POSITION PURPOSE
The Global Director of Infrastructure, Operations, and Security is a senior leadership role responsible for the reliability, scalability, resilience, and protection of the company’s global technology environment. Reporting directly to the Global Vice President, Chief Digital & Information Officer, this leader will own global infrastructure, IT operations, cybersecurity execution, service reliability, and operational risk management across all regions.
This individual will lead a geographically distributed team of engineers, architects, operations and security professionals, partnering cross-functionally with business leaders to align technology capabilities with strategic objectives. The successful candidate must bring prior hands-on and leadership experience in cybersecurity and demonstrate the ability to lead in complex global environments with accountability, urgency, and a strong business-first service mindset.
PRINCIPAL ACCOUNTABILITIES
Infrastructure & Global Operations
- Lead the global strategy, architecture, and operations for enterprise infrastructure across cloud, data center, network, endpoint, identity, and collaboration platforms.
- Establish and enforce global standards for system reliability, availability, performance, monitoring, incident response, and service recovery for business-critical services.
- Lead capacity planning, disaster recovery (DR), and business continuity planning (BCP) programs across all regions.
- Oversee 24/7 global IT operations, including service desk, infrastructure operations, major incident management, escalation frameworks, and operational communications.
- Drive automation initiatives to improve deployment velocity and reduce operational toil.
- Manage enterprise network architecture, including SD-WAN and zero-trust access across global offices.
Cybersecurity, Risk & Resilience
- Serve as the senior operational leader for cybersecurity, ensuring security priorities are embedded into infrastructure, operations, architecture, and service delivery decisions.
- Design and implement a comprehensive security program spanning identity and access management (IAM), endpoint protection, data loss prevention (DLP), and threat intelligence. Application-level governance, including SAP roles, profiles, and segregation of duties, is owned the by the Digital Applications & Product Delivery team.
- Own the enterprise Product Security program, ensuring secure-by-design principles, cybersecurity requirements, and risk management are embedded throughout the lifecycle of BAC products, connected systems, and emerging digital offerings.
- Own the enterprise AI Security program, ensuring the secure adoption, governance, and risk management of AI technologies, including protection against data leakage, model misuse, prompt injection, and emerging AI-related threats.
- Lead cybersecurity incident response readiness, security incident investigations, crisis coordination, and executive communications in partnership with legal, compliance, and business stakeholders.
- Ensure compliance with global regulatory frameworks including ISO 27001, SOC 2 Type II, GDPR, NIST CSF, and regional data protection laws.
- Manage vulnerability management, penetration testing programs, and remediation prioritization processes, and set the enterprise standard to which application-layer vulnerability remediation is held.
- Collaborate with the group SOC and other Amsted entity security leaders to define and execute the multi-year security roadmap.
Global Team Leadership
- Lead, mentor, and develop a globally distributed team of infrastructure, operations, support, and security professionals across multiple countries and time zones.
- Establish a high-performance culture rooted in accountability, continuous improvement, psychological safety, and inclusion.
- Set clear expectations, operating metrics, and team objectives aligned with business priorities; report progress, risk posture, and service performance to the CDIO and executive leadership.
- Partner with HR and talent acquisition to grow the team, close skill gaps, and maintain a robust succession plan.
- Manage vendor relationships and negotiate contracts for infrastructure, managed services, and security tooling.
Strategy, Governance & Budget
- Develop and execute a multi-year roadmap for infrastructure modernization, operational excellence, cybersecurity maturity, resilience, and global service improvement.
- Own and manage a budget encompassing capital expenditures, operating expenses, and staffing.
- Present technology strategy, cybersecurity risk posture, operational performance, investment priorities, and mitigation plans to global and regional executive leadership as required.
- Drive cost optimization through cloud rationalization, vendor consolidation, and operational efficiency programs.
NATURE AND SCOPE
The Global Director, Infrastructure, Operations, and Security will report to the Global Vice President, Chief Digital and Information Officer. As part of the Global Business Systems organization, this role will influence senior leaders globally and partner closely with regional business and technology teams. This leader will manage a globally distributed team of infrastructure, operations, support services, and security professionals across multiple time zones and will be accountable for enterprise service reliability, operational discipline, and cybersecurity execution.
KNOWLEDGE & SKILLS
- Bachelor’s degree in computer science, information systems, cybersecurity, or a closely related field; master’s degree strongly preferred.
- Minimum 12 years of progressive experience in infrastructure, IT operations, cybersecurity, and enterprise technology leadership, with at least 5 years in a senior leadership role.
- Required: Prior cybersecurity experience, including security architecture, incident response, identity and access management, vulnerability management, risk management, and security operations in an enterprise environment.
- Required: Proven experience managing a global, distributed team across multiple countries, cultures, and time zones.
- Required: Experience creating and managing an enterprise product security program.
- Preferred: Experience creating and managing AI security and risk.
- Demonstrated ability to build, scale, and mature global infrastructure, operations, and security organizations in a complex enterprise environment.
TECHNICAL EXPERTISE
- Deep expertise across cloud platforms (Azure preferred) and hybrid/multi-cloud architecture.
- Strong command of cybersecurity frameworks: NIST CSF, ISO 27001, CIS Controls, Zero Trust Architecture.
- Experience with enterprise networking, SD-WAN, firewalls, SIEM/SOAR platforms, and endpoint detection & response (EDR) tools.
- Proficiency with DevSecOps, CI/CD pipelines, containerization, and IaC.
- Familiarity with ITSM platforms, methodology, and enterprise monitoring/observability tooling.
REQUIRED AND PREFERRED CERTIFICATIONS
- Required: Active Certified Information Systems Security Professional (CISSP) certification.
- Preferred: CISM, CISA, CRISC, CCSP, Microsoft Certified: Azure Solutions Architect Expert, ITIL 4 Managing Professional or Strategic Leader, ITSM, and PMP.
PERFORMANCE INDICATORS
- Availability, performance, and resilience of business-critical infrastructure and services against agreed service levels.
- Major incident volume, time to restore, and effectiveness of escalation and crisis communication.
- Cybersecurity posture - vulnerability remediation within defined thresholds, phishing and awareness metrics, and maturity progression against the agreed framework.
- Successful completion of disaster recovery and business continuity testing across all regions.
- Management of the infrastructure and security budget within the approved envelope, and delivery of committed cost-optimization targets.
- Audit and regulatory outcomes - findings raised, remediation timeliness, and certification maintenance.
- Organizational health - retention of critical talent, succession coverage, and demonstrable capability growth.
- Grants of authority have been assigned to the Global Director, Infrastructure, Operations & Security in accordance with the Grant of Authority issued and applicable by region, covering budget approval, contract commitment, and change and incident escalation authority within defined thresholds.
WHAT SUCCESS LOOKS LIKE IN THE FIRST YEAR
- A baselined view of infrastructure and security maturity, with an agreed multi-year roadmap and funding plan.
- A stable, measured operations function with published service levels and a functioning major incident process.
- Disaster recovery and business continuity plans tested across all regions, with gaps documented and prioritized.
- A demonstrably improved security posture, with critical vulnerabilities remediated and identity governance operating reliably.
- A team structure ready to scale, with clear ownership by domain and a functioning leadership layer.
WORKING CONDITIONS:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions of the job. This position requires travel both domestically and internationally up to 30% of the time.
BAC Hiring Compensation Range $154,100- $264,000
BAC offers a comprehensive benefits package to include medical, dental, vision, paid time off, 401k, employee stock ownership plan, and more. Please see additional details on the BAC website at www.Baltimoreaircoil.com.
BAC Employees are eligible to participate in an annual bonus incentive program.