Director, Security Operations

ECS Corporate Services

Fairfax (VA)

Remote

USD 180,000 - 250,000

Full time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Everforth ECS is seeking a Director of Security Operations to lead the people, processes, and operational disciplines that support our managed cybersecurity services for commercial, government, defense, and intelligence customers. This senior leader will oversee security monitoring, threat detection, investigation, incident response, and continuous improvement across customer and enterprise environments.

The Director will mentor SOC analysts and detection engineers, partner with Security

Qualifications

  • 15+ years of experience in cybersecurity, security operations, incident response, detection engineering, threat intelligence, or a related discipline.
  • 5+ years of experience leading cybersecurity or security operations teams.
  • Preference for applicants who have led large SOC, MDR, or multi-customer security operations teams at Director level or above.
  • Deep understanding of SOC operations: monitoring, alert triage, investigation, escalation, incident response, threat hunting, continuous improvement.
  • Proven ability to lead complex security incidents coordinating technical, business, customer, and executive stakeholders.
  • Strong knowledge of detection engineering, including use-case development, validation, tuning, and MITRE ATT&CK mapping.
  • Experience integrating cyber threat intelligence into detection, hunting, and response activities.
  • Strong operational understanding of SIEM, EDR/XDR, identity, network, cloud, and other telemetry for detection and investigation.

Responsibilities

  • Lead, develop, and mentor a high-performing team of SOC analysts, detection engineers, red team operators, cyber threat intelligence analysts, and exposure management analysts.
  • Define the security operations strategy, operating standards, service model, and capability roadmap.
  • Oversee day-to-day monitoring, alert triage, investigation, escalation, and response activities across customer and enterprise environments.
  • Serve as the senior operational leader during major security incidents, coordinating investigation, containment, recovery, and executive and customer communications.
  • Lead the detection engineering program, including development, validation, tuning, coverage assessment, and lifecycle management.
  • Integrate cyber threat intelligence and threat hunting into SOC operations to improve detection and context.
  • Establish standards for alert analysis, case documentation, escalation quality, QA, and operational reporting.
  • Identify and implement practical applications of AI across security operations to accelerate triage and investigation, and improve service scalability with human oversight.
  • Develop and maintain operating procedures, investigation playbooks, escalation criteria, and incident response processes.
  • Work with customers and enterprise stakeholders to understand priorities, communicate risk, and resolve service concerns.
  • Partner with Security Engineering and IT to ensure telemetry and automation support SOC requirements.
  • Manage priorities, staffing, hiring, performance, on-call coverage, and service delivery risk.
  • Support solution development, operational proposals, service transitions, and strategic customer engagements.

Skills

Security operations leadership
Threat detection
Incident response
Threat hunting
SOC analytics
Detection engineering
Executive communication
Risk management

Tools

SIEM
EDR/XDR
Threat intelligence platforms
Cloud security

Job description

Everforth ECS is seeking a Director of Security Operations to work remotely . At Everforth ECS, we solve complex cybersecurity and technology challenges for commercial, government, defense, and intelligence customers.

We are seeking a Director of Security Operations to lead the people, processes, and operational disciplines that support our managed cybersecurity services. This leader will be accountable for effective security monitoring, threat detection, investigation, incident response, and continuous improvement across customer and enterprise environments. This is a senior operational leadership role that combines security operations strategy, people leadership, customer engagement, and hands‑on oversight. The Director will lead SOC analysts and detection engineers and partner closely with Security Engineering, the Project Management Office, customer teams, and enterprise stakeholders to deliver consistent, high‑quality security outcomes.

Responsibilities
  • Lead, develop, and mentor a high-performing team of SOC analysts, detection engineers, red team operators, cyber threat intelligence anl ysts, and exposure management analysts.
  • Define the security operations strategy, operating standards, service model, and capability roadmap.
  • Oversee day-to-day monitoring, alert triage, investigation, escalation, and response activities across customer and enterprise environments.
  • Serve as the senior operational leader during major security incidents, coordinating investigation, containment, recovery, and executive and customer communications.
  • Lead the detection engineering program, including detection development, validation, tuning, coverage assessment, and lifecycle management.
  • Integrate cyber threat intelligence and threat hunting into SOC operations to improve detection, investigative context, and proactive defense.
  • Establish clear standards for alert analysis, case documentation, escalation quality, quality assurance, and operational reporting.
  • Identify and implement practical applications of AI across security operations to accelerate triage and investigation, improve analytical quality, automate repeatable workflows, and enhance service scalability while maintaining appropriate human oversight.
  • Develop and maintain operating procedures, investigation playbooks, escalation criteria, and incident response processes.
  • Work directly with customers and enterprise stakeholders to understand priorities, communicate risk, explain operational decisions, and resolve service concerns.
  • Partner with Security Engineering and IT teams to ensure security platforms, telemetry, integrations, and automation reliably support SOC requirements.
  • Manage operational priorities, staffing, hiring, performance, professional development, on-call coverage, and service delivery risk.
  • Support solution development, operational proposals, service transitions, and strategic customer engagements.

Salary Range: $180,000-$250,000

General Description of Benefit
  • 15+ years of experience in cybersecurity, security operations, incident response, detection engineering, threat intelligence, or a related discipline.
  • 5+ years of experience leading cybersecurity or security operations teams.
  • Preference will be given to applicants who have led large SOC, MDR, or multi-customer security operations teams at the Director level or above.
  • Deep understanding of SOC operations, including monitoring, alert triage, investigation, escalation, incident response, threat hunting, and continuous improvement.
  • Demonstrated experience leading complex security incidents and coordinating technical, business, customer, and executive stakeholders through response and recovery.
  • Strong knowledge of detection engineering practices, including use-case development, detection validation, tuning, coverage analysis, and MITRE ATT&CK mapping.
  • Experience integrating cyber threat intelligence and adversary tradecraft into detection, hunting, investigation, and response activities.
  • Strong operational understanding of SIEM, EDR/XDR, identity, network, cloud, email, and other security telemetry used for detection and investigation.
  • Experience establishing SOC operating procedures, playbooks, escalation criteria, quality standards, and governance practices.
  • Experience defining and using security operations metrics to manage workload, service quality, detection effectiveness, response performance, and operational risk.
  • Proven ability to build, mentor, and lead high-performing security operations teams in demanding environments.
  • Strong ability to translate business, threat, and risk priorities into security operations priorities and execution plans.
  • Strong communication and customer-facing skills, with the ability to explain incidents, operational performance, and technical risk to analysts, technical leaders, executives, and customers.
  • Sound operational judgment, including the ability to make timely decisions under pressure, manage competing priorities, and balance risk, evidence, customer impact, and service commitments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, Security Operations
Director, Security Operations

ECS • Virginia (MN)

On-site
USD 180,000 - 250,000
Director, Security Operations
Director, Security Operations

Everforth, Inc. • United States

Remote
USD 180,000 - 250,000
Remote Director of Security Operations — Incident & Detection
Remote Director of Security Operations — Incident & Detection

Everforth, Inc. • United States

Remote
USD 180,000 - 250,000
Remote Director, Security Operations & Incident Leadership
Remote Director, Security Operations & Incident Leadership

ECS • Virginia (MN)

On-site
USD 180,000 - 250,000
Senior Director of Security Operations
Senior Director of Security Operations

Code Red Partners • United States

On-site
USD 180,000 - 280,000
Head of Security Operations & Threat Response
Head of Security Operations & Threat Response

ECS Corporate Services • Fairfax (VA)

Remote
USD 180,000 - 250,000
Cybersecurity Operations Director
Cybersecurity Operations Director

Pearl Companies • United States

Remote
USD 130,000 - 160,000
Manager
Manager

Torsap Thai Kitchen • Berkeley (CA)

On-site
USD 140,000 - 175,000
Health insurance
Dental insurance
Vision insurance
+4
Incident Response Lead
Incident Response Lead

ECS • Washington

On-site
USD 140,000 - 150,000
Senior Director, Cybersecurity Operations & Compliance
Senior Director, Cybersecurity Operations & Compliance

Ddn • Santa Clara (CA)

On-site
USD 150,000 - 210,000