Director, Cybersecurity Operations Center

Delek US

Brentwood (TN)

On-site

USD 130,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

401(k) match
Medical benefits starting day one

Job summary

Delek US Holdings seeks a senior leader to head Security Operations, directing the SOC, 24x7 monitoring, detection, triage, and incident response across IT/OT, cloud, and networks.

You will lead cross-functional teams, coordinate with providers and vendors, and drive improvements in monitoring use cases, playbooks, and incident readiness. Strong governance and executive briefing skills are essential.

Qualifications

  • Proven experience serving as incident commander for complex cyber incidents across IT and OT.
  • Experience leading SOC/MDR/incident response with direct accountability.
  • Ten or more years in security operations, monitoring and detection, threat hunting, or cyber defense.
  • Familiarity with NIST, MITRE ATT&CK, and ISA/IEC-62443 frameworks.
  • Cyber security certifications such as CISSP or GSEC preferred.

Responsibilities

  • Lead 24x7x365 SOC monitoring, detection, triage, investigation, escalation, and response.
  • Coordinate with internal teams, MSPs, incident response partners, and vendors.
  • Develop and maintain the SOC operating model, alert intake, and escalation processes.
  • Provide metrics and artifacts for audits and governance reviews.
  • Brief executives on current threats, incidents, and readiness.

Skills

Incident command
Executive coordination
Strategic planning
Team leadership
Cross-functional collaboration

Education

Bachelor's Degree
Equivalent education/experience

Tools

SIEM
SOAR
EDR/XDR
NDR
Forensics
Threat intelligence

Job description

Are you looking for a career in a dynamic and innovative company that values versatility, growth, and teamwork? Look no further than Delek US Holdings!

What is Delek? What do we do?

We are a boutique-sized diversified downstream energy company with a range of assets, including petroleum refining and logistics.

  • Our refineries in Texas, Arkansas, and Louisiana have a combined crude capacity of 302,000 barrels per day
  • Our logistics business currently owns and operates 720 miles of crude and product pipelines, a 600-mile crude oil gathering system, and storage tanks and terminals.
Delek Benefits

We offer fantastic benefits that include up to a 10% match on 401K on your hire start, with a vesting timeline of only one year, along with medical benefits that start on day one with a 30% premium rebate annually! We value your well-being and all employees now have access to the Calm app for FREE, which is used for meditation, stress management, and better sleep. Through our performance management program, you can earn additional annual incentives as you set and achieve goals. Our pay for performance culture motivates our employees to improve Delek’s year-over-year company, business unit, and individual results. With some of the highest bonus payouts in recent years, we know that our success is due to our talented and dedicated team. We are looking for individuals like you to help us continue this momentum and bring new ideas to the table. At Delek, you will have the opportunity to make an impact and grow your career in a supportive and innovative environment.

Job Summary

Leads Security Operations with primary responsibility for running the Security Operations Center (SOC), directing 24x7x365 monitoring, detection, triage, investigation, escalation, and response activities across Information Technology (IT), Operational Technology (OT), cloud, identity, network, endpoint, and third-party environments. Serves as a decisive incident commander during cyber security events by rapidly assessing severity, establishing priorities, assigning ownership, coordinating cross-functional response teams, briefing executive leadership, and driving incidents through containment, eradication, recovery, and post-incident improvement. Ensures that cyber security monitoring, detection, response, incident management, threat intelligence, threat hunting, and SOC processes are aligned with IS standards, cyber security standards, and overall cyber risk management objectives. Identifies cyber threats, suspicious activity, security incidents, and operational exposures; determines the scope, severity, and business impact of cyber events; and coordinates procedures to contain incidents, restore normal operations, and improve future detection and response capabilities. Develops techniques and procedures for conducting cyber security monitoring, alert triage, incident investigation, threat analysis, threat hunting, digital evidence collection, cyber readiness exercises, and post-incident reviews. Leads investigation and resolution of cyber security incidents such as intrusions, malware activity, unauthorized access, fraud, attacks, data loss events, or leaks.

Education And Experience
  • 4 year / Bachelor's Degree (Required)
  • In lieu of the above education requirements, an equivalent combination of education and experience may be considered.
  • Four (4) or more years management experience (Required)
  • Four (4) or more years experience leading a SOC, MDR function, incident response team, or cyber defense analysts with direct accountability for monitoring, detection, escalation, incident command, and response execution (Required)
  • Ten (10) or more years experience of relevant related field of Security Operations, Monitoring & Detection, Incident Response, Threat Intelligence, Threat Hunting, Digital Forensics, or Cyber Defense (Required)
  • Preferred Certifications/Licensures: (Cyber security related certifications such as CISSP, GSEC, etc)
Job Requirements
  • Proven experience serving as incident commander for complex cyber incidents across IT and OT, including executive coordination, business impact assessment, response decision-making, regulatory reporting, and post-incident corrective action
  • Skilled in using SIEM, SOAR, EDR/XDR, NDR, forensic, threat intelligence, and security monitoring tools, with a strong grasp of frameworks like NIST, MITRE ATT&CK, and ISA/IEC-62443
  • Strong organizational skills and ability to set priorities and handle multiple projects concurrently
  • Knowledge of cyber threat and/or intelligence analysis
  • Knowledge of cyber incident response, threat hunting, detection engineering, malware investigation, and digital forensics practices
  • Solid understanding of cyber security and ability to analyze incident reporting, investigation results, response actions, and follow-up with reporting sites
  • Strong knowledge of incident management, problem management and change management best practices
  • Lead operational engagements with internal teams, managed security providers, incident response partners, and technology vendors to support security monitoring, threat detection, and cyber response services
  • Program Management: Partner with PMO team to oversee portfolio of cyber security operational services and pipeline of projects/tasks to create, evolve, and improve monitoring, detection, and response capabilities
  • Responsible for developing, maintaining, and continuously improving the Security Operations operating model, including SOC coverage, alert intake, triage, escalation, investigation, response coordination, performance measures, and integration.
  • Ensure monitoring services are being fulfilled 24x7x365
  • Provide direct leadership, oversight, direction, scheduling, quality control, and performance management for SOC activities, analysts, service providers, and escalation processes
  • Establish and enforce incident command structure, escalation criteria, communication cadence, decision logs, action tracking, and after-action review practices for cyber security events
  • Perform review and validation of all deliverables for SOC, Incident Response, Threat Intelligence, Threat Hunting, Detection Engineering, and other assigned activities
  • Develop policies, instructions, standards, and procedures around security operations functions
  • Provide Metrics and Artifacts supporting audit activities
  • Brief executives about current cyber threats, incidents, operational readiness, and pertinent information
  • Ensure timely and accurate reporting to all relevant stakeholders (Internal & External)
  • Responsible for overall use of resources and initiation of corrective action where required for Security Operations Center activities
  • Perform threat management, identify threat vectors, monitor relevant threat actors, and develop use cases for security monitoring
  • Develop, tune, validate, and maintain security monitoring use cases, detection content, alert logic, response workflows, and escalation procedures
  • Lead threat hunting activities to identify indicators of compromise, anomalous activity, and previously undetected threats
  • Translate cyber threat intelligence into actionable monitoring, detection, hunting, and response procedures
  • Coordinate with Cybersecurity Architecture, Infrastructure, Applications, Governance, Risk & Compliance, and business teams to ensure effective operational response to identified threats, vulnerabilities, and incidents
  • Conduct cyber readiness exercises, tabletop exercises, and incident response simulations to validate operational preparedness
  • While this job description aims to provide a comprehensive overview of the role, it may not detail every task or responsibility required.
Core Competencies
  • CHANGE AGILITY (LEVEL 4 LEADING) Identifies, initiates, and adapts to organizational changes that foster enhanced effectiveness, efficiency, safety, and ultimately business results.
  • COLLABORATION (LEVEL 4 LEADING) Sees connection points across the organization and partners effectively with others to achieve common goals.
  • DECISION MAKING (LEVEL 4 LEADING) Selects a course of action to reduce risk and uncertainty and create optimal outcomes.
  • DRIVE FOR RESULTS (LEVEL 4 LEADING) Drives to achieve challenging performance objectives.
  • TEAM BUILDING (LEVEL 4 LEADING) Builds trust, fosters openness, and provides support. As the manager of a team, selects and motivates a strong team.

We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or national origin, disability status, protected veteran status, or any other characteristic protected by law. Equal Opportunity Employer/Disabled/Veterans.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, Cyber Defense & SOC Operations
Director, Cyber Defense & SOC Operations

Delek US • Brentwood (TN)

On-site
USD 130,000 - 190,000
401(k) match
Medical benefits starting day one
Sr Manager, Enterprise Operational Intelligence
Sr Manager, Enterprise Operational Intelligence

Delek US • Brentwood (TN)

On-site
USD 150,000 - 210,000
401K match up to 10%
Medical benefits from day one with 30%
Calm app access
Sr Business Operations Associate
Sr Business Operations Associate

Delek US Holdings • Brentwood (TN)

On-site
USD 95,000 - 120,000
401K match
Medical benefits
Calm app access
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

On-site
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Cybersecurity Operations Director
Cybersecurity Operations Director

Pearl Companies • United States

Remote
USD 130,000 - 160,000
Cybersecurity Analyst
Cybersecurity Analyst

usadebuskexternalcareersite • Houston (TX)

On-site
USD 72,000 - 100,000
Security Operations Lead
Security Operations Lead

Legends Global • Frisco (TX)

On-site
USD 120,000 - 150,000
Medical insurance
Dental and Vision insurance
Life and Disability insurance
+2
Lead Cyber Security Operations Center (CSOC) Analyst - USDS
Lead Cyber Security Operations Center (CSOC) Analyst - USDS

TikTok • Washington

On-site
USD 150,000 - 180,000
Medical insurance
401(k) plan
Paid parental leave
+1
Manager / Sr. Manager, SecOps & Cyber Defense
Manager / Sr. Manager, SecOps & Cyber Defense

Bullish, Inc. • New York (NY)

On-site
USD 185,000 - 235,000
Cyber Operate Senior Manager- Detect and Respond
Cyber Operate Senior Manager- Detect and Respond

Deloitte France • United States

On-site
USD 163,000 - 322,000