Acrisure

Director, Security Operations

Acrisure$125K — $150K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field.
  • 10+ years of progressive cybersecurity experience.
  • 5+ years leading Security Operations, Incident Response, Threat Hunting, SOC, or Cyber Defense teams.
  • Experience managing enterprise security operations in complex, hybrid cloud environments.
  • Deep understanding of incident response methodologies, threat detection, and cyber defense operations.
  • Experience with enterprise security platforms like Microsoft Defender, Google SecOps, or Splunk.
  • Strong leadership, communication, and stakeholder management skills.

Responsibilities

  • Lead security operations teams in monitoring, alert triage, and incident response.
  • Establish operational priorities aligned with risk reduction objectives.
  • Build scalable operating models for global detection and response.
  • Ensure consistent operational processes and service delivery standards.
  • Develop and mentor managers and analysts to foster continuous improvement.
  • Oversee enterprise detection and response capabilities across multiple environments.
  • Lead operational readiness programs including simulations and incident reviews.

Benefits

  • Opportunity to build a highly effective security operations program.
  • Collaborative cross-functional teamwork with various departments.
  • Focus on continuous improvement and automation in security operations.
  • Involvement in executive-level incident response and reporting.
  • High-visibility role with metrics-driven performance evaluation.
  • Potential for career growth in a rapidly evolving cybersecurity landscape.
Full Job Description


Job Summary

The Director, Security Operations leads the day-to-day execution and delivery of enterprise security operations capabilities, including threat detection, incident response, threat hunting, security monitoring, operational security platforms, and cyber defense processes. This role is accountable for managing teams responsible for detecting, investigating, containing, and responding to cybersecurity threats while continuously improving operational effectiveness through automation, process maturity, and technology optimization.

This is an execution-focused leadership role. Success is measured by operational excellence, rapid detection and response, platform reliability, measurable risk reduction, and strong partnership with Technology, Engineering, Legal, Privacy, Human Resources, and business stakeholders. The role does not own enterprise cybersecurity strategy but is responsible for translating strategy into operational outcomes.

Success in this role means building a highly effective security operations program that rapidly detects and responds to threats, continuously reduces operational risk, and enables the business to operate securely at scale. The Director establishes disciplined execution, operational reliability, and strong cross-functional partnerships while creating a culture of accountability, automation, and continuous improvement across the security operations organization.

Responsibilities:

Security Operations Leadership

  • Lead security operations teams responsible for security monitoring, alert triage, incident response, threat hunting, and cyber defense activities.
  • Establish operational priorities and execution plans aligned with organizational risk reduction objectives.
  • Build scalable operating models that enable efficient detection, investigation, and response across a global environment.
  • Ensure consistent operational processes, documentation, escalation procedures, and service delivery standards.
  • Develop and mentor managers, engineers, and analysts while fostering accountability, ownership, and continuous improvement.

Threat Detection & Response

  • Oversee enterprise detection and response capabilities across endpoint, identity, cloud, network, email, and application environments.
  • Ensure timely identification, investigation, containment, eradication, and recovery of cybersecurity incidents.
  • Act as a senior escalation point for major incidents and provide executive-level situational updates when required.
  • Lead operational readiness programs including playbooks, runbooks, tabletop exercises, simulations, and incident reviews.
  • Drive improvements to detection coverage and response effectiveness based on emerging threats, incidents, and intelligence.

Threat Hunting & Cyber Defense

  • Lead proactive threat hunting initiatives across enterprise environments.
  • Ensure threat intelligence is operationalized into detection content, hunting activities, and response procedures.
  • Drive maturity around adversary-focused operations utilizing frameworks such as MITRE ATT&CK.
  • Partner with Engineering and Infrastructure teams to address security weaknesses identified through operational activities.

Security Platforms & Operational Engineering

  • Own operational effectiveness of security technologies including SIEM, SOAR, EDR/XDR, threat intelligence, email security, cloud security, and related security operations tooling.
  • Drive automation initiatives that improve analyst efficiency, reduce response times, and minimize repetitive manual work.
  • Partner with Security Engineering teams to improve telemetry, integrations, detections, and platform reliability.
  • Ensure operational tooling remains scalable and aligned to business growth and acquisition activities.

Incident Management & Cross-Functional Coordination

  • Coordinate with Legal, Privacy, Human Resources, Compliance, Internal Audit, and Technology teams during security incidents.
  • Establish communication models and escalation paths for major cyber events.
  • Lead post-incident reviews to identify root causes, lessons learned, and corrective actions.
  • Ensure operational activities support regulatory, contractual, and reporting requirements.

Metrics, Reporting & Continuous Improvement

  • Define and maintain meaningful operational metrics and key performance indicators including:
  • Mean Time to Detect (MTTD)
  • Mean Time to Respond (MTTR)
  • Detection Coverage
  • Incident Severity Trends
  • Alert Fidelity
  • Automation Adoption
  • Threat Hunting Effectiveness
  • Provide regular operational reporting to cybersecurity leadership and executive stakeholders.
  • Drive disciplined continuous improvement efforts focused on increasing resilience and reducing organizational risk.

Minimum Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field.
  • 10+ years of progressive cybersecurity experience.
  • 5+ years leading Security Operations, Incident Response, Threat Hunting, SOC, or Cyber Defense teams.
  • Experience managing enterprise security operations in complex, hybrid cloud environments.
  • Deep understanding of incident response methodologies, threat detection, cyber defense operations, and security monitoring practices.
  • Experience with one or more enterprise security platforms including Microsoft Defender, Sentinel, SentinelOne, Google SecOps, Splunk, CrowdStrike, Palo Alto, or comparable technologies.
  • Strong leadership, communication, and stakeholder management skills.
  • Experience managing operational metrics, budgets, vendors, and service providers.

Preferred Qualifications

  • CISSP, GIAC, GCIH, GCFA, GCIA, CISM, or equivalent certifications.
  • Experience supporting cybersecurity operations for highly acquisitive or global organizations.
  • Experience with Microsoft Security E5 capabilities, Microsoft Defender XDR, Microsoft Sentinel, Purview, and Azure security technologies.
  • Experience implementing security automation and orchestration programs.
  • Familiarity with regulatory frameworks including NIST CSF, NIST 800-61, ISO 27001, NYDFS, SOX, and industry security best practices.
  • Experience leading ransomware, insider risk, cloud compromise, and business email compromise investigations.

Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.

About Acrisure

Acrisure is an insurance brokerage firm that provides a range of insurance products and services to businesses and individuals. The company was founded in 2005 and is headquartered in Caledonia, Michigan. Acrisure offers a wide range of insurance products, including property and casualty, employee benefits, and personal lines insurance. The company has grown rapidly through a series of acquisitions, and now has over 500 offices in the United States and around the world. Acrisure has been recognized as one of the fastest-growing companies in the United States, and has won numerous awards for its innovative insurance products and services.
Learn more about Acrisure
Size
7,000 employees
Industry
Founded
2006

Similar Jobs

More Jobs at Acrisure

More Information Technology Jobs

Find similar Director, Security Operations jobs: