Director, Security Operations and Incident Response
Office Location or Remote - USA
We’re looking for a security-minded, hands-on leader with extensive Incident Response (IR) and Threat Intelligence experience to support our global 24x7 security monitoring and IR programs. The candidate must be an experienced incident response leader with a strong track record of coordinating cross-functional teams (Compliance, Legal, HR, Corporate IT, Product Engineering, Customer Support) and executive leadership through response and recovery from major security incidents (e.g. data breaches, ransomware, etc.), with minimal impact to the business. The candidate must have strong operational knowledge of the security tool landscape and has a track record of optimizing and automating processes to achieve measurable efficiency and accuracy gains. This role is integral to the Cybersecurity program, and works directly alongside the Security Architecture / Engineering, Tech Infrastructure and Network teams.
Responsibilities
- Be a thought leader and industry expert for all functions under Security Operations
- Develop and lead a team of cybersecurity experts to manage global Security Operations functions such as monitoring and detection, incident response, threat and vulnerability management, threat intelligence, digital forensics & investigations, threat hunting, and insider threat.
- Develop and execute on Security Operations strategy, and partner with Security Architecture and Engineering to deliver new or enhance existing security controls and analyze/maintain new or existing security applications/products including SIEM, vulnerability management tools, intrusion detection and prevention, data leakage protection, network security analysis, firewalls (network and application), and Cloud security controls.
- Proven experience developing SIEM and logging feeds architecture and creating processes that translate logs into actional security events
- Engage with executive level leaders, including board members and customers, to explain concepts, present roadshows for major initiatives and programs
- Lead global security operations projects and act as the leader and mentor to Security Operations Engineers
- Designing and implementing security processes to support security monitoring and incident response using best-in-class security engineering principles; experience with the MITRE ATT&CK Framework and its Tactics and Techniques.
- Strong experience with security metrics and measurements and process automation – understand how to measure monitoring/IR processes and how to improve them based on historical data
- Partner with Security Engineers to identify and evaluate best in class security solutions and plan production deployments and help document runbooks accordingly
- Lead or coordinate enterprise cybersecurity tabletop exercises across cross-function teams …
This job isn't fresh anymore!
Search Fresh JobsJob Profile
Dental Insurance Education reimbursement Life Insurance
Tasks- Lead security operations
- Manage incident response
- Optimize security processes
Cloud Cloud Security Compliance Customer Support Cybersecurity Detection Digital Forensics Executive leadership Firewalls Healthcare HR Incident Response Investigations Legal MITRE ATT&CK Monitoring Network security Process Automation Product engineering Security Engineering Security metrics Security Operations SIEM Threat Hunting Threat Intelligence Vulnerability Management
Experience5 years
TimezonesAmerica/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9