DescriptionDirector of Cybersecurity Technology and Operations Job Description Reports To Chief Information Security Officer (CISO)
Team Leadership 2 direct reports; 10 indirect reports
Location Spartanburg, South Carolina office - onsite
Travel Up to 10%
Role Profile Hands-on cybersecurity technology and operations leadership role
Position SummaryThe Director of Cybersecurity Technology and Operations reports to the CISO and provides hands-on technical and people leadership across the design, engineering, implementation, administration, and operation of enterprise information security capabilities. The role requires meaningful depth and breadth across both information technology and information security and is expected to remain actively engaged in architecture, engineering, technical decision-making, troubleshooting, and operational execution.
The Director leads a team of cybersecurity professionals while working collaboratively across the Information Security organization and in close partnership with Information Technology teams. Success requires sound judgment, transparent ownership of outcomes, disciplined execution, constructive challenge, and a strong commitment to building practical, resilient, and sustainable security solutions that support the organization's business objectives.
Key Responsibilities- Lead, coach, and develop a cybersecurity technology and operations team consisting of 2 direct reports and 10 indirect reports, establishing clear expectations, reinforcing ownership, and ensuring commitments are delivered with quality and professionalism.
- Serve as a hands-on technical leader who can move effectively between strategy, architecture, engineering, implementation, administration, operations, incident support, and complex technical problem solving.
- Own and advance security operations center (SOC) engineering capabilities, including the architecture, integration, tuning, automation, reliability, and operational effectiveness of security monitoring, detection, investigation, and response technologies.
- Lead Blue Team engineering and defensive security operations, including the design and continuous improvement of detection content, telemetry coverage, threat-informed monitoring, incident investigation and response workflows, endpoint and network defensive capabilities, security analytics, and automation that improves defensive speed, quality, and resilience.
- Lead Red Team and offensive security capabilities appropriate to the enterprise environment, including security testing, adversary emulation, attack-path validation, control effectiveness testing, and coordinated exercises that identify exploitable weaknesses and provide actionable remediation guidance. Promote productive Blue Team and Red Team collaboration to validate detections, strengthen controls, and measurably improve defensive readiness.
- Provide security architecture leadership across enterprise technology domains, translating security requirements into practical reference architectures, design patterns, technical standards, and implementation guidance.
- Partner with application development and engineering teams to strengthen application security and CI/CD security through secure design, automated testing, code and dependency security controls, pipeline protections, secrets management, and security integration throughout the software development lifecycle.
- Architect, implement, administer, and continuously improve cloud security controls and services, working with cloud and platform teams to support secure configurations, identity and access controls, workload protection, network security, logging, monitoring, and policy enforcement.
- Lead and contribute directly to AI security, AI engineering, and AI automation initiatives, including the secure design and implementation of AI-enabled security capabilities, protection of AI systems and data, risk-informed use of automation, and engineering of repeatable controls and workflows.
- Provide technical leadership for on-premises security, enterprise networking security, firewalls, segmentation, secure connectivity, and related infrastructure protections, partnering closely with IT infrastructure and network engineering teams.
- Engineer, implement, administer, and operate security controls that are measurable, supportable, resilient, and aligned with enterprise risk, technology architecture, and operational requirements.
- Collaborate across the Information Security team to ensure security engineering and operational solutions support broader cybersecurity objectives, risk management priorities, architecture standards, governance requirements, and incident response needs.
- Build strong working relationships with Information Technology teams and engage as a trusted technical partner in the architecture, implementation, administration, and operation of information security solutions across shared technology environments.
- Make risk-based technical decisions with integrity, clearly document tradeoffs, surface material risks and constraints, and escalate issues when necessary rather than allowing unresolved concerns to remain hidden or ambiguous.
- Take initiative to identify control gaps, operational weaknesses, technical debt, automation opportunities, and emerging risks; develop practical solutions and follow through from concept to sustained operational adoption.
- Promote partnership and shared accountability across organizational boundaries by seeking input early, resolving technical disagreements constructively, and balancing security, reliability, usability, cost, and business outcomes.
- Apply a stewardship mindset to technology investments by evaluating value, scalability, maintainability, and total operational impact; favor solutions that responsibly improve security outcomes while making effective use of organizational resources.
- Create an environment in which team members can do meaningful work, grow their technical capabilities, take appropriate ownership, and understand how their contributions support the organization and its customers.
- Ensure security technologies and processes are appropriately documented, supportable, monitored, and transitioned into sustainable operating models with clear ownership, procedures, metrics, and escalation paths.
- Support incident response, major technology events, and high-priority security issues as a senior technical escalation point when leadership judgment and cross-domain expertise are required.
Core Technology and Security Domains• Security Operations Center Engineering
• AI Engineering
• Security Architecture
• CI/CD Security
• Application Security
• On-Premises Security
• Cloud Security
• Networking and Network Security
• AI Security
• Firewalls and Segmentation
• AI Automation
• Security Controls Engineering
• Blue Team Engineering and Defensive Operations
• Red Team Engineering and Adversary Emulation
Required Qualifications- Bachelor's degree in an information technology or information security field.
- Minimum of 5 years of demonstrated professional experience in information technology and a minimum of 5 years of demonstrated professional experience in information security. These experience periods may overlap.
- Minimum of 5 years of prior people-management and technical-leadership experience.
- Demonstrated hands-on technical experience relevant to multiple areas within the role's responsibilities, including security engineering, architecture, operations, application or cloud security, networking, firewalls, CI/CD security, AI-related security or engineering, and security controls engineering.
- Demonstrated Blue Team experience in defensive security engineering or operations, including security monitoring, detection engineering, threat-informed defense, incident investigation and response, telemetry and analytics, and validation of defensive control effectiveness.
- Demonstrated Red Team or offensive security experience relevant to enterprise environments, including security testing, adversary emulation, attack-path analysis, control validation, and clear communication of technical findings and remediation priorities. Experience using collaborative or purple-team approaches to improve defensive coverage is highly relevant.
- Demonstrated ability to architect, implement, administer, operate, and troubleshoot enterprise security technologies in partnership with information technology and information security teams.
- Strong written and verbal communication skills, including the ability to explain technical risks, architectural decisions, priorities, and tradeoffs to technical and leadership audiences.
- Ability to work onsite at the Spartanburg, South Carolina office and travel up to 10%.
Preferred Education and CertificationsAdvanced education and professional certifications that demonstrate continued development across information technology, information security, cloud, architecture, networking, software security, and AI-related disciplines are preferred. Relevant examples include:
- Master's degree in cybersecurity, information security, computer science, information technology, engineering, or a related discipline.
- Information security certifications such as CISSP, CCSP, CSSLP, CISM, or GIAC certifications aligned to the role's technical responsibilities.
- Blue Team, incident response, detection engineering, penetration testing, offensive security, or adversary-emulation certifications such as relevant GIAC, Offensive Security, or comparable industry credentials.
- Cloud security or cloud architecture certifications from major cloud providers, such as AWS, Microsoft Azure, or Google Cloud, where relevant to the organization's technology environment.
- Networking and infrastructure certifications such as Cisco professional-level certifications or equivalent demonstrated expertise.
- Security architecture certifications or credentials relevant to enterprise security architecture and design.
- DevSecOps, secure software development, Kubernetes/container security, automation, or infrastructure-as-code certifications or formal training relevant to the role.
- AI security, AI engineering, machine learning, or responsible AI certifications or formal technical education relevant to securing and engineering AI-enabled systems.
Leadership and Working Style- Leads from a position of personal accountability, follows through on commitments, and expects the same level of ownership from the team.
- Acts with sound judgment and integrity, particularly when technical facts, risk concerns, or business pressures create difficult tradeoffs.
- Works collaboratively across Information Security and Information Technology, treating shared outcomes as more important than organizational boundaries.
- Proactively identifies opportunities to improve security, simplify operations, reduce manual effort, and strengthen technical resilience without waiting for issues to become urgent.
- Encourages thoughtful experimentation and responsible innovation while maintaining disciplined risk management, operational reliability, and appropriate controls.
- Creates conditions for meaningful contribution and professional growth by delegating appropriately, developing technical talent, recognizing strong performance, and addressing performance issues directly and fairly.
- Balances security effectiveness, customer and business needs, operational sustainability, and responsible use of resources when making technology decisions.
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.