Director of Cybersecurity Operations
AEG · Los Angeles, CA · 2 days ago
On-siteInformation Technology$225k–$240k/yrFull-time
About the role
The Director of Cybersecurity Operations leads the organization's global cyber operations strategy, strengthening operational resilience and maturing enterprise defense capabilities across corporate, cloud, venue, and operational technology environments.
Responsibilities
- Lead the strategy, design, and optimization of Global Security Operations Center (GSOC) and Cyber Fusion Center capabilities.
- Lead threat detection, monitoring, threat hunting, incident triage, and response operations across enterprise, cloud, venue, and operational technology environments.
- Develop detection engineering capabilities, operational playbooks, escalation procedures, and automation workflows to improve response effectiveness.
- Oversee implementation and optimization of cybersecurity technologies including SIEM, SOAR, EDR/XDR, threat intelligence, and security analytics platforms.
- Manage relationships with security vendors and coordinate globally distributed cyber operations activities.
- Continuously assess and improve operational maturity aligned to industry frameworks, emerging threats, and business priorities.
- Lead enterprise incident response operations, ensuring rapid identification, containment, eradication, recovery, and post-incident remediation activities.
- Direct the development, testing, and continuous improvement of incident response plans, operational playbooks, tabletop exercises, and cyber crisis simulations.
- Cook up cross-functional response efforts involving Infrastructure, Legal, HR, Compliance, Privacy, and business stakeholders during cybersecurity incidents.
- Conduct post-incident reviews and drive lessons learned initiatives to improve operational resilience and reduce future risk exposure.
- Support cyber resilience, business continuity, and disaster recovery initiatives related to cybersecurity operations.
- Lead AEG’s Continuous Threat Exposure Management (CTEM) and enterprise vulnerability management programs across cloud, network, endpoint, application, identity, and operational technology environments.
- Lead identification, prioritization, validation, and remediation of cyber exposures based on threat intelligence, exploitability, and business risk.
- Drive exposure reduction initiatives leveraging threat intelligence, attack surface management, identity security, and security validation activities.
- Partner with Infrastructure, Engineering, Application Development, Cloud Operations, and Compliance teams to coordinate timely remediation and risk reduction initiatives.
- Support identity and access governance initiatives including privileged access management, least-privilege controls, multi-factor authentication, and identity-related risk reduction strategies.
- Oversee vulnerability scanning, attack surface visibility, remediation governance, exposure tracking, and executive-level reporting processes.
- Develop operational metrics, KPIs, and KRIs to measure exposure reduction effectiveness, remediation performance, and overall cyber risk posture.
- Enhance CTEM processes, tooling, automation, and reporting capabilities aligned with evolving threats and business priorities.
- Lead enterprise Data Loss Prevention (DLP) strategies and data protection initiatives to safeguard sensitive corporate, customer, financial, and regulated data.
- Oversee implementation and monitoring of controls designed to prevent unauthorized access, misuse, disclosure, or exfiltration of sensitive information.
- Conduct regular assessments, audits, and effectiveness reviews of DLP controls and data protection capabilities.
- Partner with Legal, Privacy, Compliance, and business stakeholders to align data protection initiatives with regulatory and organizational requirements.
- Direct internal and external penetration testing initiatives, red team exercises, and security validation assessments.
- Coordinate remediation activities and track resolution of identified vulnerabilities and security gaps.
- Evaluate effectiveness of security controls through continuous testing and adversary simulation activities.
- Provide strategic recommendations for security architecture and operational improvements based on assessment findings.
- Partner with the CISO and senior leadership to define and execute the cybersecurity operations strategy, roadmap, and maturity initiatives.
- Drive cyber risk reduction initiatives through CTEM, threat-informed defense, and operational maturity programs.
- Develop and communicate meaningful cybersecurity metrics, KPIs, and Key Risk Indicators (KRIs) to measure operational effectiveness, threat exposure, and program maturity.
- Deliver executive-level reporting and briefings on cybersecurity posture, operational resilience, incident trends, emerging threats, and strategic initiatives.
- Translate complex cybersecurity risks and operational issues into clear business-focused insights and recommendations for executive stakeholders.
- Support budget planning, vendor strategy, technology evaluations, and long-term operational planning initiatives.
- Lead, mentor, and develop high-performing cybersecurity operations teams in a complex, matrixed, and globally distributed environment.
- Foster a culture of accountability, collaboration, innovation, operational excellence, and continuous improvement.
- Support team growth through talent development, succession planning, process improvement, and operational standardization.
- Provide leadership during high-pressure cybersecurity incidents and operational escalations.
- Partner with Information Security Engineering, Infrastructure, Compliance, Legal, HR, Privacy, Audit, and business leadership teams to align cybersecurity initiatives with organizational objectives.
- Collaborate with external partners, vendors, industry groups, and law enforcement organizations as appropriate.
- Communicate effectively with technical and non-technical stakeholders to promote cybersecurity awareness, operational alignment, and informed risk management decisions.
- Embed cybersecurity operational requirements and best practices into enterprise technology transformation initiatives.
Qualifications
- BA/BS Degree (4-year) (Advanced Degree Preferred) in Information Technology, Computer Science, Cybersecurity or a related field.
- 5+ years experience building, scaling, or transforming SOCs, Fusion Centers, or global cyber defense operations.
- Experience leading Security Operations, Incident Response, CTEM/Vulnerability Management, IAM, DLP, Penetration Testing, and Threat Detection programs.
- Strong knowledge of SIEM, SOAR, EDR/XDR, MDR, IAM/PAM, vulnerability management, and cloud security technologies.
- Experience with security automation, detection engineering, threat hunting, and operational process improvement.
- Experience with cloud security operations across AWS, Azure, and/or Google Cloud environments.
- Experience developing cybersecurity metrics, KPIs, KRIs, dashboards, and executive reporting.
- Strong understanding of threat intelligence, MITRE ATT&CK, cyber risk management, and exposure reduction strategies.
- Experience managing MSSPs, MDR providers, cybersecurity vendors, and third-party security partners.
- Strong executive communication and stakeholder management skills with the ability to translate cybersecurity risks into business impact.
- Experience supporting regulatory and compliance frameworks including NIST, ISO 27001, PCI-DSS, SOX, GDPR, and privacy requirements.
- Experience leading cross-functional initiatives within large, matrixed, and geographically distributed organizations.
- 10 years progressive experience in cybersecurity operations, incident response, threat detection, vulnerability management, and enterprise cyber defense within complex enterprise environments.
- Strong written and verbal communication skills with the ability to communicate technical risks to executive and non-technical audiences.
- Deep knowledge of Security Operations, Incident Response, Threat Detection and Response, CTEM/Vulnerability Management, IAM, DLP, and Cyber Fusion Center operations.
- Proven ability to build, mature, and lead cybersecurity operations programs and high-performing teams.
- Strong understanding of modern cyber threats, attack methodologies, threat intelligence, and risk management practices.
- Knowledge of threat hunting, detection engineering, security automation, and incident response best practices.
- Strong understanding of CTEM, attack surface management, threat-informed defense, and exposure reduction strategies.
- Ability to develop cybersecurity metrics, KPIs, KRIs, dashboards, and executive-level reporting.
- Strong knowledge of cloud security principles, Zero Trust concepts, and hybrid enterprise security architectures.
- Ability to lead high-pressure incident response activities and make informed decisions during critical events.