Director, Security Engineering & Operations

Payscale,
$182,720 - $274,080Remote

About The Position

The Director, Security Engineering & Operations directs, manages, and leads Payscale’s Security Engineering and Security Operations functions. This is a hands-on leadership role: the Director sets strategy and manages the team while remaining directly engaged in architecture, tooling, automation, and incident command. Responsibilities span the design and hardening of security controls, threat detection and incident response, vulnerability and exposure management, endpoint and identity protection, and security automation across Payscale’s corporate, cloud, and hosting environments. The Director owns Payscale’s MDR relationship and is accountable for the maturity, performance, and roadmap of both functions. This role reports to the CISO, VP - Cybersecurity & Enterprise Technology.

Requirements

  • 10+ years in information security, including 4+ years in a lead or management role across security engineering and/or security operations functions
  • Proven people-management track record: direct reports, performance cycles, and team development in a security context
  • Expert, hands-on knowledge of both security engineering (controls design, automation, tooling integration) and security operations (detection, incident response) — capable of acting as architect, engineer, incident handler, lead, and manager
  • Experience with the CrowdStrike Falcon platform (EDR, Identity Protection, Data Protection, AIDR, ZTA, Exposure Management) and SIEM/SOAR orchestration
  • Demonstrated experience owning or managing an MDR or MSSP vendor relationship
  • Strong foundation in cloud security (AWS preferred), endpoint security, identity and access management, and zero-trust architecture
  • Strong experience in vulnerability and exposure management and mitigation/remediation strategies
  • Scripting and automation ability in PowerShell, Python, or Bash; comfortable with detection-as-code and infrastructure-as-code approaches
  • Experience with the MITRE ATT&CK framework and the ability to map operational data to TTPs for structured threat analysis
  • Experience building operational, engineering, and vulnerability metrics and management reporting, and driving improvement through a regular reporting cadence
  • Experience with zero-trust networks and platforms such as Cloudflare, Zscaler, or AppGate
  • Experience with Data Loss Prevention and CASB architectures and tooling such as Forcepoint, Netskope, or Zscaler
  • Familiarity with SOAR and automation platforms such as Tines, n8n, or Ansible

Nice To Haves

  • Certifications such as CISSP or CISM
  • Experience in a remote-first SaaS and/or PE-backed environment

Responsibilities

  • Direct, manage, and lead the security engineering and security operations team members; own hiring, onboarding, performance reviews, and career development plans aligned to Payscale’s Information Security Career Ladder
  • Set strategy and quarterly/annual objectives for both functions and translate them into a prioritized, measurable roadmap; hold regular 1:1s and team connects to maintain a high-performance, feedback-rich culture
  • Mentor engineers and analysts at all career levels, providing task-based directives, technical coaching, and growth-oriented feedback
  • Own the on-call rotation and after-hours escalation path across both functions, ensuring coverage for time-sensitive detection and response
  • Serve as a working leader — remaining hands-on in engineering, architecture, and incident response rather than leading solely through delegation
  • Own the design, implementation, and continuous hardening of security controls across corporate, cloud, and hosting environments
  • Build and maintain security automation and integrations — SOAR, detection-as-code, and infrastructure-as-code guardrails — to scale coverage without adding headcount
  • Engineer and operate the security tooling stack (EDR/XDR, SIEM, identity protection, DLP/CASB, vulnerability scanning), ensuring platforms are well-integrated and meet architectural standards
  • Partner with Engineering and Infrastructure to embed “secure by design” into CI/CD, cloud architecture, and product development
  • Drive adoption of a zero-trust methodology across identity, endpoint, network, and application layers
  • Lead security engineering for enterprise AI and agentic tooling adoption, building controls and guardrails for safe internal use
  • Drive the threat detection and incident response capability: detection engineering, playbook development, tabletop exercises, and continuous improvement of MTTA/MTTR metrics
  • Lead or oversee incident response events as the designated incident manager for significant or multi-team incidents, running incident command end-to-end
  • Own the MDR relationship, holding the provider accountable to SLAs, coverage, and response outcomes
  • Extend detection and response to secure enterprise AI and agentic tooling adoption
  • Own the vulnerability and exposure management function across all corporate and hosting environments, coordinating cross-functionally on mitigation and remediation with clear SLAs
  • Expand security monitoring, visibility, and coverage using existing platforms and open-source tooling
  • Own the security engineering and operations portion of the Information Security program roadmap, delivering operational metrics, risk-posture data, and capacity analysis
  • Establish and report security KPIs to technology and executive leadership on a regular cadence
  • Collaborate with the GRC team on ISO 27001 and SOC 2 evidence, control effectiveness, and audit readiness as it relates to security engineering and operations
  • Lead technical evaluations of emerging security vendors and technologies; provide buy/build/partner recommendations to technology management
  • Represent security engineering and operations in cross-functional product, engineering, and infrastructure initiatives, ensuring security requirements are incorporated by design

Benefits

  • Flexible paid time off
  • 14 Paid Company Holidays, includes 2 floating holidays (you choose!)
  • A comprehensive benefits plan including medical, dental, life, vision, disability, and life insurance covered up to 100% by Payscale
  • Unlimited infertility coverage benefits through our medical plans
  • Additional supplemental health benefits offered to you and your family
  • 401(k) retirement program with a fully vested immediate company match
  • 16 weeks of paid parental leave for birthing and non-birthing parents
  • Health Savings Account (HSA) options and company contributions each pay period
  • Flexible Spending Account (FSA) options for pre-tax employee allocations
  • Annual remote work stipend to be used on wellness or home office equipment
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service