
Director, Security Engineering – Operations
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Direct, manage, and lead the security engineering and security operations team members; oversee hiring, onboarding, performance evaluations, and career development plans aligned with Payscale’s Information Security Career Ladder.
• Establish strategy and quarterly/annual objectives for both functions, translating them into a prioritized, measurable roadmap; conduct regular 1:1s and team meetings to foster a high-performance, feedback-rich culture.
• Mentor engineers and analysts across all career stages, providing task-oriented directives, technical guidance, and constructive feedback focused on growth.
• Manage the on-call rotation and after-hours escalation path for both functions, ensuring availability for time-sensitive detection and response activities.
• Act as a working leader — remaining actively involved in engineering, architecture, and incident response instead of solely leading through delegation.
• Take ownership of the design, implementation, and continuous enhancement of security controls across corporate, cloud, and hosting environments.
• Develop and maintain security automation and integrations — including SOAR, detection-as-code, and infrastructure-as-code guardrails — to scale coverage without increasing headcount.
• Engineer and manage the security tooling stack (EDR/XDR, SIEM, identity protection, DLP/CASB, vulnerability scanning), ensuring platforms are well-integrated and comply with architectural standards.
• Collaborate with Engineering and Infrastructure to incorporate “secure by design” principles into CI/CD, cloud architecture, and product development.
• Promote the adoption of a zero-trust approach across identity, endpoint, network, and application layers.
• Lead security engineering initiatives for enterprise AI and agentic tooling adoption, creating controls and guardrails for safe internal usage.
• Enhance the threat detection and incident response capabilities: detection engineering, playbook creation, tabletop exercises, and ongoing improvement of MTTA/MTTR metrics.
• Oversee incident response events as the appointed incident manager for significant or multi-team incidents, managing the incident command from start to finish.
• Manage the MDR relationship, ensuring the provider meets SLAs, coverage, and response expectations.
• Extend detection and response capabilities to secure enterprise AI and agentic tooling adoption.
• Supervise the vulnerability and exposure management function across all corporate and hosting environments, coordinating cross-functionally on mitigation and remediation with defined SLAs.
• Enhance security monitoring, visibility, and coverage using existing platforms and open-source tools.
• Oversee the security engineering and operations aspect of the Information Security program roadmap, delivering operational metrics, risk posture data, and capacity analysis.
• Establish and regularly report security KPIs to technology and executive leadership.
• Collaborate with the GRC team on ISO 27001 and SOC 2 evidence, control effectiveness, and audit readiness related to security engineering and operations.
• Lead technical assessments of emerging security vendors and technologies; provide recommendations for buy/build/partner strategies to technology management.
• Represent security engineering and operations in cross-functional product, engineering, and infrastructure initiatives, ensuring security requirements are integrated by design.
• Over 10 years of experience in information security, including a minimum of 4 years in a leadership or management role within security engineering and/or security operations functions.
• Demonstrated success in people management: direct reports, performance cycles, and team development in a security context.
• Expert-level, hands-on expertise in both security engineering (controls design, automation, tooling integration) and security operations (detection, incident response) — capable of functioning as architect, engineer, incident handler, lead, and manager.
• Experience with the CrowdStrike Falcon platform (EDR, Identity Protection, Data Protection, AIDR, ZTA, Exposure Management) and SIEM/SOAR orchestration.
• Proven experience managing or owning an MDR or MSSP vendor relationship.
• Strong foundational knowledge in cloud security (preferably AWS), endpoint security, identity and access management, and zero-trust architecture.
• Extensive experience in vulnerability and exposure management as well as mitigation/remediation strategies.
• Proficiency in scripting and automation using PowerShell, Python, or Bash; comfortable with detection-as-code and infrastructure-as-code methodologies.
• Familiarity with the MITRE ATT&CK framework and the ability to correlate operational data to TTPs for structured threat analysis.
• Experience developing operational, engineering, and vulnerability metrics and management reporting, with a focus on continuous improvement through a regular reporting schedule.
• Knowledge of zero-trust networks and platforms such as Cloudflare, Zscaler, or AppGate.
• Experience with Data Loss Prevention and CASB architectures and tools such as Forcepoint, Netskope, or Zscaler.
• Familiarity with SOAR and automation platforms, including Tines, n8n, or Ansible.
• Flexible paid time off, allowing you to rest, relax, and recharge away from work.
• 14 Paid Company Holidays, including 2 floating holidays (your choice!).
• A comprehensive benefits package including medical, dental, life, vision, disability, and life insurance fully covered by Payscale.
• Unlimited infertility coverage benefits through our medical plans.
• Additional supplemental health benefits available for you and your family.
• 401(k) retirement plan with an immediate, fully vested company match.
• 16 weeks of paid parental leave for both birthing and non-birthing parents.
• Health Savings Account (HSA) options with company contributions each pay period.
• Flexible Spending Account (FSA) options for pre-tax employee contributions.
• Annual remote work stipend to be utilized for wellness or home office equipment.
RealTime eClinical Solutions
GitLab
Asymmetric
Get handpicked remote jobs straight to your inbox weekly.