OVERVIEW
RESPONSIBILITIES
Job Information
The Director of Cyber Security Operations leads enterprise-wide security operations that protect the organization’s cloud-native and hybrid infrastructure, data, employee, and digital assets. This position is accountable for end-to-end cybersecurity monitoring, incident response, digital forensics, and supporting risk-reduction programs that preserve resilience and regulatory compliance. The role oversees advanced security architecture and tooling (SIEM, SOAR, AI/ML analytics), defines and reports organizational risk posture to executive leadership and regulators, and drives continuous innovation through process automation and technology modernization. This leader develops high-performing teams across monitoring, response, engineering, and cloud disciplines while integrating cybersecurity operations with enterprise IT and infrastructure functions to maintain audit-ready, financial-grade defenses.
Key Job Functions
Lead and mature enterprise-scale monitoring operations, including 24×7 Security Operations Center (SOC) oversight, real-time detection and alerting programs, telemetry optimization, and automation to reduce mean time to detect and respond.
Direct incident response and forensics programs, coordinating containment, eradication, and recovery across infrastructure and application domains while managing executive and regulatory communications during major security events.
Support risk-reduction initiatives encompassing vulnerability management, secure configuration baselines, patch governance, system integrity/authorized change, and compliance alignment for reduction in residual enterprise risk.
Architect and operationalize security platforms and analytics, implementing SIEM, SOAR, and AI/ML-driven tooling that enhance detection, automation, and response at enterprise scale.
Support cloud-native, hybrid and associated security operations, embedding DevSecOps practices, workload segmentation, and identity governance across cloud environments (AWS, Azure, GCP).
Define and report cyber-risk posture to executive leadership and regulatory bodies, aligning operational practices with enterprise risk frameworks and audit requirements.
Drive innovation and process automation in cybersecurity operations, evaluating emerging technologies to enhance predictive detection, orchestration, and operational efficiency.
Build, mentor, and lead high-performance cybersecurity teams across monitoring, response, engineering, and cloud disciplines, ensuring accountability and professional growth.
Integrate cybersecurity operations with infrastructure and IT processes, enforcing secure configuration standards, consistent baselines, and unified incident management workflows.
Represent the organization in audits, examinations, and crisis events, ensuring compliance with federal, financial, and industry-specific regulatory requirements.
QUALIFICATIONS
Education
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field required; Advanced degrees (MS, PhD) strongly preferred.
- Industry Certification required, e.g. GSOM, GSOC, CISSP, CISA, CISM or equivalent designation.
Minimum Experience
- Minimum of 10 years experience:
- Leading enterprise-scale monitoring operations, including 24×7 Security Operations Center management, real-time detection and alerting programs, “eyes-on-glass” analyst oversight, telemetry and log pipeline optimization, and the development of automated response processes to reduce mean time to detect and respond.
- Directing comprehensive incident response and forensics functions, encompassing major incident handling, digital evidence collection, post-mortem analysis, executive and regulator engagement during breaches, and coordination with infrastructure and engineering teams to ensure containment and eradication of threats.
- Architecting and operationalizinge advanced security platforms and tooling, including implementation of SIEM/SOAR systems, integration of AI/ML analytics into detection and response workflows, deployment of new enterprise-wide security solutions, and definition of long-term technical roadmaps for operational resilience.
- Minimum of 6-10 years experience:
- Managing enterprise-level risk-reduction programs, covering vulnerability management, compliance alignment, secure configuration baselining, patch governance, and audit remediation—driving measurable decreases in residual risk and ensuring adherence to regulatory and cybersecurity control frameworks.
- Overseeing cloud-native cybersecurity operations, ensuring protection of workloads across cloud providers (AWS, Azure, GCP); embedding DevSecOps practices; maintaining compliance within virtualized and hybrid infrastructures; and governing identity, access, and workload isolation in dynamic cloud environments.
- Applicants must be authorized to work in the US without requiring employer sponsorship currently or in the future. U.S. FinTech does not offer sponsorship for this position.
Specialized Knowledge & Skills
- Deep expertise in Security Operations Center (SOC) design and management, including tiered analyst structures, alert triage workflows, and automated incident response orchestration.
- Advanced proficiency in incident response leadership, including containment, eradication, digital forensics, and crisis communications with executive and regulatory stakeholders.
- Proven ability to architect and maintain SIEM and SOAR platforms (e.g., Splunk, Power Automate, Scripting, KQL), optimizing correlation logic, enrichment pipelines, and playbook automation.
- Strong knowledge of AI/ML integration in cybersecurity, including behavior-based analytics, anomaly detection, and large language model applications for threat hunting and automation.
- Expertise in vulnerability management and risk reduction, including threat-based prioritization, patch lifecycle governance, secure configuration baselines, and exposure, and leveraging that information to drive threat and compromise detection.
- Advanced understanding of secure cloud architecture and DevSecOps practices across AWS, Azure, and GCP, including workload isolation, zero-trust principles, and continuous compliance monitoring.
- Proficiency in digital forensics and evidence preservation, including memory, disk, and network artifact analysis aligned to legal and regulatory standards.
- Demonstrated capability to lead cybersecurity risk governance, mapping technical controls to NIST CSF, ISO 27001, SOC 2, and FHFA/Fed examination requirements, combined with strong understanding of regulatory and audit frameworks impacting fintech operations and enterprises.
- Strong command of cybersecurity automation and orchestration frameworks, integrating endpoint, identity, and network telemetry into cohesive operational pipelines.
- Strong knowledge in identity and access management (IAM), least-privilege enforcement, privileged-access controls, and integration with cloud-native identity providers.
- Experience implementing and tuning data loss prevention (DLP), insider risk, and threat intelligence programs to detect anomalous user and data activity.
- High fluency in security metrics and KPI development, including incident trends, dwell time analysis, patch compliance, and automation ROI reporting to executives.
- Significant skills in cross-functional program leadership, aligning cybersecurity operations with IT, infrastructure, compliance, and product engineering teams.
- Expertise in vendor and third-party risk management, including integration of external threat intelligence and performance monitoring.
- Ability to design and execute enterprise cybersecurity testing and validation programs, including tabletop exercises, red team coordination, and control assurance.
- Strong communication and executive presentation skills, translating technical risk into business impact for boards, regulators, and senior stakeholders.
- Track record of innovation and continuous improvement, leveraging automation, ML/AI, and analytics to modernize cybersecurity operations at scale.
- Exceptional leadership and team-building acumen, with the ability to recruit, mentor, and retain top technical talent across multiple cybersecurity domains.
Pay Range $208,500 to $235,750
U.S. FinTech's pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) a candidate’s qualifications, skills, competencies, and experience, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. U.S. FinTech offers a competitive total compensation package, which includes a performance bonus, 401k match, healthcare coverage, PTO, and a broad range of other benefits.
Employment
As a condition of employment with U.S. Financial Technology, any successful job applicant will be required to successfully complete a background investigation, which may also include a credit check for positions in some areas of our business.
##LI-Remote