Director of Cyber Security Operations

Common Securitization Solutions

• $208K — $235K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field; advanced degrees preferred.
  • Industry certification required (e.g., GSOM, GSOC, CISSP, CISA, CISM).
  • 10+ years experience in leading enterprise-scale security operations, specifically in SOC management and incident response.
  • 6-10 years experience in managing risk-reduction programs and overseeing cloud-native cybersecurity operations.
  • Expertise in advanced security technologies, including SIEM and SOAR platforms.

Responsibilities

  • Lead and mature enterprise-scale security operations with a 24×7 SOC.
  • Direct incident response and forensic investigations, managing key communications during security events.
  • Support risk-reduction initiatives aligned with compliance and cyber risk frameworks.
  • Architect and deploy advanced security systems and AI/ML-driven tools.
  • Oversee cloud security operations, integrating DevSecOps and workload isolation strategies.
  • Define organizational risk posture reports for executive leadership and regulators.
  • Drive innovation in cybersecurity processes and technologies.

Benefits

  • Performance-based bonus structure
  • 401k matching program
  • Healthcare coverage
  • Paid time off (PTO) policy
  • Flexible working arrangements in a remote role
Full Job Description
OVERVIEW

 

RESPONSIBILITIES

 

Job Information

The Director of Cyber Security Operations leads enterprise-wide security operations that protect the organization’s cloud-native and hybrid infrastructure, data, employee, and digital assets. This position is accountable for end-to-end cybersecurity monitoring, incident response, digital forensics, and supporting risk-reduction programs that preserve resilience and regulatory compliance. The role oversees advanced security architecture and tooling (SIEM, SOAR, AI/ML analytics), defines and reports organizational risk posture to executive leadership and regulators, and drives continuous innovation through process automation and technology modernization. This leader develops high-performing teams across monitoring, response, engineering, and cloud disciplines while integrating cybersecurity operations with enterprise IT and infrastructure functions to maintain audit-ready, financial-grade defenses. 

 

Key Job Functions

  • Lead and mature enterprise-scale monitoring operations, including 24×7 Security Operations Center (SOC) oversight, real-time detection and alerting programs, telemetry optimization, and automation to reduce mean time to detect and respond.

     

  • Direct incident response and forensics programs, coordinating containment, eradication, and recovery across infrastructure and application domains while managing executive and regulatory communications during major security events.

     

  • Support risk-reduction initiatives encompassing vulnerability management, secure configuration baselines, patch governance, system integrity/authorized change, and compliance alignment for reduction in residual enterprise risk.

     

  • Architect and operationalize security platforms and analytics, implementing SIEM, SOAR, and AI/ML-driven tooling that enhance detection, automation, and response at enterprise scale.

     

  • Support cloud-native, hybrid and associated security operations, embedding DevSecOps practices, workload segmentation, and identity governance across cloud environments (AWS, Azure, GCP).

     

  • Define and report cyber-risk posture to executive leadership and regulatory bodies, aligning operational practices with enterprise risk frameworks and audit requirements.

     

  • Drive innovation and process automation in cybersecurity operations, evaluating emerging technologies to enhance predictive detection, orchestration, and operational efficiency.

     

  • Build, mentor, and lead high-performance cybersecurity teams across monitoring, response, engineering, and cloud disciplines, ensuring accountability and professional growth.

     

  • Integrate cybersecurity operations with infrastructure and IT processes, enforcing secure configuration standards, consistent baselines, and unified incident management workflows.

     

  • Represent the organization in audits, examinations, and crisis events, ensuring compliance with federal, financial, and industry-specific regulatory requirements.

     

QUALIFICATIONS

 

Education   

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field required; Advanced degrees (MS, PhD) strongly preferred.
  • Industry Certification required, e.g. GSOM, GSOC, CISSP, CISA, CISM or equivalent designation.

Minimum Experience  

  • Minimum of 10 years experience: 
    • Leading enterprise-scale monitoring operations, including 24×7 Security Operations Center management, real-time detection and alerting programs, “eyes-on-glass” analyst oversight, telemetry and log pipeline optimization, and the development of automated response processes to reduce mean time to detect and respond. 
    • Directing comprehensive incident response and forensics functions, encompassing major incident handling, digital evidence collection, post-mortem analysis, executive and regulator engagement during breaches, and coordination with infrastructure and engineering teams to ensure containment and eradication of threats.
    • Architecting and operationalizinge advanced security platforms and tooling, including implementation of SIEM/SOAR systems, integration of AI/ML analytics into detection and response workflows, deployment of new enterprise-wide security solutions, and definition of long-term technical roadmaps for operational resilience.
  • Minimum of 6-10 years experience: 
    • Managing enterprise-level risk-reduction programs, covering vulnerability management, compliance alignment, secure configuration baselining, patch governance, and audit remediation—driving measurable decreases in residual risk and ensuring adherence to regulatory and cybersecurity control frameworks.  
    • Overseeing cloud-native cybersecurity operations, ensuring protection of workloads across cloud providers (AWS, Azure, GCP); embedding DevSecOps practices; maintaining compliance within virtualized and hybrid infrastructures; and governing identity, access, and workload isolation in dynamic cloud environments. 
  • Applicants must be authorized to work in the US without requiring employer sponsorship currently or in the future. U.S. FinTech does not offer sponsorship for this position.

 

Specialized Knowledge & Skills     

  • Deep expertise in Security Operations Center (SOC) design and management, including tiered analyst structures, alert triage workflows, and automated incident response orchestration.
  • Advanced proficiency in incident response leadership, including containment, eradication, digital forensics, and crisis communications with executive and regulatory stakeholders.
  • Proven ability to architect and maintain SIEM and SOAR platforms (e.g., Splunk, Power Automate, Scripting, KQL), optimizing correlation logic, enrichment pipelines, and playbook automation.
  • Strong knowledge of AI/ML integration in cybersecurity, including behavior-based analytics, anomaly detection, and large language model applications for threat hunting and automation.
  • Expertise in vulnerability management and risk reduction, including threat-based prioritization, patch lifecycle governance, secure configuration baselines, and exposure, and leveraging that information to drive threat and compromise detection.
  • Advanced understanding of secure cloud architecture and DevSecOps practices across AWS, Azure, and GCP, including workload isolation, zero-trust principles, and continuous compliance monitoring.
  • Proficiency in digital forensics and evidence preservation, including memory, disk, and network artifact analysis aligned to legal and regulatory standards.
  • Demonstrated capability to lead cybersecurity risk governance, mapping technical controls to NIST CSF, ISO 27001, SOC 2, and FHFA/Fed examination requirements, combined with strong understanding of regulatory and audit frameworks impacting fintech operations and enterprises.
  • Strong command of cybersecurity automation and orchestration frameworks, integrating endpoint, identity, and network telemetry into cohesive operational pipelines.
  • Strong knowledge in identity and access management (IAM), least-privilege enforcement, privileged-access controls, and integration with cloud-native identity providers.
  • Experience implementing and tuning data loss prevention (DLP), insider risk, and threat intelligence programs to detect anomalous user and data activity.
  • High fluency in security metrics and KPI development, including incident trends, dwell time analysis, patch compliance, and automation ROI reporting to executives.
  • Significant skills in cross-functional program leadership, aligning cybersecurity operations with IT, infrastructure, compliance, and product engineering teams.
  • Expertise in vendor and third-party risk management, including integration of external threat intelligence and performance monitoring.
  • Ability to design and execute enterprise cybersecurity testing and validation programs, including tabletop exercises, red team coordination, and control assurance.
  • Strong communication and executive presentation skills, translating technical risk into business impact for boards, regulators, and senior stakeholders.
  • Track record of innovation and continuous improvement, leveraging automation, ML/AI, and analytics to modernize cybersecurity operations at scale.
  • Exceptional leadership and team-building acumen, with the ability to recruit, mentor, and retain top technical talent across multiple cybersecurity domains.

 

Pay Range $208,500 to $235,750

 

U.S. FinTech's pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) a candidate’s qualifications, skills, competencies, and experience, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. U.S. FinTech offers a competitive total compensation package, which includes a performance bonus, 401k match, healthcare coverage, PTO, and a broad range of other benefits.

 

Employment

As a condition of employment with U.S. Financial Technology, any successful job applicant will be required to  successfully complete a background investigation, which may also include a credit check for positions in some areas of our business.   

     

##LI-Remote

Similar Jobs

More Jobs at Common Securitization Solutions

More Information Technology Jobs

Find similar Director of Cyber Security Operations jobs: