Director of Cyber Security Operations

U.S. Financial Technology

• $208K — $235K *
US-AnywhereRemote in United States
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity, or related field; advanced degrees preferred.
  • Relevant industry certification required (e.g., GSOM, GSOC, CISSP, CISA, CISM).
  • 10 years leading enterprise-scale SOC operations with automated response processes.
  • Experience in directing incident response and forensic functions during major security events for 6-10 years.
  • 6-10 years in managing risk-reduction programs and overseeing cloud-native cybersecurity operations.

Responsibilities

  • Lead enterprise-scale monitoring operations and 24x7 SOC oversight.
  • Direct incident response and forensic programs during major security events.
  • Support risk-reduction initiatives including vulnerability management and compliance alignment.
  • Architect and operationalize security platforms, implementing advanced SIEM and SOAR tools.
  • Support cloud-native security operations and embed DevSecOps practices.
  • Define and report cyber-risk posture to leadership and regulatory bodies.
  • Drive innovation and process automation in cybersecurity operations.

Benefits

  • Performance bonus and 401k match.
  • Comprehensive healthcare coverage.
  • Generous paid time off (PTO).
  • Broad range of additional benefits.
Full Job Description
OVERVIEW

RESPONSIBILITIES

Job Information

The Director of Cyber Security Operations leads enterprise-wide security operations that protect the organization's cloud-native and hybrid infrastructure, data, employee, and digital assets. This position is accountable for end-to-end cybersecurity monitoring, incident response, digital forensics, and supporting risk-reduction programs that preserve resilience and regulatory compliance. The role oversees advanced security architecture and tooling (SIEM, SOAR, AI/ML analytics), defines and reports organizational risk posture to executive leadership and regulators, and drives continuous innovation through process automation and technology modernization. This leader develops high-performing teams across monitoring, response, engineering, and cloud disciplines while integrating cybersecurity operations with enterprise IT and infrastructure functions to maintain audit-ready, financial-grade defenses.

Key Job Functions
  • Lead and mature enterprise-scale monitoring operations, including 24x7 Security Operations Center (SOC) oversight, real-time detection and alerting programs, telemetry optimization, and automation to reduce mean time to detect and respond.
  • Direct incident response and forensics programs, coordinating containment, eradication, and recovery across infrastructure and application domains while managing executive and regulatory communications during major security events.
  • Support risk-reduction initiatives encompassing vulnerability management, secure configuration baselines, patch governance, system integrity/authorized change, and compliance alignment for reduction in residual enterprise risk.
  • Architect and operationalize security platforms and analytics, implementing SIEM, SOAR, and AI/ML-driven tooling that enhance detection, automation, and response at enterprise scale.
  • Support cloud-native, hybrid and associated security operations, embedding DevSecOps practices, workload segmentation, and identity governance across cloud environments (AWS, Azure, GCP).
  • Define and report cyber-risk posture to executive leadership and regulatory bodies, aligning operational practices with enterprise risk frameworks and audit requirements.
  • Drive innovation and process automation in cybersecurity operations, evaluating emerging technologies to enhance predictive detection, orchestration, and operational efficiency.
  • Build, mentor, and lead high-performance cybersecurity teams across monitoring, response, engineering, and cloud disciplines, ensuring accountability and professional growth.
  • Integrate cybersecurity operations with infrastructure and IT processes, enforcing secure configuration standards, consistent baselines, and unified incident management workflows.
  • Represent the organization in audits, examinations, and crisis events, ensuring compliance with federal, financial, and industry-specific regulatory requirements.


QUALIFICATIONS

Education
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field required; Advanced degrees (MS, PhD) strongly preferred.
  • Industry Certification required, e.g. GSOM, GSOC, CISSP, CISA, CISM or equivalent designation.

Minimum Experience
  • Minimum of 10 years experience:
    • Leading enterprise-scale monitoring operations, including 24x7 Security Operations Center management, real-time detection and alerting programs, "eyes-on-glass" analyst oversight, telemetry and log pipeline optimization, and the development of automated response processes to reduce mean time to detect and respond.
    • Directing comprehensive incident response and forensics functions, encompassing major incident handling, digital evidence collection, post-mortem analysis, executive and regulator engagement during breaches, and coordination with infrastructure and engineering teams to ensure containment and eradication of threats.
    • Architecting and operationalizinge advanced security platforms and tooling, including implementation of SIEM/SOAR systems, integration of AI/ML analytics into detection and response workflows, deployment of new enterprise-wide security solutions, and definition of long-term technical roadmaps for operational resilience.
  • Minimum of 6-10 years experience:
    • Managing enterprise-level risk-reduction programs, covering vulnerability management, compliance alignment, secure configuration baselining, patch governance, and audit remediation-driving measurable decreases in residual risk and ensuring adherence to regulatory and cybersecurity control frameworks.
    • Overseeing cloud-native cybersecurity operations, ensuring protection of workloads across cloud providers (AWS, Azure, GCP); embedding DevSecOps practices; maintaining compliance within virtualized and hybrid infrastructures; and governing identity, access, and workload isolation in dynamic cloud environments.
  • Applicants must be authorized to work in the US without requiring employer sponsorship currently or in the future. U.S. FinTech does not offer sponsorship for this position.


Specialized Knowledge & Skills
  • Deep expertise in Security Operations Center (SOC) design and management, including tiered analyst structures, alert triage workflows, and automated incident response orchestration.
  • Advanced proficiency in incident response leadership, including containment, eradication, digital forensics, and crisis communications with executive and regulatory stakeholders.
  • Proven ability to architect and maintain SIEM and SOAR platforms (e.g., Splunk, Power Automate, Scripting, KQL), optimizing correlation logic, enrichment pipelines, and playbook automation.
  • Strong knowledge of AI/ML integration in cybersecurity, including behavior-based analytics, anomaly detection, and large language model applications for threat hunting and automation.
  • Expertise in vulnerability management and risk reduction, including threat-based prioritization, patch lifecycle governance, secure configuration baselines, and exposure, and leveraging that information to drive threat and compromise detection.
  • Advanced understanding of secure cloud architecture and DevSecOps practices across AWS, Azure, and GCP, including workload isolation, zero-trust principles, and continuous compliance monitoring.
  • Proficiency in digital forensics and evidence preservation, including memory, disk, and network artifact analysis aligned to legal and regulatory standards.
  • Demonstrated capability to lead cybersecurity risk governance, mapping technical controls to NIST CSF, ISO 27001, SOC 2, and FHFA/Fed examination requirements, combined with strong understanding of regulatory and audit frameworks impacting fintech operations and enterprises.
  • Strong command of cybersecurity automation and orchestration frameworks, integrating endpoint, identity, and network telemetry into cohesive operational pipelines.
  • Strong knowledge in identity and access management (IAM), least-privilege enforcement, privileged-access controls, and integration with cloud-native identity providers.
  • Experience implementing and tuning data loss prevention (DLP), insider risk, and threat intelligence programs to detect anomalous user and data activity.
  • High fluency in security metrics and KPI development, including incident trends, dwell time analysis, patch compliance, and automation ROI reporting to executives.
  • Significant skills in cross-functional program leadership, aligning cybersecurity operations with IT, infrastructure, compliance, and product engineering teams.
  • Expertise in vendor and third-party risk management, including integration of external threat intelligence and performance monitoring.
  • Ability to design and execute enterprise cybersecurity testing and validation programs, including tabletop exercises, red team coordination, and control assurance.
  • Strong communication and executive presentation skills, translating technical risk into business impact for boards, regulators, and senior stakeholders.
  • Track record of innovation and continuous improvement, leveraging automation, ML/AI, and analytics to modernize cybersecurity operations at scale.
  • Exceptional leadership and team-building acumen, with the ability to recruit, mentor, and retain top technical talent across multiple cybersecurity domains.


Pay Range $208,500 to $235,750

U.S. FinTech's pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) a candidate's qualifications, skills, competencies, and experience, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. U.S. FinTech offers a competitive total compensation package, which includes a performance bonus, 401k match, healthcare coverage, PTO, and a broad range of other benefits.

Employment

As a condition of employment with U.S. Financial Technology, any successful job applicant will be required to successfully complete a background investigation, which may also include a credit check for positions in some areas of our business.

##LI-Remote

Similar Jobs

More Jobs at U.S. Financial Technology

More Finance & Insurance Jobs

Find similar Director of Cyber Security Operations jobs: