Job Description
Chromalloy is a global engineering & solutions company. We are a leading provider of aftermarket parts, repairs, and solutions that safely & reliably extend the life of aircraft engines and gas turbines. We develop, manufacture and repair critical turbine components for a range of engine platforms. Our solutions support the engines running the aerospace, energy and defense industries around the world.
Video: What We Do
Why work at Chromalloy?
Chromalloy employees are proud, passionate problem-solvers who strive to live our values every day. A career with Chromalloy is an opportunity to learn from top industry experts, work with important technologies, and unlock a passion for innovation. Join our team of experts, innovators and problem-solvers delivering world-class solutions for our customers. As a global company, we are committed to creating an inclusive environment where all employees feel represented, heard, and able to bring their best selves to work every day. Be part of something bigger with Chromalloy!
Our Total Rewards Program is designed to support you today and in the future.
• Comprehensive and flexible benefit options starting on day one, including medical, dental, vision, EAP, wellness incentives, and 401(k) with employer matching.
• Development & progression opportunities for every employee – regular performance conversations, training and development curriculum, and engineering fellowship programs.
• Paid time off, including vacation, sick time, paid holidays, and parental leave—all eligible on your first day of employment!
• Competitive pay, including eligibility for quarterly and annual bonuses, depending on role and site.
Eligibility for individual benefit plans may vary based on employment status.
Work schedule: 11:00am - 7:00pm Pacific or Mountain Time
The Global IT Security Analyst monitors, detects, investigates, and responds to cybersecurity threats across Chromalloy's global environment of 20+ facilities. Following Chromalloy's CMMC Level 2 certification (110/110 NIST 800-171 practices met), this role is central to sustaining that posture — operating an expanding security platform portfolio, driving incident response, and supporting the controls and evidence required of a defense-industrial-base company under ITAR, CUI, DFARS, and SOX obligations.
This is a hands-on role for someone motivated by incident response, cross-functional collaboration, and strengthening the security of systems, infrastructure, and end-user computing. The analyst exercises strong technical judgment to prioritize and drive incidents to resolution while clearly communicating impact and next steps to technical teams and business partners. Chromalloy operates two Global IT Security Analyst seats on staggered East/West U.S. coast schedules to extend daily coverage and share an on-call rotation.
Primary Accountabilities:
• Monitor, triage, and investigate security alerts using SIEM and EDR tooling (ReliaQuest GreyMatter MDR, CrowdStrike Falcon, Microsoft Defender, Palo Alto); validate severity and scope and document findings.
• Serve as an internal escalation point for the 24/7 MDR provider; lead containment and remediation (isolate endpoints, disable accounts, block indicators, reset credentials) and track actions to closure.
• Execute and continuously improve incident response processes and maintain playbooks/runbooks for common scenarios (phishing, malware, account compromise, ransomware), aligned to CYBER-002/CYBER-003.
• Operate and tune the FY26 security platform portfolio as assigned: SailPoint IGA (identity lifecycle, access reviews), Delinea PAM (and CyberArk evaluation), Titus and DSPM (data classification/posture), AI governance tooling (Securiti.AI, Harmonic), Palo Alto IoT/OT security, and the GRC platform.
• Own and run the security awareness program: phishing simulation campaigns, weekly user training, and monthly security culture communications; engage end users during investigations with clear, empathetic guidance.
• Coordinate and support the annual tabletop exercise, penetration test, and purple team engagement — including scoping, facilitation, and tracking all findings through remediation to closure with audit-ready evidence.
• Support governance and assurance: control evidence collection, policy/standard reviews, and third-party/vendor risk activities aligned to NIST 800-171, CMMC, DFARS 252.204-7012, ISO 27001, and CIS Controls.
• Create and tune detection content (queries, correlation rules, indicators) to improve signal quality and reduce false positives; maintain threat-intelligence awareness and translate it into actionable detections and hardening.
• Perform vulnerability management activities and basic malware triage and forensic collection as needed.
Qualifications
• BS in Computer Science, Engineering, Information Technology, or equivalent experience.
• 3–5 years in a cybersecurity / SOC / IT security operations role with hands-on incident triage, investigation, and coordinated response.
• Working knowledge of security frameworks and how they translate into operational controls: NIST 800-171/800-53, CMMC, DFARS, ISO 27001/27002, CIS Controls.
• Experience with common security tooling preferred: SIEM, EDR (CrowdStrike preferred), email security, vulnerability scanning, and identity/PAM platforms (SailPoint, Delinea/CyberArk); SOAR a plus.
• U.S. person status required for ITAR/CUI access (see Location & Eligibility).
• Security+ required; CySA+, GCIH, GCIA, CEH, or SSCP preferred.
• Strong written and verbal communication; able to explain risk and response to end users and stakeholders, produce incident documentation, and present post-incident findings.
• Ability to participate in a shared after-hours and weekend on-call rotation.
• Able to travel as needed, sometimes up to 30%.
This position may require work hours outside of the regularly scheduled hours to meet operational needs. This may include work during evenings, weekends, and/or holidays. Additional work hours are assigned based on business requirements. Non-exempt employees will be paid overtime in accordance with applicable federal, state, and local laws.
The salary range for this position reflects a broad spectrum of experience levels. Individual compensation within the range is determined by multiple factors, including relevant experience, education, certifications, job related skills, internal equity, and market conditions. We evaluate each candidate individually to ensure fair and competitive pay decisions.
Due to government regulation only US persons (U.S. citizen, U.S. naturalized citizen, U.S. permanent resident, holder of U.S. approved political asylee or refugee status) may be considered for this role.
Chromalloy participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S.
Any offer of employment will also be conditioned upon the successful completion of a background investigation and drug screen in accordance with company policy and applicable federal and state regulations.
Chromalloy is an equal opportunity employer - vets/disabled.
In the United States, if you need a reasonable accommodation for the online application process due to a disability, please contact: https://www.chromalloy.com/contact-us/