The Role:The Director, Security Monitoring & Engineering leads the organization's enterprise security monitoring and engineering function, overseeing the full security operations lifecycle from threat detection and incident response through security architecture, engineering, and DevSecOps. Reporting to the VP, Cybersecurity, this role provides enterprise governance for Identity and Access Management (IAM), Data Loss Prevention (DLP), and vulnerability management while overseeing outsourced security monitoring capabilities. As a player-coach, the Director combines strategic leadership with hands-on technical expertise to strengthen security capabilities across a complex, multi-brand healthcare environment.
Primary Responsibilities- Lead enterprise security monitoring and incident response, providing strategic oversight of outsourced MDR/XDR services while strengthening detection, threat intelligence, behavioral analytics, forensic capabilities, and incident readiness.
- Own security architecture and engineering across cloud, network, endpoint, and application environments, designing and implementing scalable security solutions that protect enterprise systems and sensitive data.
- Lead enterprise DLP and IAM governance, establishing policies, controls, access standards, and workflows that strengthen least-privilege access and protect PHI and PII.
- Own the vulnerability management technology and operational lifecycle, including tooling, scanning capabilities, remediation tracking, metrics, and reporting in partnership with GRC and Security Operations.
- Build and mature DevSecOps and Secure SDLC capabilities, integrating security controls and testing into development pipelines while establishing secure coding and application security standards.
- Lead and develop the Security Monitoring & Engineering team while establishing clear responsibilities and operating models across internal teams, matrixed resources, and outsourced security providers.
What you Bring to the Table:Qualifications- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related technical field preferred.
- 10+ years of progressive, hands-on security operations and engineering experience, including leadership of security monitoring, SOC, or security engineering functions.
- Experience overseeing outsourced MDR/MSSP providers, including SLA management, detection use-case development, escalation governance, and performance management.
- Deep experience with SIEM/XDR, incident response, threat intelligence, security architecture, and behavioral analytics, with experience building or maturing DLP, IAM, vulnerability management, or DevSecOps capabilities.
- Strong knowledge of healthcare security and regulatory requirements, including HIPAA and HITRUST, with experience protecting PHI and other sensitive information.
- Experience operating across complex cloud and on-premises environments; CISSP, CISM, GIAC, or similar security certifications preferred.
Skills- Security operations
- Security engineering
- Incident response
- Security architecture
- Threat detection and intelligence
- IAM and DLP
- Vulnerability management
- DevSecOps
- Team leadership
- Executive communication
What we Bring to the Table:- Company-sponsored medical, dental, and vision plan for employees and their dependents
- 401(k) participation after 3 months of continuous service
- Wellness program, learning development program
- Life insurance, long-term disability coverage
- Charitable contribution matching, volunteer time off, and employee assistance program
- In addition to accrued vacation time and sick time, TEAM recognizes 12 paid federal holidays
The expected California Pay Range for this position:
$170,000-$200,000 USD