance conversations, training and development curriculum, and engineering fellowship programs.
  • Paid time off, including vacation, sick time, paid holidays, floating holidays, and parental leave-all eligible on your first day of employment!
  • Competitive pay, including eligibility for quarterly and annual bonuses, depending on role and site.


Eligibility for individual benefit plans may vary based on employment status.

We are seeking a highly experienced analyst to lead and support advanced cybersecurity initiatives across our enterprise, with a strong emphasis on aerospace and defense manufacturing environments. This role requires deep technical expertise in data protection, operational technology (OT) governance, digital forensics, and secure infrastructure. The ideal candidate will have a proven track record in implementing NIST 800-171 controls and supporting compliance efforts in regulated industries.



Responsibilities:

  • Serve as a technical lead and subject matter expert for cybersecurity projects and initiatives.
  • Design, implement, and maintain security architectures that align with business and regulatory requirements.
  • Collaborate with cross-functional teams including IT, engineering, legal, and compliance to ensure security is embedded across systems and processes.
  • Conduct risk assessments and threat modeling to identify vulnerabilities and recommend mitigation strategies.
  • Develop and maintain security plans, and procedures, support maintenance of policies and standards.
  • Monitor and respond to security incidents, ensuring timely resolution and documentation.
  • Mentor junior security analysts and leads and contribute to team development and knowledge sharing.
  • Stay current with emerging threats, technologies, and industry best practices.
  • Support audits, assessments, and reporting for internal and external stakeholders.
  • Advocate for security awareness and training across the organization.



Key Responsibilities:

  • DLP Strategy & Execution
    Lead the evaluation, selection, and deployment of modern Data Loss Prevention (DLP) solutions to replace legacy systems, ensuring alignment with compliance and business needs.
  • Operational Technology (OT) Governance
    Develop and enforce security policies and controls for OT environments, including ICS/SCADA systems, with a focus on secure integration in aerospace and defense manufacturing settings.
  • Digital Forensics & Investigations
    Conduct forensic analysis of security incidents, support internal investigations, and maintain proper chain-of-custody and evidence handling procedures.
  • Digital Signatures & Email Encryption
    Design and manage enterprise-wide digital signature and secure email encryption solutions to protect sensitive communications and intellectual property.
  • Systems Hardening & STIG Compliance
    Lead efforts to harden systems across the enterprise, with a strong focus on applying DISA STIGs and other industry benchmarks to ensure secure configurations for Windows and Linux OSes, networking with PAN firewalls and GlobalProtect VPN, O365, TeamCenter, and other organizational systems.
  • Classification Suite Replacement
    Lead the transition from legacy data classification tools to modern, automated classification and labeling solutions that support compliance with NIST 800-171 and ITAR.
  • Zero Trust Architecture Implementation
    Drive the design and implementation of Zero Trust principles across identity, device, network, and application layers.
  • Secure Access Service Edge (SASE)
    Architect and deploy SASE solutions to unify networking and security services, enabling secure access for distributed and hybrid workforces.
  • NIST 800-171 Compliance
    Ensure security controls and processes align with NIST 800-171 requirements, supporting DFARS compliance and audit readiness.
  • SIEM Configuration and Management
    Configure and manage log sources, syslog servers; assist with automation development, conduct regular reviews of log sources and event IDs.



Qualifications:

  • Bachelor's or Master's degree in Cybersecurity, Computer Science, or a related field.
  • 7+ years of experience in cybersecurity engineering roles, preferably in aerospace, defense, or other regulated industries.
  • Deep understanding of NIST 800-171, DFARS, and ITAR compliance requirements.
  • Extensive track record as a technical lead and subject matter expert for implementation of cybersecurity projects and initiatives.
  • Proven experience in systems hardening, including application of DISA STIGs and CIS benchmarks.
  • Hands-on experience with forensic tools and investigative methodologies.
  • Familiarity with OT environments and associated security challenges.
  • Experience with enterprise DLP, classification, and encryption technologies.
  • Excellent communication, documentation, and cross-functional collaboration skills.
  • Relevant certifications (e.g., CISSP, GIAC, GCFA, CEH, CKS) are highly desirable.



Preferred Skills:

  • Experience with cloud-native security tools (AWS, Azure) as well as legacy on-premises solutions.
  • Knowledge of Zero Trust and SASE frameworks.
  • Scripting and automation skills (Python, Bash, etc.).
  • Experience working with government or defense contractors.

Due to government regulation only US persons (U.S. citizen, U.S. naturalized citizen, U.S. permanent resident, holder of U.S. approved political asylee or refugee status) may be considered for this role.


Chromalloy participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S.


Any offer of employment will also be conditioned upon the successful completion of a background investigation and drug screen in accordance with company policy and applicable federal and state regulations.


Chromalloy is an equal opportunity employer - vets/disabled.


In the United States, if you need a reasonable accommodation for the online application process due to a disability, please contact: https://www.chromalloy.com/contact-us/

Applied = 0

(web-c549ffc9f-bf25r)