Director, Cybersecurity Operations

KLDiscoveryUnited States,

About The Position

The Director, Cybersecurity Operations leads Security Operations and Incident Response, Security Engineering, Vulnerability Management, and Threat Intelligence. This is a player-coach leadership role reporting directly to the CISO, partnering with the Director, Cyber GRC as one unified cyber team. The Director will bring hands-on technical depth, strong leadership capability, and the ability to modernize security operations through MDR deployment, AI-informed detection, and a security engineering team organized around functional specialization.

Requirements

  • 15+ years of progressive experience in information security, including at least 7 years in a security leadership role
  • Demonstrated ownership of a security operations or engineering function at the Director or equivalent level
  • Experience operating and maturing an MDR deployment (CrowdStrike Falcon Complete, Arctic Wolf, Expel, or equivalent) in a corporate environment
  • Hands-on background in at least two of the following: security engineering, penetration testing/offensive security, cloud security, application security, or incident response; this is not a purely strategic role
  • Demonstrated experience deploying or maturing security automation, such as SOAR playbooks, detection engineering, IaC security, or CI/CD pipeline security
  • Familiarity with cloud-native security (AWS, Azure, or GCP), including CSPM, cloud IAM, and workload protection
  • Working knowledge of cybersecurity frameworks such as NIST SP 800-171, ISO 27001, and SOC 2
  • Understanding of the vulnerability management lifecycle: scanning, prioritization, remediation tracking, and SLA enforcement
  • Familiarity with AppSec disciplines: SAST/DAST tooling, secure SDLC, and security gate integration into CI/CD
  • Understanding of IAM security governance (PAM, access review programs, and SSO/MFA architecture) as distinct from IT provisioning execution
  • Foundational awareness of CMMC requirements
  • An exceptional communicator, able to translate complex cyber risk and compliance concepts into clear business language for executives, clients, and regulators alike
  • A natural collaborator and client-facing presence, comfortable leading enterprise client security discussions, representing KLDiscovery in due diligence meetings, and building trust with external stakeholders
  • Business-minded, balancing security requirements against commercial realities and making practical decisions without sacrificing rigor
  • A continuous learner with genuine curiosity, energized by a fast-growing company and a rapidly evolving regulatory and threat landscape
  • Discreet and trusted, exercising sound judgment, maintaining confidentiality, and operating with professionalism

Nice To Haves

  • Experience with AI security considerations (model testing, prompt injection, AI tool access governance, and emerging AI governance frameworks such as the NIST AI RMF and ISO 42001) is a meaningful differentiator
  • Professional certifications such as CISSP, CISM, CISA, GPEN, GCIA, or other GIAC certifications strongly preferred
  • Master's degree or MBA with a security focus preferred

Responsibilities

  • Own the MDR relationship, including SLA management, escalation accountability, detection tuning, and quarterly threat hunt reviews
  • Lead the incident response function: IR runbooks, major incident coordination, executive communication during active incidents, and post-incident root cause analysis
  • Oversee SOC detection engineering, ensuring SIEM rules, SOAR playbooks, and automated response actions are maintained, tested, and tuned to the current threat landscape
  • Direct and develop the security analyst pool, redeploying analyst capacity from frontline triage toward MDR validation, threat hunt support, and stakeholder reporting
  • Oversee four specialized engineering lanes [endpoint, identity, cloud, and application security], ensuring each lane has clear ownership, defined scope, and measurable outcomes
  • Drive security architecture reviews and engineering decisions for large or complex IT projects, ensuring security requirements are built in rather than bolted on
  • Shape the security tooling stack strategy, evaluating, selecting, and retiring tools across endpoint, identity, cloud, and application security
  • Enforce automation-first engineering practices, including IaC security gates, CI/CD pipeline security, CSPM auto-remediation, and SOAR-driven response workflows
  • Lead the operationalization of threat intelligence, translating MDR findings and external threat data into detection rule updates, architecture decisions, and risk register inputs for the GRC team
  • Own the vulnerability management lifecycle: scanning coverage, risk-based prioritization, remediation tracking, and SLA enforcement
  • Own the purple team and control validation program, confirming that deployed controls operate as intended and that detection capabilities fire correctly against known attack techniques
  • Drive threat modeling across the engineering function, identifying attack paths before they are exploited and feeding findings into remediation prioritization
  • Oversee the AppSec function: secure SDLC, code review gates, SAST/DAST tooling, and security collaboration with the Product and Engineering teams
  • Own cloud security posture management: CSPM, cloud workload protection, cloud IAM governance, and cloud-native security architecture
  • Set the team-wide AI security posture, overseeing AI security controls across all engineering lanes, including model security, prompt injection testing, and AI tool access governance in partnership with cyber leadership
  • Lead the ongoing maturation of the MDR deployment, expanding coverage, improving response fidelity, and integrating MDR outputs with internal SIEM, IAM, and compliance evidence workflows
  • Champion security automation across the team, reducing manual toil in detection, response, vulnerability tracking, and reporting through SOAR, scripting, and platform integrations
  • Evaluate emerging security technologies and make build/buy/partner recommendations to the CISO with clear business and risk rationale
  • Lead, develop, and performance-manage a lean engineering team
  • Partner with the Director, Cyber GRC as one unified cyber function, feeding operational threat intelligence into the risk register, supporting compliance evidence for technical controls, and jointly presenting security posture
  • Provide regular metrics and reporting to the CISO on incident trends, control coverage, MDR performance, vulnerability posture, and team development
  • Build a team culture of continuous improvement, automation-first execution, and proactive security, where threat hunting and control validation are protected activities rather than aspirational ones
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service