
VP, Cybersecurity Operations – Engineering
Posted Sep 17

Posted Sep 17
This is a fully remote position, open to applicants in California, +5 more states.
• Oversee enterprise cybersecurity operations and engineering initiatives, including strategy formulation, risk governance, roadmap creation, budgeting, KPI reporting, and communication with executives.
• Contribute to the development of cybersecurity policies, standards, procedures, and control frameworks.
• Create governance forums, prepare steering committee materials, provide risk updates, and develop business cases for senior leadership.
• Collaborate with legal, compliance, privacy, internal audit, technology, and business stakeholders.
• Promote consistent security practices across corporate, cloud, application, and business environments.
• Convert threat assessments, control findings, and evaluation results into prioritized remediation strategies.
• Offer executive oversight for SOC/MSSP performance, alert monitoring, incident triage, escalation management, and operational readiness.
• Manage incident response planning, runbooks, tabletop exercises, and cross-functional coordination for responses.
• Supervise threat intelligence, threat detection, threat hunting, and vulnerability management functions.
• Ensure readiness to protect, detect, respond to, and recover from cyber incidents.
• Develop and monitor operational metrics and service-level indicators.
• Oversee cybersecurity technology and control measures across on-premises, cloud, endpoint, identity, and network domains.
• Collaborate with infrastructure, platform, and software engineering teams to integrate security into architecture and workflows.
• Support secure development lifecycle, software assurance, secure coding, and application security efforts.
• Guide the selection and optimization of SIEM, EDR, IDS/IPS, firewalls, vulnerability management, logging, monitoring, and protection technologies.
• Advocate for automation, orchestration, and simplification of processes.
• Lead cyber risk assessments across infrastructure, applications, vendors, business processes, and emerging technologies.
• Assist in enhancing compliance and control maturity for NIST, ISO 27001, PCI-DSS, SOC, SOX, GDPR, privacy, and other standards.
• Provide security leadership for vendor reviews, architectural assessments, significant initiatives, and transformation projects.
• Cultivate relationships with business and technology leaders to foster growth, resilience, and informed risk-taking.
• Champion security awareness, education, and cultural initiatives.
• Lead, mentor, and develop cybersecurity managers and team members.
• Promote accountability, collaboration, continuous improvement, and a service-oriented partnership.
• Mentor technical teams in incident response, operational excellence, architecture, and executive communication.
• Maintain the cyber risk register and oversee the risk governance process.
• Support procurement schedules, budgets, actuals, strategic documents, project portfolios, roadmaps, and materials for C-suite/IT leadership.
• Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.
• Over 12 years of progressive cybersecurity experience, including leadership of enterprise security programs in complex, high-growth, or globally distributed organizations.
• More than 7 years of leadership experience managing managers, cross-functional teams, and/or external service providers across various cybersecurity domains.
• Proven track record in building or enhancing cybersecurity governance, program management, security operations, and security engineering capabilities.
• Strong familiarity with cybersecurity frameworks, regulatory requirements, and assurance practices, including NIST CSF, ISO 27001, PCI-DSS, SOC, SOX, data privacy, and related standards.
• Experience leading or overseeing incident response, threat intelligence, vulnerability management, detection engineering, and security monitoring initiatives.
• Solid technical understanding of cloud security, identity and access management, endpoint protection, network security, logging and monitoring, system hardening, and enterprise security architecture.
• Experience collaborating closely with software development and infrastructure teams to embed security into lifecycle management, architecture, and operational processes.
• Demonstrated ability to define metrics, communicate risks clearly, and present relevant security insights to operational, technical, and executive stakeholders.
• Strong business acumen with the capability to balance risk reduction, operational efficiency, and strategic enablement.
• Excellent written and verbal communication skills, with the ability to influence at all organizational levels.
• Must reside in one of the specified remote locations: New York, Connecticut, California, New Jersey, Texas, or Ohio.
• Short- and long-term incentives.
• Opportunities for growth and development.
• Health care benefits.
• Retirement plans.
• Vacation and additional paid time off.
• Other offerings.
• Reasonable accommodations for qualified individuals with disabilities.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.