Director of Cybersecurity Operations

AEG WorldwideLos Angeles, CA

About The Position

The Director of Cybersecurity Operations leads the organization's global cyber operations strategy, strengthening operational resilience and maturing enterprise defense capabilities across corporate, cloud, venue, and operational technology environments. Reporting to the Chief Information Security Officer (CISO), this role provides strategic and operational leadership for Security Operations, Threat Detection and Response, Vulnerability Management, Identity and Access Management (IAM), Data Loss Prevention (DLP), Penetration Testing, and Cyber Fusion Center operations. This leader designs, builds, optimizes, and continuously evolves scalable cybersecurity operations—including Global Security Operations Centers (GSOC), advanced detection/response programs, security automation and orchestration, threat intelligence, and globally distributed cyber operations—bringing deep technical expertise, operational leadership, and strategic vision to proactively defend against evolving threats while enabling business growth and technology transformation. The Director partners closely with Information Security Engineering, Infrastructure, Compliance, Legal, HR, and business leaders to strengthen security posture, reduce operational risk, and align initiatives with organizational objectives and regulatory requirements, while developing and communicating meaningful cybersecurity metrics, KPIs, and Key Risk Indicators (KRIs) through executive reporting and briefings on cyber risk, operational maturity, incident trends, and resilience initiatives to support informed decision-making. Success requires building and maturing high-performing programs, leading through complex and fast-changing threat landscapes, communicating effectively with technical and executive stakeholders, and translating cyber risk into actionable, business-focused strategies and outcomes.

Requirements

  • BA/BS Degree (4-year) (Advanced Degree Preferred) Information Technology, Computer Science, Cybersecurity or a related field. Master’s degree preferred.
  • 5+ years experience building, scaling, or transforming SOCs, Fusion Centers, or global cyber defense operations.
  • Experience leading Security Operations, Incident Response, CTEM/Vulnerability Management, IAM, DLP, Penetration Testing, and Threat Detection programs.
  • Strong knowledge of SIEM, SOAR, EDR/XDR, MDR, IAM/PAM, vulnerability management, and cloud security technologies.
  • Experience with security automation, detection engineering, threat hunting, and operational process improvement.
  • Experience with cloud security operations across AWS, Azure, and/or Google Cloud environments.
  • Experience developing cybersecurity metrics, KPIs, KRIs, dashboards, and executive reporting.
  • Strong understanding of threat intelligence, MITRE ATT&CK, cyber risk management, and exposure reduction strategies.
  • Experience managing MSSPs, MDR providers, cybersecurity vendors, and third-party security partners.
  • Strong executive communication and stakeholder management skills with the ability to translate cybersecurity risks into business impact.
  • Experience supporting regulatory and compliance frameworks including NIST, ISO 27001, PCI-DSS, SOX, GDPR, and privacy requirements.
  • Experience leading cross-functional initiatives within large, matrixed, and geographically distributed organizations.
  • 10 years progressive experience in cybersecurity operations, incident response, threat detection, vulnerability management, and enterprise cyber defense within complex enterprise environments.
  • Strong written and verbal communication skills with the ability to communicate technical risks to executive and non-technical audiences.
  • Deep knowledge of Security Operations, Incident Response, Threat Detection and Response, CTEM/Vulnerability Management, IAM, DLP, and Cyber Fusion Center operations.
  • Proven ability to build, mature, and lead cybersecurity operations programs and high-performing teams.
  • Strong understanding of modern cyber threats, attack methodologies, threat intelligence, and risk management practices.
  • Experience with SIEM, SOAR, EDR/XDR, IAM/PAM, vulnerability management, DLP, and cloud security technologies.
  • Knowledge of threat hunting, detection engineering, security automation, and incident response best practices.
  • Strong understanding of CTEM, attack surface management, threat-informed defense, and exposure reduction strategies.
  • Ability to develop cybersecurity metrics, KPIs, KRIs, dashboards, and executive-level reporting.
  • Strong knowledge of cloud security principles, Zero Trust concepts, and hybrid enterprise security architectures.
  • Ability to lead high-pressure incident response activities and make informed decisions during critical events.
  • Strong project, program, organizational, and operational leadership skills.
  • Ability to align cybersecurity strategies and operational priorities with business objectives and enterprise risk management goals.
  • Strong collaboration skills with the ability to work effectively across technical, operational, legal, compliance, and business teams.
  • Knowledge of applicable cybersecurity and privacy frameworks including NIST, ISO 27001, PCI-DSS, SOX, and GDPR.

Nice To Haves

  • CISSP Certified Information Systems Security Professional highly desirable
  • CISM - Certified Information Security Manager highly desirable
  • Certified Emergency Management Specialist (CEMS) highly desirable
  • Other equivalent certification highly desirable
  • Commitment to continuous improvement and staying current with evolving cybersecurity threats, technologies, and industry trends.

Responsibilities

  • Lead the strategy, design, and optimization of Global Security Operations Center (GSOC) and Cyber Fusion Center capabilities.
  • Lead threat detection, monitoring, threat hunting, incident triage, and response operations across enterprise, cloud, venue, and operational technology environments.
  • Develop detection engineering capabilities, operational playbooks, escalation procedures, and automation workflows to improve response effectiveness.
  • Oversee implementation and optimization of cybersecurity technologies including SIEM, SOAR, EDR/XDR, threat intelligence, and security analytics platforms.
  • Manage relationships with security vendors and coordinate globally distributed cyber operations activities.
  • Continuously assess and improve operational maturity aligned to industry frameworks, emerging threats, and business priorities.
  • Lead enterprise incident response operations, ensuring rapid identification, containment, eradication, recovery, and post-incident remediation activities.
  • Direct the development, testing, and continuous improvement of incident response plans, operational playbooks, tabletop exercises, and cyber crisis simulations.
  • Coordinate cross-functional response efforts involving Infrastructure, Legal, HR, Compliance, Privacy, and business stakeholders during cybersecurity incidents.
  • Conduct post-incident reviews and drive lessons learned initiatives to improve operational resilience and reduce future risk exposure.
  • Support cyber resilience, business continuity, and disaster recovery initiatives related to cybersecurity operations.
  • Lead AEG’s Continuous Threat Exposure Management (CTEM) and enterprise vulnerability management programs across cloud, network, endpoint, application, identity, and operational technology environments.
  • Lead identification, prioritization, validation, and remediation of cyber exposures based on threat intelligence, exploitability, and business risk.
  • Drive exposure reduction initiatives leveraging threat intelligence, attack surface management, identity security, and security validation activities.
  • Partner with Infrastructure, Engineering, Application Development, Cloud Operations, and Compliance teams to coordinate timely remediation and risk reduction initiatives.
  • Support identity and access governance initiatives including privileged access management, least-privilege controls, multi-factor authentication, and identity-related risk reduction strategies.
  • Oversee vulnerability scanning, attack surface visibility, remediation governance, exposure tracking, and executive-level reporting processes.
  • Develop operational metrics, KPIs, and KRIs to measure exposure reduction effectiveness, remediation performance, and overall cyber risk posture.
  • Enhance CTEM processes, tooling, automation, and reporting capabilities aligned with evolving threats and business priorities.
  • Lead enterprise Data Loss Prevention (DLP) strategies and data protection initiatives to safeguard sensitive corporate, customer, financial, and regulated data.
  • Oversee implementation and monitoring of controls designed to prevent unauthorized access, misuse, disclosure, or exfiltration of sensitive information.
  • Conduct regular assessments, audits, and effectiveness reviews of DLP controls and data protection capabilities.
  • Partner with Legal, Privacy, Compliance, and business stakeholders to align data protection initiatives with regulatory and organizational requirements.
  • Direct internal and external penetration testing initiatives, red team exercises, and security validation assessments.
  • Coordinate remediation activities and track resolution of identified vulnerabilities and security gaps.
  • Evaluate effectiveness of security controls through continuous testing and adversary simulation activities.
  • Provide strategic recommendations for security architecture and operational improvements based on assessment findings.
  • Partner with the CISO and senior leadership to define and execute the cybersecurity operations strategy, roadmap, and maturity initiatives.
  • Drive cyber risk reduction initiatives through CTEM, threat-informed defense, and operational maturity programs.
  • Develop and communicate meaningful cybersecurity metrics, KPIs, and Key Risk Indicators (KRIs) to measure operational effectiveness, threat exposure, and program maturity.
  • Deliver executive-level reporting and briefings on cybersecurity posture, operational resilience, incident trends, emerging threats, and strategic initiatives.
  • Translate complex cybersecurity risks and operational issues into clear business-focused insights and recommendations for executive stakeholders.
  • Support budget planning, vendor strategy, technology evaluations, and long-term operational planning initiatives.
  • Lead, mentor, and develop high-performing cybersecurity operations teams in a complex, matrixed, and globally distributed environment.
  • Foster a culture of accountability, collaboration, innovation, operational excellence, and continuous improvement.
  • Support team growth through talent development, succession planning, process improvement, and operational standardization.
  • Provide leadership during high-pressure cybersecurity incidents and operational escalations.
  • Partner with Information Security Engineering, Infrastructure, Compliance, Legal, HR, Privacy, Audit, and business leadership teams to align cybersecurity initiatives with organizational objectives.
  • Collaborate with external partners, vendors, industry groups, and law enforcement organizations as appropriate.
  • Communicate effectively with technical and non-technical stakeholders to promote cybersecurity awareness, operational alignment, and informed risk management decisions.
  • Support enterprise technology transformation initiatives by embedding cybersecurity operational requirements and best practices.

Benefits

  • medical, dental and vision insurance
  • paid holidays
  • vacation and sick time
  • company paid basic life insurance
  • voluntary life insurance
  • parental leave
  • 401k Plan (with a current employer match of 3%)
  • flexible spending and health savings account options
  • wellness offerings
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service