Director, Security Operations

Everforth, Inc.

United States

Remote

USD 180,000 - 250,000

Full time

13 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Everforth ECS seeks a Director of Security Operations to lead SOC analysts, detection engineers, and cyber threat intelligence teams in a remote, senior leadership role. You will define security operations strategy, maintain service delivery across customer and enterprise environments, and coordinate incident response with executive and customer stakeholders.

The role requires extensive experience in security operations, incident response, and threat intelligence, with a track record of building

Qualifications

  • Senior leader responsible for security operations, incident response, and threat detection across multiple environments.

Responsibilities

  • Lead SOC analysts, detection engineers, red team operators, threat intelligence analysts, and exposure management analysts.
  • Define the security operations strategy, operating standards, service model, and capability roadmap.
  • Oversee day-to-day monitoring, alert triage, investigation, escalation, and response activities.
  • Coordinate major security incidents with executives, customers, and stakeholders.
  • Lead detection engineering, production of detections, tuning, and coverage assessment.
  • Integrate threat intelligence and threat hunting into SOC operations.
  • Develop playbooks, escalation criteria, and incident response processes.
  • Explore AI applications to accelerate triage, improve quality, and scale services.

Skills

SOC leadership
Incident response
Threat intelligence
Detection engineering
MITRE ATT&CK mapping
AI in security
SOAR platforms
Security operations
Customer engagement
Team mentorship

Tools

SIEM
EDR/XDR
SOAR

Job description

Everforth ECS is seeking a Director of Security Operations to work remotely.

At Everforth ECS, we solve complex cybersecurity and technology challenges for commercial, government, defense, and intelligence customers.

We are seeking a Director of Security Operations to lead the people, processes, and operational disciplines that support our managed cybersecurity services. This leader will be accountable for effective security monitoring, threat detection, investigation, incident response, and continuous improvement across customer and enterprise environments.

This is a senior operational leadership role that combines security operations strategy, people leadership, customer engagement, and hands-on oversight. The Director will lead SOC analysts and detection engineers and partner closely with Security Engineering, the Project Management Office, customer teams, and enterprise stakeholders to deliver consistent, high-quality security outcomes.

Responsibilities
  • Lead, develop, and mentor a high-performing team of SOC analysts, detection engineers, red team operators, cyber threat intelligence anlaysts, and exposure management analysts.
  • Define the security operations strategy, operating standards, service model, and capability roadmap.
  • Oversee day-to-day monitoring, alert triage, investigation, escalation, and response activities across customer and enterprise environments.
  • Serve as the senior operational leader during major security incidents, coordinating investigation, containment, recovery, and executive and customer communications.
  • Lead the detection engineering program, including detection development, validation, tuning, coverage assessment, and lifecycle management.
  • Integrate cyber threat intelligence and threat hunting into SOC operations to improve detection, investigative context, and proactive defense.
  • Establish clear standards for alert analysis, case documentation, escalation quality, quality assurance, and operational reporting.
  • Identify and implement practical applications of AI across security operations to accelerate triage and investigation, improve analytical quality, automate repeatable workflows, and enhance service scalability while maintaining appropriate human oversight.
  • Develop and maintain operating procedures, investigation playbooks, escalation criteria, and incident response processes.
  • Work directly with customers and enterprise stakeholders to understand priorities, communicate risk, explain operational decisions, and resolve service concerns.
  • Partner with Security Engineering and IT teams to ensure security platforms, telemetry, integrations, and automation reliably support SOC requirements.
  • Manage operational priorities, staffing, hiring, performance, professional development, on-call coverage, and service delivery risk.
  • Support solution development, operational proposals, service transitions, and strategic customer engagements.
  • 15+ years of experience in cybersecurity, security operations, incident response, detection engineering, threat intelligence, or a related discipline.
  • 5+ years of experience leading cybersecurity or security operations teams. Preference will be given to applicants who have led large SOC, MDR, or multi-customer security operations teams at the Director level or above.
  • Deep understanding of SOC operations, including monitoring, alert triage, investigation, escalation, incident response, threat hunting, and continuous improvement.
  • Demonstrated experience leading complex security incidents and coordinating technical, business, customer, and executive stakeholders through response and recovery.
  • Strong knowledge of detection engineering practices, including use-case development, detection validation, tuning, coverage analysis, and MITRE ATT&CK mapping.
  • Experience integrating cyber threat intelligence and adversary tradecraft into detection, hunting, investigation, and response activities.
  • Strong operational understanding of SIEM, EDR/XDR, identity, network, cloud, email, and other security telemetry used for detection and investigation.
  • Experience establishing SOC operating procedures, playbooks, escalation criteria, quality standards, and governance practices.
  • Experience defining and using security operations metrics to manage workload, service quality, detection effectiveness, response performance, and operational risk.
  • Proven ability to build, mentor, and lead high-performing security operations teams in demanding environments.
  • Strong ability to translate business, threat, and risk priorities into security operations priorities and execution plans.
  • Strong communication and customer-facing skills, with the ability to explain incidents, operational performance, and technical risk to analysts, technical leaders, executives, and customers.
  • Sound operational judgment, including the ability to make timely decisions under pressure, manage competing priorities, and balance risk, evidence, customer impact, and service commitments.
Desired Skills
  • Experience leading security operations within a managed security services, managed detection and response, enterprise SOC, or other multi-customer service environment.
  • Demonstrated success building, modernizing, or maturing a SOC while maintaining service continuity and operational performance.
  • Demonstrated understanding of how AI can be applied to security operations, including alert triage, investigation support, analytical quality assurance, knowledge management, reporting, and workflow acceleration.
  • Experience using SOAR platforms and operational automation to improve consistency, speed, and analyst effectiveness.
  • Experience operating security monitoring and incident response capabilities across public cloud and hybrid enterprise environments.
  • Experience establishing quality assurance, case review, and continuous improvement programs for security operations.
  • Experience managing service-level commitments, operational risk, and customer expectations in a managed services environment.
  • Experience managing relationships with security technology vendors, intelligence providers, and operational partners.
  • Demonstrated ability to lead teams successfully through organizational, process, or operational change.
  • CISSP, GCIH, GCIA, or comparable advanced cybersecurity certification preferred.

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

Meet the challenge. Make a difference with Everforth ECS!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, Security Operations
Director, Security Operations

ECS • Virginia (MN)

On-site
USD 180,000 - 250,000
Director, Security Operations
Director, Security Operations

ecsfederal • Virginia (MN)

Hybrid
USD 180,000 - 250,000
Senior Director, Security Operations — Remote
Senior Director, Security Operations — Remote

ecsfederal • Virginia (MN)

Hybrid
USD 180,000 - 250,000
Remote Director of Security Operations — Incident & Detection
Remote Director of Security Operations — Incident & Detection

Everforth, Inc. • United States

Remote
USD 180,000 - 250,000
Incident Response Lead
Incident Response Lead

ECS • Washington

On-site
USD 140,000 - 150,000
Remote Director, Security Operations & Incident Leadership
Remote Director, Security Operations & Incident Leadership

ECS • Virginia (MN)

On-site
USD 180,000 - 250,000
Cybersecurity Operations Manager
Cybersecurity Operations Manager

ECS • Washington

On-site
USD 155,000 - 165,000
Cyber Solution Area Lead
Cyber Solution Area Lead

Everforth ECS • Merrifield (VA)

On-site
USD 180,000 - 290,000
CISO
CISO

ECS • Sierra Vista (AZ)

On-site
USD 180,000 - 240,000
Cyber Solution Area Lead
Cyber Solution Area Lead

ECS • Fairfax (VA)

On-site
USD 275,000 - 350,000
Executive leadership exposure