Seagate Technology LLC

Director, Security Operations (Onsite)

Seagate Technology LLC$167K — $249K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years of cybersecurity experience, including 7+ years in Security Operations or SOC leadership.
  • Proven experience managing global 24x7 security operations teams across a hybrid delivery model.
  • In-depth knowledge of incident response, threat intelligence, and vulnerability management processes.
  • Familiarity with modern security operations technologies like SIEM, EDR/XDR, and SOAR.
  • Demonstrated ability to communicate complex technical issues to senior leadership and non-technical stakeholders.

Responsibilities

  • Lead and execute the global Security Operations strategy and establish measurable performance outcomes.
  • Ensure 24x7 monitoring and incident response across enterprise IT and OT environments.
  • Develop and maintain detection engineering capabilities and threat hunting initiatives.
  • Own the incident response framework, including playbooks and escalation procedures.
  • Manage vulnerability programs and coordinate remediation across security and business teams.

Benefits

  • Eligibility for a discretionary bonus program.
  • Comprehensive medical, dental, and vision insurance.
  • 401(k) with company contribution and employee stock purchase plan.
  • Paid time off, including holidays and flexible leave options.
  • 16 weeks of paid parental leave and health savings accounts.
Full Job Description
About the role - you will:

The Director, Security Operations leads Seagate's global Security Operations capability and is accountable for a mature, measurable, and continuously improving defense program.

The role leads 24x7 monitoring and response and oversees the Security Operations portfolio across SOC, incident response, detection engineering, threat intelligence, threat hunting, vulnerability management coordination, firewall operations, and security control operations assigned to the function.

  • Lead a global Security Operations organization with clear ownership, priorities, service levels, and measurable outcomes.
  • Operate effectively across internal teams, managed security service providers, specialist partners, and retained incident-response capabilities.
  • Ensure monitoring, detection, response, and vulnerability management coverage is appropriate across enterprise IT, cloud, and OT environments, in partnership with OT Security where applicable.
  • Translate operational security signals into prioritized action and clear communication for Information Security, IT, manufacturing, engineering, and business stakeholders.
  • Build a high-accountability team culture focused on disciplined execution, continuous improvement, and risk reduction.


This is a people leadership role with global responsibility, including oversight of a firewall operations manager and team responsible for firewall-related service requests and operational execution.

About you:

  • You are a pragmatic, execution-oriented security leader who combines strong operational judgment with enough technical depth to challenge assumptions and make sound decisions.
  • You remain calm during high-severity incidents and communicate clearly with both technical and executive audiences.
  • You focus on outcomes over activity and use data to prioritize the work that most improves security outcomes.
  • You are comfortable operating in complex, heterogeneous environments with competing priorities and constraints.
  • You build strong partnerships while maintaining clear accountability and decision rights.


You will be responsible for the following activities:

Security Operations Leadership & Operating Model:

  • Own the Security Operations strategy, service portfolio, staffing model, priorities, and performance.
  • Set clear accountabilities across in-house teams, managed services, and specialist providers, including service levels and escalation paths.
  • Establish a risk-based operating cadence focused on the highest-impact threats, incidents, vulnerabilities, and control gaps.


SOC, Detection Engineering & Threat Hunting:

  • Lead 24x7 monitoring, triage, escalation, and advanced analysis across enterprise IT, cloud, and OT environments, including OT-related security alerts in partnership with OT Security.
  • Own the detection lifecycle: use-case strategy, rule development, testing, tuning, coverage analysis, and retirement of ineffective detections.
  • Build an intelligence-led threat hunting capability and partner with Architecture & Engineering on SIEM, EDR/XDR, telemetry, and security platform architecture.


Incident Response & Crisis Readiness:

  • Own incident response plans, playbooks, severity models, command structures, and escalation processes.
  • Lead or oversee significant incidents from investigation and containment through recovery and post-incident review, including OT-related cyber incidents in coordination with OT Security and manufacturing stakeholders.
  • Maintain enterprise and plant/engineering-specific playbooks, tabletop exercises, simulations, and forensics readiness.


Threat Intelligence & Vulnerability Management:

  • Own threat intelligence collection, analysis, prioritization, and operationalization, translating intelligence into detections, hunts, and response readiness.
  • Lead the vulnerability management program by driving scanning coverage, risk-based prioritization, tracking, escalation, and reporting, while coordinating remediation through accountable system, application, infrastructure, and OT owners.
  • Coordinate remediation with Architecture & Engineering, IT, application teams, OT Security, and business owners using exposure, exploitability, asset criticality, and threat context.


Security Control Operations & Service Reliability:

  • Oversee centralized firewall operations, including a manager-led team responsible for firewall service requests, port open and close requests, change execution, monitoring, and operational reliability.
  • Ensure EDR/XDR and related controls are used effectively for investigation, containment, and response. Partner with Architecture & Engineering on platform engineering and lifecycle management.
  • Drive automation and orchestration that improve analyst efficiency, response speed, consistency, and quality.


Metrics, Continuous Improvement & Partnerships:

  • Define operational metrics, including time to detect, time to contain/respond, detection coverage and fidelity, incident recurrence, remediation velocity, and service performance.
  • Provide clear, fact-based reporting on operational effectiveness, trends, risks, trade-offs, and constraints to Information Security and IT leadership.
  • Create a closed-loop feedback process so incident lessons, threat intelligence, control failures, and vulnerability trends inform future architecture, engineering, and risk decisions.
  • Recruit, develop, coach, and retain a high-performing global team and hold security service providers accountable for measurable outcomes.


Your experience includes:

  • Typically 12+ years of cybersecurity experience, including 7+ years leading Security Operations, SOC, incident response, or closely related teams in a large enterprise environment.
  • Demonstrated experience leading global or distributed 24x7 security operations using in-house, managed-service, or hybrid delivery models.
  • Experience overseeing firewall operations or similar security-control service teams responsible for request intake, change execution, access changes, and operational reliability.
  • Strong experience with incident response, crisis management, detection engineering, threat intelligence, threat hunting, and vulnerability management.
  • Working knowledge of modern security operations technologies, including SIEM, EDR/XDR, SOAR, threat intelligence, and vulnerability management platforms.
  • Experience establishing operational metrics and using data to improve control effectiveness, detection quality, response performance, and remediation outcomes.
  • Demonstrated ability to lead high-severity incidents and communicate technical issues, business impact, decisions, and trade-offs to senior leadership.
  • Proven people leadership experience, including organizational design, talent development, performance management, and leading through change.
  • Strong experience managing security service providers and holding third parties accountable for measurable outcomes.


You Might Also Have:

  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Engineering, or a related technical discipline and 15+ years of experience; or 12 years and a Master's degree; or a PhD with 8 years of experience; or equivalent experience.
  • Experience in manufacturing, OT, industrial, or other environments where availability, safety, and operational continuity materially affect security decisions.
  • Experience improving security operations across complex hybrid environments spanning on-premises infrastructure, cloud services, endpoints, identity, and OT.
  • Certifications such as CISSP, CISM, GIAC incident response/detection certifications, or equivalent practical experience.
  • Experience with global incident exercises, forensics retainers, regulatory or customer security obligations, and executive-level security reporting.


The estimated base salary range for this position is $167,730.00 - $249,071.00. The individual salary is based on work location and additional factors, including job-related skills, experience, and relevant education or training.

Seagate offers comprehensive benefits to its eligible employees, including, but not limited to, eligibility to participate in a discretionary bonus program, medical, dental, vision, and life insurance, short- and long-term disability, 401(k), employee stock purchase plan, health savings account, dependent care, and healthcare spending accounts. Seagate also offers paid time off, including 12 holidays, flexible time off provided pursuant to Seagate policy, a minimum of 48 hours of paid sick leave, and 16 weeks of paid parental leave. The benefits for this position are based on a full-time schedule for a full calendar year and may differ depending on work location.

Location:

This role is an on-site position based in Longmont, CO.

Our Longmont product-design campus is nestled against the foothills with exceptional views of the Rocky Mountains. Here at work, you can grab breakfast and lunch in the on-site cafeteria or get an afternoon espresso, prepared by a professional barista. Our 600+ employees enjoy an active on-site experience from sporting activities (get in a few laps at lunch on our 1-mile walking path around campus, play ping-pong or volleyball, or stop in our 24-hour fitness center for a group or individual workout). We also offer opportunities for community service and participation in various employee resource groups.

Location: Longmont, United States
Travel: Up to 10%

About Seagate Technology LLC

Seagate Technology LLC is an American data storage company. It was incorporated in 1978 as Shugart Technology and commenced business in 1979. Since then, the company has been providing data storage solutions to a wide range of customers, including businesses, governments, and individuals. Seagate Technology LLC is headquartered in Cupertino, California, and has operations in more than 40 countries around the world. The company is known for its hard disk drives, solid-state drives, and hybrid drives, which are used in a variety of applications, including desktop and laptop computers, gaming consoles, and data centers.
Learn more about Seagate Technology LLC
Size
40,000 employees
Market Cap
$10.6 billion
Industry
Net Income
$989 million
Founded
1979
5 Year Trend
+1.6%
Revenue
$10.1 billion
NASDAQ

Similar Jobs

More Jobs at Seagate Technology LLC

More Information Technology Jobs

Find similar Director, Security Operations (Onsite) jobs: