Director, Cybersecurity Operations

🏢 KLDiscovery · all 20 jobs
📍 United States
📅 Posted Sep 13, 2026 · via Himalayas
🏷 Director Of Security Operations, Director Of Cybersecurity, Security Operations Leadership, Ciso, Incident Response Director, Cybersecurity Director +3 more
Apply on original site ↗

Role overview

The Director, Cybersecurity Operations leads Security Operations and Incident Response, Security Engineering, Vulnerability Management, and Threat Intelligence. This is a player-coach leadership role reporting directly to the CISO, partnering with the Director, Cyber GRC as one unified cyber team. The Director will bring hands-on technical depth, strong leadership capability, and the ability to modernize security operations through MDR deployment, AI-informed detection, and a security engineering team organized around functional specialization.
Key responsibilities

Security operations and incident response Security operations and incident response

-
Own the MDR relationship, including SLA management, escalation accountability, detection tuning, and quarterly threat hunt reviews

-
Lead the incident response function: IR runbooks, major incident coordination, executive communication during active incidents, and post-incident root cause analysis

-
Oversee SOC detection engineering, ensuring SIEM rules, SOAR playbooks, and automated response actions are maintained, tested, and tuned to the current threat landscape

-
Direct and develop the security analyst pool, redeploying analyst capacity from frontline triage toward MDR validation, threat hunt support, and stakeholder reporting

Security engineering

-
Oversee four specialized engineering lanes [endpoint, identity, cloud, and application security], ensuring each lane has clear ownership, defined scope, and measurable outcomes

-
Drive security architecture reviews and engineering decisions for large or complex IT projects, ensuring security requirements are built in rather than bolted on

-
Shape the security tooling stack strategy, evaluating, selecting, and retiring tools across endpoint, identity, cloud, and application security

-
Enforce automation-first engineering practices, including IaC security gates, CI/CD pipeline security, CSPM auto-remediation, and SOAR-driven response workflows

Threat intelligence, vulnerability management, and control validation

-
Lead the operationalization of threat intelligence, translating MDR findings and external threat data into detection rule updates, architecture decisions, and risk register inputs for the GRC team

-
Own the vulnerability management lifecycle: scanning coverage, risk-based prioritization, remediation tracking, and SLA enforcement

-
Own the purple team and control validation program, confirming that deployed controls operate as intended and that detection capabilities fire correctly against known attack techniques

-
Drive threat modeling across the engineering function, identifying attack paths before they are exploited and feeding findings into remediation prioritization

AppSec, cloud, and AI security

-
Oversee the AppSec function: secure SDLC, code review gates, SAST/DAST tooling, and security collaboration with the Product and Engineering teams

-
Own cloud security posture management: CSPM, cloud workload protection, cloud IAM governance, and cloud-native security architecture

-
Set the team-wide AI security posture, overseeing AI security controls across all engineering lanes, including model security, prompt injection testing, and AI tool access governance in partnership with cyber leadership

MDR, automation, and tooling modernization

-
Lead the ongoing maturation of the MDR deployment, expanding coverage, improving response fidelity, and integrating MDR outputs with internal SIEM, IAM, and compliance evidence workflows

-
Champion security automation across the team, reducing manual toil in detection, response, vulnerability tracking, and reporting through SOAR, scripting, and platform integrations

-
Evaluate emerging security technologies and make build/buy/partner recommendations to the CISO with clear business and risk rationale

Team leadership and CISO partnership

-
Lead, develop, and performance-manage a lean engineering team

← All remote jobs

Get remote jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you