Jobgether
Director of Security Operations
- Location
- US
- Arrangement
- Remote
- Employment type
- Full-time
- Level
- Director
- Posted
- 28 September 2026 (2 days ago)
Checked 2 days agoApplications go to the employer, never to RoleSprint
About this role
Accountabilities • Lead the daily operations of the Security Operations Center (SOC), establishing effective processes, priorities, monitoring strategies, and operational standards.
• Oversee incident response and threat management activities, ensuring security incidents are identified, contained, investigated, and resolved effectively.
• Develop and evolve security monitoring, threat intelligence, and detection capabilities to improve the organization's ability to identify emerging threats.
• Lead vulnerability management efforts and help prioritize remediation based on business and security risk.
• Develop, implement, and maintain security policies, procedures, and operational controls aligned with organizational requirements.
• Manage security risk by balancing immediate operational needs with longer-term strategies that strengthen the organization's security posture.
• Anticipate developments in AI and AIOps and assess opportunities to improve automation, log ingestion, monitoring, and incident response while maintaining security quality.
• Build, manage, and develop a high-performing security operations team through effective hiring, coaching, feedback, goal-setting, and performance management.
• Establish clear and ambitious objectives, remove roadblocks, and ensure the team consistently delivers against its priorities.
• Build strong relationships with stakeholders across technology, operations, compliance, and other business functions to increase the effectiveness and reach of security initiatives.
• Partner with organizational leaders to strengthen the processes and systems protecting sensitive information, patients, employees, and business operations.
• Support compliance and risk-management activities involving requirements and frameworks such as HIPAA, GDPR, PCI DSS, NIST, ISO 27001, and CIS Controls.
Requirements
• Bachelor’s degree in Computer Science, Information Security, or a related discipline; a master’s degree is preferred.
• At least 10 years of professional experience in security operations, including a minimum of 5 years in a leadership or management capacity.
• Proven experience managing a Security Operations Center and leading incident response programs.
• Strong technical knowledge of security technologies such as SIEM, IDS/IPS, EDR, firewalls, and vulnerability management platforms.
• Experience working with regulatory and compliance requirements, including HIPAA, GDPR, and PCI DSS.
• Strong understanding of recognized security frameworks and standards, including NIST, ISO 27001, and CIS Controls.
• Excellent analytical, problem-solving, and risk-management capabilities, with a proactive and forward-looking approach.
• Strong leadership and people-development skills, including the ability to provide clear, timely, and actionable feedback.
• Excellent written, verbal, and interpersonal communication skills, with the ability to influence stakeholders across functions and levels.
• Ability to manage multiple priorities, navigate high-pressure situations, and make sound decisions in complex or ambiguous environments.
• Demonstrated ability to collaborate effectively across teams and translate security priorities into meaningful business outcomes.
• Interest in emerging security technologies, automation, AI, and AIOps, with an ability to identify practical opportunities for improving security operations.
Benefits
• Fully remote work environment within the United States.
• Flexible work schedules for eligible roles.
• Health, dental, and vision insurance with the employer covering up to 80% of premiums for employees, dependents, and domestic partners.
• 21 days of paid time off during the first year.
• 11 paid holidays and two paid volunteer days.
• 12 weeks of paid parental leave for all new parents.
• Six-week paid sabbatical after six years of service.
• 401(k) plan with up to a 4% employer match.
• Stock options.
• Educational assistance and clinical employee reimbursement programs.
• Opportunities for professional development in a collaborative, innovation-focused environment.
• A remote-first culture emphasizing work-life flexibility, inclusion, learning, and meaningful impact.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Work location
- US
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 28 September 2026, last checked 2 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.