Dir Security Operations & Engineering

Empower • $138K — $200K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-8 years in IT security operations or engineering.
  • Proven leadership of multiple security teams.
  • Experience managing a Security Operations Center or similar.
  • Strong grasp of SIEM, IDS/IPS, and firewalls.
  • Project management experience with complex security initiatives.
  • Ability to communicate security risks in business terms.
  • Experience in a regulated industry, preferably financial services.

Responsibilities

  • Lead daily operations of security teams, setting priorities and expectations.
  • Contribute to departmental goals, policies, and resource planning.
  • Oversee incident response and security monitoring activities.
  • Analyze security logs to detect unauthorized access and threats.
  • Manage security technologies and ensure their effectiveness.
  • Develop and present operational metrics and trends to leadership.
  • Direct the creation of standard operating procedures for security operations.

Benefits

  • Comprehensive medical, dental, vision, and life insurance coverage.
  • 401(k) retirement plan with substantial company matching.
  • Tuition reimbursement up to $5,250 annually.
  • Generous paid time off policy and ten paid holidays.
  • Paid volunteer time of 16 hours per year.
  • Diversity-focused Business Resource Groups for professional bonding.
  • Options for a business-casual dress code.
Full Job Description
The Director Security Operations & Engineering will lead security operations and engineering teams responsible for protecting the organization's information systems and technology environment. This role will serve as a security advocate and trusted partner to key stakeholders and service owners, providing guidance on security operations, engineering, and the effective balance of security and business requirements. The Director will be accountable for the performance and results of multiple related teams responsible for security monitoring, event analysis, incident response, security engineering, and security controls. This role will provide input into security policies, procedures, and departmental priorities and translate broader information security objectives into actionable plans for assigned teams. What you will do: - Lead the day to day management and performance of multiple security operations and engineering teams, including subordinate managers and professional level security staff, establishing priorities, objectives, and performance expectations. - Provide input into annual departmental goals, objectives, policies, procedures, and priorities, and develop departmental plans and resource allocations that support broader Information Security objectives. - Oversee cybersecurity monitoring, event analysis, identification, escalation, investigation, reporting, and incident response processes. - Direct analysis of security logs and other relevant data to identify unauthorized access, malicious activity, intrusion attempts, potential compromises, and emerging threats. - Oversee security services and technologies including SIEM, IDS/IPS, firewalls, web application firewalls, security event correlation capabilities, and related security platforms. - Ensure external threat intelligence, vulnerability assessment information, and other relevant security data are effectively incorporated into monitoring, investigation, and response processes. - Develop and monitor operational metrics and reporting related to security events, trends, vulnerabilities, mitigation activities, service performance, and departmental effectiveness, and present findings and risks to senior security leadership and stakeholders. - Oversee the development and execution of standard operating procedures, job aids, security hardening standards, and processes that support consistent security operations and engineering activities. - Ensure security devices and controls are appropriately designed, implemented, maintained, monitored, tested, and improved in accordance with established architecture and change control processes, including cryptographic controls within assigned areas of responsibility. - Identify security risks, direct the development of remediation strategies or mitigating controls, and oversee or approve application and system change requests requiring security review. - Provide subject matter expertise and departmental leadership for enterprise information security initiatives, strategies, projects, policies, regulatory inspections, and internal and external audits. - Lead or oversee Information Security and Risk projects, coordinating with internal teams, subject matter experts, business and technology stakeholders, and third parties to resolve complex security issues and apply appropriate security strategies, policies, frameworks, and recommendations. - Assign teams and staff to projects, monitor project status, schedules, budgets, resource constraints, and departmental issues, and escalate significant risks or issues to senior security leadership as appropriate. - Participate in departmental budget planning, manage assigned resources and expenditures, forecast staffing requirements, and make recommendations regarding workforce needs and priorities. - Hire, develop, coach, mentor, and evaluate managers and professional staff; support performance and personnel decisions; develop leadership capability; and promote talent management, succession planning, knowledge sharing, professional development, and productive relationships across Information Technology, Risk, Audit, Compliance, and business functions. Perform other duties and responsibilities as assigned. What you will bring: - Significant experience in information technology security operations, engineering, security architecture, or related information security disciplines. - 6 to 8 years of related management experience, consistent with the career level expectations for this role. - Demonstrated experience leading multiple teams of security professionals and/or subordinate managers. - Experience with security operations and monitoring, incident response, security system design, deployment, and delivery. - Demonstrated experience managing or providing leadership for a Security Operations Center and/or security engineering function. - Strong knowledge of information security technologies, tools, controls, and industry practices, including SIEM, IDS/IPS, firewalls, web application firewalls, security event correlation, and related security platforms. - Demonstrated knowledge of information systems security standards and practices, including access controls, system hardening, audit and log monitoring, security policies, vulnerability management, and incident handling. - Experience working with third party service providers as part of a comprehensive security program. - Project management experience, including demonstrated ability to organize, plan, prioritize, resource, and deliver assignments through direct and indirect reports. - Demonstrated ability to identify and resolve complex security problems within assigned disciplines and areas of responsibility. - Ability to translate security risks and technical issues into clear business language for technical and non technical audiences, including senior leaders, auditors, clients, end users, and IT staff. - Strong organizational and prioritization skills with demonstrated ability to adapt departmental plans and resources in a fast paced, changing environment. - Demonstrated ability to manage professional staff, subordinate managers, indirect resources, and vendors. - Proven analytical, problem solving, and critical thinking skills. - Strong written and verbal communication skills with the ability to collaborate with and influence stakeholders across multiple levels of the organization. What will set you apart: - Bachelor's Degree in Computer Science, Information Systems, Cybersecurity, or a related discipline, or equivalent applicable experience. - Security certifications such as CISSP, CISM, SANS GCIH (Certified Incident Handler), GCIA (Certified Intrusion Analyst), CEH (Certified Ethical Hacker), GIAC certification, or comparable industry certifications. - Experience in a complex technical environment, with financial services or another highly regulated industry preferred. This job operates in a professional office environment. This job description is not intended to be an exhaustive list of all duties, responsibilities and qualifications of the job. The employer has the right to revise this job description at any time. You will be evaluated in part based on your performance of the responsibilities and/or tasks listed in this job description. You may be required to perform other duties that are not included on this job description. The job description is not a contract for employment, and either you or the employer may terminate employment at any time, for any reason, as per terms and conditions of your employment contract. What we offer you We offer an array of diverse and inclusive benefits regardless of where you are in your career. We believe that providing our employees with the means to lead healthy balanced lives results in the best possible work performance. - Medical, dental, vision and life insurance - Retirement savings - 401(k) plan with generous company matching contributions (up to 6%), financial advisory services, potential company discretionary contribution, and a broad investment lineup - Tuition reimbursement up to $5,250/year - Business-casual environment that includes the option to wear jeans - Generous paid time off upon hire - including a paid time off program plus ten paid company holidays and three floating holidays each calendar year - Paid volunteer time - 16 hours per calendar year - Leave of absence programs - including paid parental leave, paid short- and long-term disability, and Family and Medical Leave (FMLA) - Business Resource Groups (BRGs) - BRGs facilitate inclusion and collaboration across our business internally and throughout the communities where we live, work and play. BRGs are open to all. Base Salary Range $138,000.00 - $200,100.00 The salary range above shows the typical minimum to maximum base salary range for this position in the location listed. Non-sales positions have the opportunity to participate in a bonus program. Sales positions are eligible for sales incentives, and in some instances a bonus plan, whereby total compensation may far exceed base salary depending on individual performance. Actual compensation offered may vary from posted hiring range based upon geographic location, work experience, education, licensure requirements and/or skill level and will be finalized at the time of offer. ***For remote and hybrid positions you will be required to provide reliable high-speed internet with a wired connection as well as a place in your home to work with limited disruption. You must have reliable connectivity from an internet service provider that is fiber, cable or DSL internet. Other necessary computer equipment, will be provided. You may be required to work in the office if you do not have an adequate home work environment and the required internet connection.*** Job Posting End Date at 12:01 am on: 10-16-2026 Want the latest money news and views shaping how we live, work and play? Stay in the know with The Currency and sign up for Empower's free newsletter.

About Empower

Empower is a retirement plan recordkeeping financial holding company based in Greenwood Village, Colorado, United States. It is the second-largest retirement plan provider in the United States.
Learn more about Empower

Similar Jobs

More Jobs at Empower

More Information Technology Jobs

Find similar Dir Security Operations & Engineering jobs: