OVERVIEWRESPONSIBILITIESJob InformationThe Director of Cyber Security Operations leads enterprise-wide security operations that protect the organization's cloud-native and hybrid infrastructure, data, employee, and digital assets. This position is accountable for end-to-end cybersecurity monitoring, incident response, digital forensics, and supporting risk-reduction programs that preserve resilience and regulatory compliance. The role oversees advanced security architecture and tooling (SIEM, SOAR, AI/ML analytics), defines and reports organizational risk posture to executive leadership and regulators, and drives continuous innovation through process automation and technology modernization. This leader develops high-performing teams across monitoring, response, engineering, and cloud disciplines while integrating cybersecurity operations with enterprise IT and infrastructure functions to maintain audit-ready, financial-grade defenses.
Key Job Functions- Lead and mature enterprise-scale monitoring operations, including 24x7 Security Operations Center (SOC) oversight, real-time detection and alerting programs, telemetry optimization, and automation to reduce mean time to detect and respond.
- Direct incident response and forensics programs, coordinating containment, eradication, and recovery across infrastructure and application domains while managing executive and regulatory communications during major security events.
- Support risk-reduction initiatives encompassing vulnerability management, secure configuration baselines, patch governance, system integrity/authorized change, and compliance alignment for reduction in residual enterprise risk.
- Architect and operationalize security platforms and analytics, implementing SIEM, SOAR, and AI/ML-driven tooling that enhance detection, automation, and response at enterprise scale.
- Support cloud-native, hybrid and associated security operations, embedding DevSecOps practices, workload segmentation, and identity governance across cloud environments (AWS, Azure, GCP).
- Define and report cyber-risk posture to executive leadership and regulatory bodies, aligning operational practices with enterprise risk frameworks and audit requirements.
- Drive innovation and process automation in cybersecurity operations, evaluating emerging technologies to enhance predictive detection, orchestration, and operational efficiency.
- Build, mentor, and lead high-performance cybersecurity teams across monitoring, response, engineering, and cloud disciplines, ensuring accountability and professional growth.
- Integrate cybersecurity operations with infrastructure and IT processes, enforcing secure configuration standards, consistent baselines, and unified incident management workflows.
- Represent the organization in audits, examinations, and crisis events, ensuring compliance with federal, financial, and industry-specific regulatory requirements.
QUALIFICATIONSEducation- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field required; Advanced degrees (MS, PhD) strongly preferred.
- Industry Certification required, e.g. GSOM, GSOC, CISSP, CISA, CISM or equivalent designation.
Minimum Experience - Minimum of 10 years experience:
- Leading enterprise-scale monitoring operations, including 24x7 Security Operations Center management, real-time detection and alerting programs, "eyes-on-glass" analyst oversight, telemetry and log pipeline optimization, and the development of automated response processes to reduce mean time to detect and respond.
- Directing comprehensive incident response and forensics functions, encompassing major incident handling, digital evidence collection, post-mortem analysis, executive and regulator engagement during breaches, and coordination with infrastructure and engineering teams to ensure containment and eradication of threats.
- Architecting and operationalizinge advanced security platforms and tooling, including implementation of SIEM/SOAR systems, integration of AI/ML analytics into detection and response workflows, deployment of new enterprise-wide security solutions, and definition of long-term technical roadmaps for operational resilience.
- Minimum of 6-10 years experience:
- Managing enterprise-level risk-reduction programs, covering vulnerability management, compliance alignment, secure configuration baselining, patch governance, and audit remediation-driving measurable decreases in residual risk and ensuring adherence to regulatory and cybersecurity control frameworks.
- Overseeing cloud-native cybersecurity operations, ensuring protection of workloads across cloud providers (AWS, Azure, GCP); embedding DevSecOps practices; maintaining compliance within virtualized and hybrid infrastructures; and governing identity, access, and workload isolation in dynamic cloud environments.
- Applicants must be authorized to work in the US without requiring employer sponsorship currently or in the future. U.S. FinTech does not offer sponsorship for this position.
Specialized Knowledge & Skills - Deep expertise in Security Operations Center (SOC) design and management, including tiered analyst structures, alert triage workflows, and automated incident response orchestration.
- Advanced proficiency in incident response leadership, including containment, eradication, digital forensics, and crisis communications with executive and regulatory stakeholders.
- Proven ability to architect and maintain SIEM and SOAR platforms (e.g., Splunk, Power Automate, Scripting, KQL), optimizing correlation logic, enrichment pipelines, and playbook automation.
- Strong knowledge of AI/ML integration in cybersecurity, including behavior-based analytics, anomaly detection, and large language model applications for threat hunting and automation.
- Expertise in vulnerability management and risk reduction, including threat-based prioritization, patch lifecycle governance, secure configuration baselines, and exposure, and leveraging that information to drive threat and compromise detection.
- Advanced understanding of secure cloud architecture and DevSecOps practices across AWS, Azure, and GCP, including workload isolation, zero-trust principles, and continuous compliance monitoring.
- Proficiency in digital forensics and evidence preservation, including memory, disk, and network artifact analysis aligned to legal and regulatory standards.
- Demonstrated capability to lead cybersecurity risk governance, mapping technical controls to NIST CSF, ISO 27001, SOC 2, and FHFA/Fed examination requirements, combined with strong understanding of regulatory and audit frameworks impacting fintech operations and enterprises.
- Strong command of cybersecurity automation and orchestration frameworks, integrating endpoint, identity, and network telemetry into cohesive operational pipelines.
- Strong knowledge in identity and access management (IAM), least-privilege enforcement, privileged-access controls, and integration with cloud-native identity providers.
- Experience implementing and tuning data loss prevention (DLP), insider risk, and threat intelligence programs to detect anomalous user and data activity.
- High fluency in security metrics and KPI development, including incident trends, dwell time analysis, patch compliance, and automation ROI reporting to executives.
- Significant skills in cross-functional program leadership, aligning cybersecurity operations with IT, infrastructure, compliance, and product engineering teams.
- Expertise in vendor and third-party risk management, including integration of external threat intelligence and performance monitoring.
- Ability to design and execute enterprise cybersecurity testing and validation programs, including tabletop exercises, red team coordination, and control assurance.
- Strong communication and executive presentation skills, translating technical risk into business impact for boards, regulators, and senior stakeholders.
- Track record of innovation and continuous improvement, leveraging automation, ML/AI, and analytics to modernize cybersecurity operations at scale.
- Exceptional leadership and team-building acumen, with the ability to recruit, mentor, and retain top technical talent across multiple cybersecurity domains.
Pay Range $208,500 to $235,750
U.S. FinTech's pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) a candidate's qualifications, skills, competencies, and experience, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. U.S. FinTech offers a competitive total compensation package, which includes a performance bonus, 401k match, healthcare coverage, PTO, and a broad range of other benefits.
EmploymentAs a condition of employment with U.S. Financial Technology, any successful job applicant will be required to successfully complete a background investigation, which may also include a credit check for positions in some areas of our business.
##LI-Remote