Director, Security Engineering & Operations
About Payscale
Payscale is the pioneer of compensation intelligence, helping organizations make smarter pay decisions that drive business performance. For more than 20 years, Payscale has combined trusted market data with AI-powered technology to deliver actionable insights that turn pay from a cost into a catalyst for growth. The Payscale Intelligence Cloud portfolio of solutions—Ascent, JobNav, and Paycycle—empower top companies and businesses like Cintas, Leidos, Chipotle, Ohio State University, and TJX Companies. Create confidence in your compensation. Payscale.
Job Summary
The Director, Security Engineering & Operations directs, manages, and leads Payscale’s Security Engineering and Security Operations functions. This is a hands-on leadership role: the Director sets strategy and manages the team while remaining directly engaged in architecture, tooling, automation, and incident command. Responsibilities span the design and hardening of security controls, threat detection and incident response, vulnerability and exposure management, endpoint and identity protection, and security automation across Payscale’s corporate, cloud, and hosting environments. The Director owns Payscale’s MDR relationship and is accountable for the maturity, performance, and roadmap of both functions. This role reports to the CISO, VP - Cybersecurity & Enterprise Technology.
What You'll Do
Led, managed, and led the security engineering and security operations team members; owned hiring, onboarding, performance reviews, and career development plans aligned to Payscale’s Information Security Career Ladder
Set strategy and quarterly/annual objectives for both functions and translated them into a prioritized, measurable roadmap; held regular 1:1s and team connects to maintain a high-performance, feedback-rich culture
Mentor engineers and analysts at all career levels, providing task-based directives, technical coaching, and growth-oriented feedback; owned the on-call rotation and after-hours escalation path across both functions, ensuring coverage for time-sensitive detection and response
Served as a working leader—remaining hands-on in engineering, architecture, and incident response rather than leading solely through delegation; Security Engineering
Own the design, implementation, and continuous hardening of security controls across corporate, cloud, and hosting environments; Engineer and operate the security tooling stack (EDR/XDR, SIEM, identity protection, DLP/CASB, vulnerability scanning), ensuring platforms were well-integrated and met architectural standards
Partnered with Engineering and Infrastructure to embed “secure by design” into CI/CD, cloud architecture, and product development; Lead security engineering for enterprise AI and agentic tooling adoption, building controls and guardrails for safe internal use
Drive adoption of a zero-trust methodology across identity, endpoint, network, and application layers; Vulnerability & Exposure Management
Own the vulnerability and exposure management function across all corporate and hosting environments, coordinating cross-functionally on mitigation and remediation with clear SLAs; Expand security monitoring, visibility, and coverage using existing platforms and open-source tooling
Program, Metrics & Stakeholder Engagement; Own the security engineering and operations portion of the Information Security program roadmap, delivering operational metrics, risk-posture data, and capacity analysis; Establish and report security KPIs to technology and executive leadership on a regular cadence; Collaborate with the GRC team on ISO 27001 and SOC 2 evidence, control effectiveness, and audit readiness as it relates to security engineering and operations; Lead technical evaluations of emerging security vendors and technologies; provide buy/build/partner recommendations to technology management; Represent security engineering and operations in cross-functional product, engineering, and infrastructure initiatives, ensuring security requirements are incorporated by design
What We're Looking For
10+ years in information security, including 4+ years in a lead or management role across security engineering and/or security operations functions
Proven people-management track record: direct reports, performance cycles, and team development in a security context
Expert, hands-on knowledge of both security engineering (controls design, automation, tooling integration) and security operations (detection, incident response) — capable of acting as architect, engineer, incident handler, lead, and manager
Experience with the CrowdStrike Falcon platform (EDR, Identity Protection, Data Protection, AIDR, ZTA, Exposure Management) and SIEM/SOAR orchestration
Demonstrated experience owning or managing an MDR or MSSP vendor relationship
Strong foundation in cloud security (AWS preferred), endpoint security, identity and access management, and zero-trust architecture
Strong experience in vulnerability and exposure management and mitigation/remediation strategies
Scripting and automation ability in PowerShell, Python, or Bash; comfortable with detection-as-code and infrastructure-as-code approaches
Experience with the MITRE ATT&CK framework and the ability to map operational data to TTPs for structured threat analysis
Experience building operational, engineering, and vulnerability metrics and management reporting, and driving improvement through a regular reporting cadence
Experience with zero-trust networks and platforms such as Cloudflare, Zscaler, or AppGate
Experience with Data Loss Prevention and CASB architectures and tooling such as Forcepoint, Netskope, or Zscaler
Familiarity with SOAR and automation platforms such as Tines, n8n, or Ansible
Certifications such as CISSP or CISM
Nice to Have: Experience in a remote-first SaaS and/or PE-backed environment
Location
Payscale has an employee-centric remote-first model that provides you the flexibility to do your best work in a space that supports you, while also finding time to collaborate in person for the moments that matter. In our remote-first model, employees can work from the location that works best for them. We do not have centralized corporate offices. Employees can choose to work from home, in company-paid co-working spaces, or any combination of the two that best suits their unique needs. If you work from home, we recommend ensuring that you can meet the following technology, equipment and workspace requirements: High-Speed Internet - A stable broadband or fiber connection (satellite is highly discouraged) with a minimum speed of 100 Mbps in a dedicated workspace that has a reliable Wi-Fi signal. Device for Multifactor Authentication (MFA/2FA) - smartphone, tablet, etc.
Benefits & Perks
All around awesome culture where together we strive to live our 5 values: Data informed decision making. Customer first. Always. Succeed together. Relentless about results. Obsessed with excellence. Lead the change. Shape the standard.
Monthly company All Hands meetings
Regular opportunities for executive leadership exposure through things like AMAs
Access to continued learning & development opportunities
Our commitment to a continuous feedback culture which allows us to drive performance and career growth
A growing network of Employee Resource Groups
Company sponsored volunteer hours
Annual remote work stipend to be used on wellness or home office equipment
Equal Opportunity Employer
We embrace equal employment opportunity. Payscale is committed to a policy of equal employment opportunity for all applicants and employees. It is our policy that employees will not be subjected to unlawful discrimination on the basis of race, color, religion, sex, age, national origin, or ancestry, physical or mental disability, veteran or military status, marital status, sexual orientation, political ideology, and any other basis protected by federal, state, or local laws. This policy applies to all terms and conditions of employment, including but not limited to: recruitment, hiring, transfers, promotions, training, discipline, termination, compensation and benefits, performance appraisals, education, and social and recreational programs.
Compensation Range
$182,720 - $274,080