Lead, Cybersecurity Architecture & Operations

Culligan Water

Rosemont (IL)

Hybrid

USD 140,000 - 180,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
Dental insurance
Vision insurance
401(k)

Job summary

Culligan Water seeks a seasoned Lead, Cybersecurity Architecture & Operations to anchor our global security program. You will own architecture, SSPM/DSPM operations, vulnerability management, and SOC activities across a multi-region environment.

This hybrid role based in Rosemont, IL reports to the Global CISO and balances strategic influence with hands-on technical work, maturing controls, audits, and incident response.

Qualifications

  • 6+ years of hands-on cybersecurity engineering, architecture, and/or security operations.
  • Deep, practitioner-level experience with SSPM and DSPM platforms (e.g., deploying, operating, and driving remediation at scale).
  • Proven ownership of an enterprise vulnerability management program, including risk-based prioritization and remediation governance.
  • Hands-on experience administering a SIEM and managing a SOC (MSSP/MDR relationships).
  • Strong knowledge of cloud security, IAM, and SaaS ecosystems.
  • Experience in a global, multi-region environment with distributed teams.
  • Excellent communication skills—briefing executives, writing standards, influencing engineers without direct authority.
  • Self-starter who drives initiatives end-to-end.

Responsibilities

  • Security architecture: Define and maintain enterprise security architecture and reference patterns across cloud, SaaS, network, endpoint, and identity domains.
  • SSPM: Deploy, operate, and tune SSPM; remediate SaaS misconfigurations and access sprawl globally.
  • DSPM: Lead DSPM implementation and operations; protect sensitive data and support governance.
  • Vulnerability management: End-to-end lifecycle ownership, risk-based prioritization, remediation SLAs.
  • SIEM: Administer and optimize SIEM, detection engineering, and incident response.
  • SOC operations: Run day-to-day SOC, oversee MSSP/MDR, and mature response playbooks.
  • Audit & compliance: Strengthen controls and evidence for SOX ITGC and audits.
  • Threat-informed defense: Track threats and translate into detections and priorities.
  • Global collaboration: Mentor teams across regions and drive security maturity.
  • Tooling & automation: Evaluate, select, and integrate security tooling; drive consolidation.

Skills

Security architecture
Vulnerability management
SDLC security
Executive briefing
Mentorship
Cloud security
IAM
SaaS ecosystems
Threat intel
Communication

Tools

SSPM platforms
DSPM platforms
SIEM tooling
SOAR platforms

Job description

Lead, Cybersecurity Architecture & Operations
  • Posted on July 7, 2026
Locations

Showing 1 location

Rosemont IL
9399 W Higgins Rd
Ste 1100
Rosemont, IL 60018, USA

Rosemont IL
9399 W Higgins Rd
Ste 1100
Rosemont, IL 60018, USA

  • Hybrid
  • Information Technology
  • Full-Time
  • Requisition #: LEADC008335
Description

Position: Lead, Cybersecurity Architecture & Operations

Supervisor: Global Chief Information Security Officer

Location: Rosemont, IL

Summary:

We are seeking a seasoned, self-motivated, hands-on cybersecurity leader to serve as the technical anchor of our global security program. Reporting directly to the Global CISO, you will own the architecture and day-to-day operation of our core security capabilities—SaaS and data security posture management, vulnerability management, SIEM, and SOC operations—across a complex, global environment.

This is a player-coach role for someone who wants both strategic influence and technical depth: you will design the architecture, then roll up your sleeves to build, tune, and run it. You will also play a key role in maturing our security controls, evidence, and audit readiness.

Responsibilities:

  • Security architecture:Define and maintain the enterprise security architecture and reference patterns across cloud, SaaS, network, endpoint, and identity domains.
  • SSPM:Deploy, operate, and continuously tune our SSPM platform; drive remediation of SaaS misconfigurations, risky integrations, and identity/permission sprawl across the global SaaS estate.
  • DSPM:Lead DSPM implementation and operations—discover, classify, and protect sensitive data across cloud and on-premises stores; partner with privacy and legal on data governance.
  • Vulnerability management:Own the end-to-end vulnerability management lifecycle: scanning coverage, risk-based prioritization, remediation SLAs, exception handling, and executive reporting across global infrastructure and applications.
  • SIEM:Administer and optimize the SIEM platform—log source onboarding, parsing, detection engineering, use-case development, and cost/ingestion management.
  • SOC operations:Run day-to-day SOC operations, including oversight of MSSP/MDR partners; mature triage, escalation, and incident response playbooks; lead and coordinate response to security incidents across time zones.
  • Audit and Compliance:Strengthen controls, documentation, and evidence to support SOX ITGC and internal/external audits; conduct application and technology security assessments to evaluate risk and ensure compliance with security standards.
  • Threat-informed defense:Track threat actor activity relevant to our industry and translate it into detections, hardening priorities, and leadership briefings.
  • Global collaboration & mentorship:Partner with IT, infrastructure, application, and business teams across regions; mentor analysts and engineers and raise the technical bar of the broader team.
  • Tooling & automation:Evaluate, select, and integrate security tooling; manage vendor relationships and drive consolidation and automation where it adds value.

Requirements:

  • 6+ years of progressive, hands-on experience in cybersecurity engineering, architecture, and/or security operations.
  • Deep, practitioner-level experience with SSPM and DSPM platforms (e.g., deploying, operating, and driving remediation at scale).
  • Proven ownership of an enterprise vulnerability management program, including risk-based prioritization and remediation governance.
  • Hands-on experience administering a SIEM (e.g., detection engineering, log onboarding, tuning) and managing or overseeing a SOC, including MSSP/MDR relationships.
  • Strong working knowledge of cloud security (AWS, Azure, and/or GCP), identity and access management, and SaaS ecosystems (e.g., M365, Salesforce, Workday).
  • Experience operating in a global, multi-region environment with distributed teams and follow-the-sun coordination.
  • Excellent communication skills—able to brief executives, write clear standards, and influence engineers without direct authority.
  • Self-starter who operates with minimal direction and drives initiatives from concept to steady-state operation.

Preferred Qualifications:

  • Experience supporting SOX ITGC controls or operating in a public company environment.
  • Familiarity with frameworks and regulations such as NIST CSF, ISO 27001, CIS Controls, GDPR, and PCI DSS.
  • Scripting/automation skills (Python, PowerShell, APIs) and experience with SOAR platforms.
  • Relevant certifications such as CISSP, CISM, GIAC (GCIA, GCIH, GDSA), or cloud security certifications (AWS/Azure security specialty, CCSP).
  • Experience in manufacturing, consumer products, or other distributed-operations industries.

What Success Looks Like:

  • SSPM and DSPM platforms are fully operational, with a measurable reduction in SaaS misconfigurations and unprotected sensitive data.
  • Vulnerability management SLAs are defined, reported, and trending in the right direction across all regions.
  • SIEM detection coverage mapped to MITRE ATT&CK with documented, tested response playbooks; SOC/MSSP performance metrics in place.
  • Security controls and evidence ready to withstand internal and external audit scrutiny.

Work Arrangements:

This is a hybrid position based at our Rosemont, IL office, with three days per week onsite. Occasional travel and flexibility for calls across global time zones is expected.

Target Salary Range: $140,000 - $180,000 year plus bonus. Exact pay will be based on factors including, but not limited to relevant education, qualifications, experience, level, geographic location, and business and organizational needs. Full-time positions are eligible for competitive benefits, including: paid time off, health, dental, vision, life, disability benefits and 401(k).

Qualifications

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead, Cybersecurity Architecture & Operations
Lead, Cybersecurity Architecture & Operations

Culligan International • Rosemont (IL)

Hybrid
USD 140,000 - 180,000
Global Cybersecurity Engineer
Global Cybersecurity Engineer

Ledgent Technology • Manassas (VA)

Hybrid
USD 140,000 - 145,000
Medical insurance
Dental insurance
Vision insurance
+5
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Chicago (IL)

On-site
USD 250,000 - 275,000
Unlimited Paid Time Off (PTO)
Incentive compensation plans
Company-funded 401k contributions
+3
Lead Security Engineer - Managed Services
Lead Security Engineer - Managed Services

Triwill Group • United States

On-site
USD 133,000 - 193,000
Remote work options
Bonus opportunity: quarterly 10%
Competitive benefits package
+1
Senior Staff Engineer - DevSecOps
Senior Staff Engineer - DevSecOps

Exelixis Inc • Alameda (CA)

On-site
USD 154,500 - 220,500
401(k) plan with company contributions
Group medical, dental, and vision coverage
Flexible spending accounts
+1
Senior Manager, Cyber Security - US
Senior Manager, Cyber Security - US

Pace Industries, LLC • San Antonio (TX)

Hybrid
USD 148,011 - 217,082
Incentive compensation
Employee Stock Purchase Plan (ESPP)
Senior Manager, Security Engineering
Senior Manager, Security Engineering

Jobgether • United States

On-site
USD 137,000 - 222,000
401(k) match
Medical benefits
Equity opportunities
+2
Senior Manager, Global Security Operations
Senior Manager, Global Security Operations

Triwill Group • United States

On-site
USD 152,000 - 210,000
Remote work opportunity
Private workspace provided
Connectivity reimbursement
+1
AVP - Information Security - Americas
AVP - Information Security - Americas

PRA GROUP, INC. • Norfolk (VA)

On-site
USD 130,000 - 160,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000