Director of Security Operations

Cyber 429

Kansas

Hybrid

USD 140,000 - 175,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Cyber 429 in the Kansas City area is seeking a Director of Security Operations to own and scale our SOCs, lead a small senior team, and drive incident response for clients and student programs.

You will tune detections, own data pipelines, and mentor the next generation of defenders, balancing hands-on work with strategic leadership.

This role emphasizes teaching, strong automation skills, and the ability to operate across commercial and educational initiatives.

Qualifications

  • Minimum 5 years in security operations or incident response.
  • At least 2 years leading or mentoring analysts.
  • Hands-on today with incident handling and detections tuning.
  • Direct experience owning incidents end to end.
  • Experience with SIEM and an EDR platform, especially Defender & Sentinel.
  • Scripting or automation ability (Python/PowerShell/SOAR).
  • Clear written and verbal communication with clients.
  • US work eligibility; security clearance if needed.

Responsibilities

  • Own the 429 SOC end to end, including runbooks and coverage.
  • Lead the student SOC and mentor learners.
  • Run incident response when events occur; develop IR playbooks.
  • Own data pipelines, logging, normalization, and SIEM/EDR integration.
  • Balance training with client-facing responsibilities.
  • Define standards and ensure on-call performance.

Skills

Incident response
Detection engineering
Mentoring analysts
Scripting automation
Communication skills
SOC leadership
Owner mindset

Tools

SIEM
EDR
Microsoft Defender
Microsoft Sentinel

Job description

Director of Security Operations
Cyber 429 · Kansas City

Company: Cyber 429 (cyber429.com)

Location: Kansas City metro area. Hybrid, with time on-site for SOC work and campus operations.

Reports to: Founder/CEO, working day-to-day with the COO.

Type: Full-time.

About us

Cyber 429 protects the organizations that get hit hardest and defend the worst. A lot of this industry runs on fear. Sell the scary headline, sell the shelfware, move on. We don’t work that way. We think security should be honest and within reach for the people who need it.

We’re a small, senior team, and we move like one. Beyond our commercial managed-security work, our CIPHER partnership and related higher-education initiatives are helping us stand up student-run SOCs that train the next generation of defenders on real environments. This is an early, senior leadership hire, and you’ll feel it.

What this job is

You run security operations. Our own managed-security operations for our clients and our student-SOC programs both sit under you. You’ll own the 429 SOC, lead the team that builds and runs our student SOCs, take point on incident response when things go sideways, and own the data and engineering that detection depends on.

This is a player/coach job, not a manager who sits above the work, because we are all rolling up our sleeves to build something that matters together. You’ll build the team and set the direction, but you’ll also be in the console tuning detections and working incidents alongside your analysts. In a SOC this size, the people doing the work won’t follow someone who can’t do it too.

You also own how well our student SOCs run. These are campus-based programs that will expand across Kansas, Missouri, and beyond, and you keep the program work and our commercial work cleanly separated where funding and compliance require it.

What you’ll own

The 429 SOC. This is yours end to end: monitoring, detection engineering, triage, escalation, on-call, and the quality of what your analysts produce. You write the runbooks and set the coverage model, and you answer for what clients actually experience.

The student SOC. You lead the team that builds and runs our student SOCs. That means setting how students can safely work in real environments, developing the people who coach and mentor them, and turning the whole thing into a pipeline that feeds our own team. The teaching and talent-development mindset isn’t a nice-to-have here. It’s a big chunk of the job, and you need to actually want it.

Incident response. When something’s burning, you’re the one running it, with our team of senior experts who pitch in when we need help: containment, investigation, and talking clients through it while it’s happening. You’ll also build the IR playbooks and readiness so the team can handle most of it without you having to be on every call.

Data and engineering. Detection is only as good as the data feeding it. You own the pipelines and tooling: log ingestion, normalization, SIEM and EDR integration, the plumbing across client and program environments. You should be able to build this yourself where it matters, and you’ll lean on our contracted architects where that’s the smarter call.

What the first year should look like

A few things we’d expect to be true twelve months in:

  • The 429 SOC runs on real, written standards for coverage, runbooks, detection quality, and on-call, and the founder is no longer in the loop on daily operations.
  • The student SOC exists and works: students safely contributing to live monitoring, a mentorship model that holds up, and new talent coming through it.
  • Incident response is faster and more consistent than it is today, with playbooks in place and clients kept through incidents we handled well.
  • Data integration has stopped being a bottleneck. Pipelines are reliable, detection inputs are clean, and there’s less manual grinding across environments.
What you need to have

These are the must-haves. If you don’t meet most of them, this probably isn’t the right role, and that’s okay. We’d rather be clear now than waste your time.

  • At least 5 years in security operations, incident response, or detection engineering, in a hands-on technical capacity. This is not a role you grow into from an adjacent field.
  • At least 2 years leading or formally mentoring analysts, whether as a team lead, shift lead, SOC manager, or the senior person others escalated to. You’ve been responsible for other people’s output, not just your own.
  • You are still hands-on today, not several years removed from the console. You can personally work an incident, write and tune detections, and reason through attacker behavior without leaning on your team to do it for you.
  • Direct experience owning incidents end to end: detection, containment, investigation, and communicating with stakeholders or clients while an incident is live. You can point to specific incidents you ran.
  • Working proficiency with a SIEM and an EDR platform (any major products), and specifically Microsoft Defender & Sentinel. You can build and tune detections, not just read the dashboards.
  • Practical detection and data-engineering experience: log ingestion, parsing and normalization, and integrating disparate sources into a usable pipeline. You have built or substantially rebuilt this kind of plumbing yourself.
  • Enough scripting or automation ability (for example Python, PowerShell, or SOAR playbooks) to automate toil and stand up integrations without waiting on someone else.
  • You can write and speak clearly enough to brief clients, produce written IR reports, and set standards a team will actually follow.
  • You must be eligible to work in the United States and able to obtain a US security clearance if needed.
Strongly preferred

Not required to apply, but these move you to the top of the stack:

  • At least one active certification such as CISSP, GCIH, GCIA, GCFA, or an equivalent hands-on credential.
  • MSP/MSSP or multi-tenant / shared-SOC experience, where you defended more than one client environment at once.
  • Detection-as-code or mature SOAR automation experience.
  • Cloud security depth (identity, logging, and detection in at least one major cloud).
  • Experience teaching, mentoring formally, or building in an academic or apprenticeship setting. The student SOC is central to this role, and this is a real differentiator.
  • Familiarity operating in a grant-funded or compliance-bound environment where program and commercial work must stay separated.
Who you are

Skills get you in the door. These are the things that make someone actually work out here:

  • You want to teach. Mentoring the student SOC is a big chunk of the job, so if developing early-career people isn’t something you enjoy, this isn’t the right seat.
  • You stay organized and follow through when things are chaotic. You close loops and hold the line on standards under pressure.
  • You act like an owner. You treat our problems as yours, move without waiting to be told, and care how this turns out beyond the paycheck. If the mission, protecting people this industry usually ignores, isn’t part of why you’d take this over a bigger-name job, we’re probably not the right fit.
  • Startup wiring: comfortable with ambiguity, low ego, willing to work hard, and reachable when a client or an incident needs you outside normal hours. Security doesn’t keep office hours and neither do we, within reason.
Compensation

Base salary in the range of $140,000 to $175,000, depending on experience, plus a team bonus tied to SOC performance, client retention, and program milestones. You’ll also have the opportunity for future profit-share and equity participation, real upside in what you help build, which we’ll walk through during the process. Benefits, PTO, and a professional development budget round it out. Our partnerships with universities also come with the potential for our employees to obtain low-cost or no-cost tuition remission for themselves and their dependents for undergraduate and/or advanced degrees.

Why take it

We want owners, not renters. This is the technical heart of Cyber 429. You’ll own how we defend real clients and lead the teams that build student SOCs training the next generation of defenders. You’ll operate at the center of a real business with a mission that matters. If we execute on what’s in front of us, this role grows into a VP of Security Operations or CISO-track position, and you’ll have earned it from the inside, with profit participation that means you share directly in what you built.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Director of Cyber Security
Director of Cyber Security

The Security Executive Council • Kansas City (MO)

On-site
USD 180,000 - 240,000
Unlimited PTO
401(k) match (4%)
Health, dental, & vision insurance
+4
Security Operations Lead
Security Operations Lead

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2
SOC Manager (Hands-On) - Remote (USA)
SOC Manager (Hands-On) - Remote (USA)

Echelon Risk + Cyber • Washington

On-site
USD 110,000 - 140,000
Health, dental, and vision insurance
401(k) with employer contribution
Flexible vacation policy
+1
SOC Manager
SOC Manager

RADICL Defense • Boulder (CO)

Hybrid
USD 170,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+3
SOC Manager with BS Degree
SOC Manager with BS Degree

Acumenz Consulting • United States

Remote
USD 120,000 - 150,000
SOC Manager
SOC Manager

RADICL • Colorado

Hybrid
USD 120,000 - 180,000
Health insurance
401(k) plan
Paid time off
+1
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000
Lead OT SOC Architect
Lead OT SOC Architect

Jacobs • Houston (TX)

On-site
USD 180,000 - 240,000
Senior SOC Security Engineer
Senior SOC Security Engineer

Unisys • United States

On-site
USD 110,000 - 150,000