Leads Security Operations with primary responsibility for running the Security Operations Center (SOC), directing 24x7x365 monitoring, detection, triage, investigation, escalation, and response activities across Information Technology (IT), Operational Technology (OT), cloud, identity, network, endpoint, and third-party environments. Serves as a decisive incident commander during cyber security events by rapidly assessing severity, establishing priorities, assigning ownership, coordinating cross-functional response teams, briefing executive leadership, and driving incidents through containment, eradication, recovery, and post-incident improvement. Ensures that cyber security monitoring, detection, response, incident management, threat intelligence, threat hunting, and SOC processes are aligned with IS standards, cyber security standards, and overall cyber risk management objectives. Identifies cyber threats, suspicious activity, security incidents, and operational exposures; determines the scope, severity, and business impact of cyber events; and coordinates procedures to contain incidents, restore normal operations, and improve future detection and response capabilities. Develops techniques and procedures for conducting cyber security monitoring, alert triage, incident investigation, threat analysis, threat hunting, digital evidence collection, cyber readiness exercises, and post-incident reviews. Leads investigation and resolution of cyber security incidents such as intrusions, malware activity, unauthorized access, fraud, attacks, data loss events, or leaks.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Director