Director, Security Operations (Onsite)

Seagate TechnologyLongmont, CO
$167,730 - $249,071Onsite

About The Position

Seagate Technology is seeking a Director, Security Operations to lead its global Security Operations capability. This role is accountable for a mature, measurable, and continuously improving defense program. The position leads 24x7 monitoring and response, overseeing the Security Operations portfolio which includes SOC, incident response, detection engineering, threat intelligence, threat hunting, vulnerability management coordination, firewall operations, and security control operations. The role requires leading a global Security Operations organization with clear ownership, priorities, service levels, and measurable outcomes. It involves operating effectively across internal teams, managed security service providers, specialist partners, and retained incident-response capabilities. The Director will ensure appropriate monitoring, detection, response, and vulnerability management coverage across enterprise IT, cloud, and OT environments, in partnership with OT Security where applicable. A key responsibility is translating operational security signals into prioritized action and clear communication for Information Security, IT, manufacturing, engineering, and business stakeholders. The role also focuses on building a high-accountability team culture centered on disciplined execution, continuous improvement, and risk reduction. This is a people leadership role with global responsibility, including oversight of a firewall operations manager and team.

Requirements

  • Typically 12+ years of cybersecurity experience, including 7+ years leading Security Operations, SOC, incident response, or closely related teams in a large enterprise environment.
  • Demonstrated experience leading global or distributed 24x7 security operations using in-house, managed-service, or hybrid delivery models.
  • Experience overseeing firewall operations or similar security-control service teams responsible for request intake, change execution, access changes, and operational reliability.
  • Strong experience with incident response, crisis management, detection engineering, threat intelligence, threat hunting, and vulnerability management.
  • Working knowledge of modern security operations technologies, including SIEM, EDR/XDR, SOAR, threat intelligence, and vulnerability management platforms.
  • Experience establishing operational metrics and using data to improve control effectiveness, detection quality, response performance, and remediation outcomes.
  • Demonstrated ability to lead high-severity incidents and communicate technical issues, business impact, decisions, and trade-offs to senior leadership.
  • Proven people leadership experience, including organizational design, talent development, performance management, and leading through change.
  • Strong experience managing security service providers and holding third parties accountable for measurable outcomes.

Nice To Haves

  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Engineering, or a related technical discipline and 15+ years of experience; or 12 years and a Master’s degree; or a PhD with 8 years of experience; or equivalent experience.
  • Experience in manufacturing, OT, industrial, or other environments where availability, safety, and operational continuity materially affect security decisions.
  • Experience improving security operations across complex hybrid environments spanning on-premises infrastructure, cloud services, endpoints, identity, and OT.
  • Certifications such as CISSP, CISM, GIAC incident response/detection certifications, or equivalent practical experience.
  • Experience with global incident exercises, forensics retainers, regulatory or customer security obligations, and executive-level security reporting.

Responsibilities

  • Lead a global Security Operations organization with clear ownership, priorities, service levels, and measurable outcomes.
  • Operate effectively across internal teams, managed security service providers, specialist partners, and retained incident-response capabilities.
  • Ensure monitoring, detection, response, and vulnerability management coverage is appropriate across enterprise IT, cloud, and OT environments, in partnership with OT Security where applicable.
  • Translate operational security signals into prioritized action and clear communication for Information Security, IT, manufacturing, engineering, and business stakeholders.
  • Build a high-accountability team culture focused on disciplined execution, continuous improvement, and risk reduction.
  • Own the Security Operations strategy, service portfolio, staffing model, priorities, and performance.
  • Set clear accountabilities across in-house teams, managed services, and specialist providers, including service levels and escalation paths.
  • Establish a risk-based operating cadence focused on the highest-impact threats, incidents, vulnerabilities, and control gaps.
  • Lead 24x7 monitoring, triage, escalation, and advanced analysis across enterprise IT, cloud, and OT environments, including OT-related security alerts in partnership with OT Security.
  • Own the detection lifecycle: use-case strategy, rule development, testing, tuning, coverage analysis, and retirement of ineffective detections.
  • Build an intelligence-led threat hunting capability and partner with Architecture & Engineering on SIEM, EDR/XDR, telemetry, and security platform architecture.
  • Own incident response plans, playbooks, severity models, command structures, and escalation processes.
  • Lead or oversee significant incidents from investigation and containment through recovery and post-incident review, including OT-related cyber incidents in coordination with OT Security and manufacturing stakeholders.
  • Maintain enterprise and plant/engineering-specific playbooks, tabletop exercises, simulations, and forensics readiness.
  • Own threat intelligence collection, analysis, prioritization, and operationalization, translating intelligence into detections, hunts, and response readiness.
  • Lead the vulnerability management program by driving scanning coverage, risk-based prioritization, tracking, escalation, and reporting, while coordinating remediation through accountable system, application, infrastructure, and OT owners.
  • Coordinate remediation with Architecture & Engineering, IT, application teams, OT Security, and business owners using exposure, exploitability, asset criticality, and threat context.
  • Oversee centralized firewall operations, including a manager-led team responsible for firewall service requests, port open and close requests, change execution, monitoring, and operational reliability.
  • Ensure EDR/XDR and related controls are used effectively for investigation, containment, and response. Partner with Architecture & Engineering on platform engineering and lifecycle management.
  • Drive automation and orchestration that improve analyst efficiency, response speed, consistency, and quality.
  • Define operational metrics, including time to detect, time to contain/respond, detection coverage and fidelity, incident recurrence, remediation velocity, and service performance.
  • Provide clear, fact-based reporting on operational effectiveness, trends, risks, trade-offs, and constraints to Information Security and IT leadership.
  • Create a closed-loop feedback process so incident lessons, threat intelligence, control failures, and vulnerability trends inform future architecture, engineering, and risk decisions.
  • Recruit, develop, coach, and retain a high-performing global team and hold security service providers accountable for measurable outcomes.

Benefits

  • Eligibility to participate in a discretionary bonus program
  • Medical, dental, vision, and life insurance
  • Short- and long-term disability
  • 401(k)
  • Employee stock purchase plan
  • Health savings account
  • Dependent care and healthcare spending accounts
  • Paid time off, including 12 holidays
  • Flexible time off provided pursuant to Seagate policy
  • A minimum of 48 hours of paid sick leave
  • 16 weeks of paid parental leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service