Stand out for this role — generate a tailored resume and cover letter in about a minute.
TKO Group Holdings, Inc. in New York seeks a VP, Cybersecurity Operations & Engineering to lead enterprise security programs, governance, and risk management across global environments.
This role partners with legal, compliance, privacy, and technology to strengthen controls, improve resilience, and drive measurable security outcomes, including detection, response, vulnerability management, and threat‑informed defense.
TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company. TKO owns iconic properties including UFC, the world’s premier mixed martial arts organization; WWE, the global leader in sports entertainment; and PBR, the world’s premier bull riding organization. Together, these properties reach 1 billion households across 210 countries and territories and organize more than 500 live events year-round, attracting more than three million fans. TKO also services and partners with major sports rights holders through IMG, an industry-leading global sports marketing agency; and On Location, a global leader in premium experiential hospitality.
The VP, Cybersecurity Operations & Engineering is responsible for leading and maturing the enterprise cybersecurity Operations and Engineering programs with oversight on Cybersecurity program execution, and risk management, while leading cybersecurity operations and engineering capabilities. This leader partners across Cybersecurity, technology, legal, compliance, privacy, and business units to align and articulate strategy, operationalize policy, strengthen controls, improve resilience, and provide measurable security outcomes across a complex global environment. The ideal candidate brings a strong blend of executive leadership, program & project management discipline, technical depth, and business partnership. They are equally effective shaping long‑range roadmaps, communicating across all levels of an enterprise, driving control maturity, and ensuring day‑to‑day operational readiness across detection, response, vulnerability management, security engineering, risk management, and threat‑informed defense.
Lead the enterprise cybersecurity operations & engineering programs, including documenting strategy, risk governance, organization roadmap development, budgeting, KPI reporting, and preparing executive communications. Contribute to cybersecurity policies, standards, procedures, and control frameworks aligned to business objectives and risk appetite. Develop and maintain governance forums, steering committee materials, risk updates, and decision‑supporting business cases for senior leadership. Partner with legal, compliance, privacy, internal audit, and technology stakeholders to strengthen the company’s overall security, regulatory, and governance posture. Drive consistent security practices across corporate, cloud, application, and business environments, ensuring alignment with enterprise architecture and operating models. Translate threat, control, and assessment findings into practical, risk‑informed recommendations and prioritized remediation plans.
Provide executive oversight for security operations, including SOC and/or MSSP performance, alert monitoring, incident triage, escalation management, and operational readiness. Own and mature incident response planning, operational runbooks, tabletop exercises, and cross‑functional response coordination with technology, legal, HR, and compliance teams. Oversee threat intelligence, threat detection, threat hunting, and vulnerability management capabilities to improve visibility, response speed, and control effectiveness. Ensure the organization is prepared to protect, detect, respond to, and recover from cybersecurity events affecting critical systems, intellectual property, data, and brand reputation. Develop and monitor operational metrics and service‑level indicators for security operations, incident management, remediation progress, and program effectiveness.
Oversee the design, implementation, enhancement, and lifecycle management of cybersecurity technologies and control capabilities across on‑premises, cloud, endpoint, identity, and network domains. Partner closely with infrastructure, platform, and software engineering teams to embed security into enterprise architecture, system design, and operational workflows. Support secure development lifecycle practices, software assurance, secure coding, and application security initiatives across internal and customer‑facing environments. Guide the selection and optimization of security tools and services, including SIEM, EDR, IDS/IPS, firewalls, vulnerability management, logging, monitoring, and related protection technologies. Promote automation, orchestration, and process simplification to improve scalability, consistency, and efficiency across cybersecurity operations and engineering.
Lead cyber risk assessments across infrastructure, applications, vendors, business processes, and emerging technology initiatives. Support compliance and control maturity efforts related to frameworks and obligations such as NIST, ISO 27001, PCI‑DSS, SOC, SOX, GDPR, privacy, and other applicable requirements. Provide security leadership for vendor and third‑party reviews, architectural reviews, major initiatives, and transformation programs. Build trusted relationships with business and technology leaders to ensure security enables growth, resilience, and informed risk‑taking. Champion security awareness, education, and culture‑building efforts that improve employee behavior and strengthen organizational readiness.
Lead, coach, and develop high‑performing cybersecurity managers and individual contributors across program, operations, and engineering functions. Foster a culture of accountability, collaboration, continuous improvement, and service‑oriented partnership. Mentor technical teams on incident response, operational excellence, architectural decision‑making, and effective communication with executive and non‑technical audiences.
Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience. 12+ years of progressive cybersecurity experience, including leadership of enterprise security programs in complex, high‑growth, or globally distributed organizations. 7+ years of leadership experience managing managers, cross‑functional teams, and/or external service providers across multiple cybersecurity domains. Demonstrated success building or maturing cybersecurity governance, program management, security operations, and security engineering capabilities. Strong working knowledge of cybersecurity frameworks, regulatory requirements, and assurance practices, including NIST CSF, ISO 27001, PCI‑DSS, SOC, SOX, data privacy, and related standards. Experience leading or overseeing incident response, threat intelligence, vulnerability management, detection engineering, and security monitoring programs. Strong technical understanding of cloud security, identity and access management, endpoint protection, network security, logging and monitoring, system hardening, and enterprise security architecture. Experience working closely with software development and infrastructure teams to integrate security into lifecycle management, architecture, and operational processes. Proven ability to define metrics, communicate risk clearly, and present meaningful security insights to operational, technical, and executive stakeholders. Strong business judgment and the ability to balance risk reduction, operational efficiency, and strategic enablement. Excellent written and verbal communication skills, with the ability to influence across all levels of the organization.
Master’s degree in a relevant discipline. CISSP or comparable industry certification. Experience in media, entertainment, sports, or other fast‑paced global operating environments. Experience overseeing a hybrid model that includes internal teams and managed security partners. Experience building metric‑driven security programs and using automation to streamline cyber workflows.
A clearly governed cybersecurity program with measurable outcomes, executive visibility, and aligned priorities. Strong project portfolio management including active projects, roadmaps, greenlighting materials, and overall strategy documents. Maintains Cyber Risk Register and Risk governance process. Supports procurement calendar, budget, and actuals for current and future year. Mature operational readiness across monitoring, response, vulnerability remediation, and threat‑informed defense. Supports engaging C‑Suite and IT Leadership content, meeting materials, and agendas. Strong partnership across technology and business teams, resulting in better security‑by‑design and faster risk reduction. Scalable engineering and program capabilities that improve resilience while enabling the business.
Per local requirements and in the interest of transparency, the hourly rate shown below reflects the prevalent current hiring range for this position. Hiring pay rates are based on a number of factors, including location and may vary depending on job‑related qualifications, knowledge, skills and experience. The company strives to provide locally competitive rewards packages, which include base rate along with, as applicable, short‑and long‑term incentives, growth and developmental opportunities, robust benefits, such as health care, retirement, vacation and other paid time off, and additional offerings.
Hiring Rate Minimum: $225,000 annually (minimum will not fall below the applicable State/local minimum salary thresholds)
Hiring Rate Maximum: $300,000 annually
TKO is an Equal Opportunity Employer and complies with all applicable federal, state, and local laws regarding non‑discrimination in employment. TKO makes employment decisions based on merit and qualifications, without considering an employee’s or applicant’s race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, marital status, veteran status, or any other basis prohibited under federal, state or local laws governing non‑discrimination in employment in every location in which the Company has facilities. TKO also provides reasonable accommodations for qualified individuals with disabilities in accordance with the Americans with Disabilities Act (ADA) and applicable state or local laws.
For information about Privacy and Information Security for TKO employment candidates, please review our Privacy Policy. For information regarding Terms of Use for this and other TKO websites, please review our Terms of Use.
About WWE WWE® is an integrated media organization and the recognized global leader in sports entertainment. The company consists of a portfolio of businesses that create and deliver original content 52 weeks a year to a global audience. WWE is committed to family‑friendly entertainment on its television programming, premium live events, digital media, and publishing platforms. WWE’s TV‑PG programming can be seen in more than 1 billion households worldwide in more than 20 languages through world‑class distribution partners including NBCUniversal, The CW and Netflix. In the United States, NBCUniversal’s streaming service, Peacock, is the exclusive home to all premium live events, a variety of original programming and a massive video‑on‑demand library. Netflix is the exclusive home for WWE programming around the world, other than select international markets. WWE is part of TKO Group Holdings (NYSE: TKO). Additional information on WWE can be found at wwe.com and corporate.wwe.com.
About UFC UFC® is the world’s premier mixed martial arts organization (MMA), with more than 700 million fans and approximately 290 million social media followers. The organization produces more than 40 live events annually in some of the most prestigious arenas around the world while broadcasting to over 975 million households across more than 170 countries. UFC’s athlete roster features the world’s best MMA athletes representing more than 80 countries. The organization’s digital offerings include UFC FIGHT PASS®, one of the world’s leading streaming services for combat sports. UFC is part of TKO Group Holdings (NYSE: TKO) and is headquartered in Las Vegas, Nevada. For more information, visit UFC.com and follow UFC at Facebook.com/UFC and @UFC on X, Snapchat, Instagram, and TikTok: @UFC.
About IMG IMG is a leading global sports marketing agency, specializing in media rights management and sales, multi‑channel content production and distribution, brand partnerships, strategic consulting, digital services, and events management. It powers growth of revenues, fanbases and IP for more than 200 federations, associations, events, and teams, including the National Football League, English Premier League, International Olympic Committee, National Hockey League, Major League Soccer, ATP and WTA Tours, the AELTC (Wimbledon), Euroleague Basketball, CONMEBOL, DP World Tour, and The R&A, as well as UFC, WWE, and PBR. IMG is a subsidiary of TKO Group Holdings, Inc. (NYSE: TKO), a premium sports and entertainment company.
About PBR PBR is the world’s premier bull riding organization. More than 1,000 bull riders compete in more than 200 events annually across the televised PBR Unleash The Beast tour (UTB), which features the top bull riders in the world; the PBR Pendleton Whisky Velocity Tour (PWVT); the PBR Touring Pro Division (TPD); and the PBR’s international circuits in Australia, Brazil, and Canada. In 2022, PBR launched the nationally televised PBR Teams league—eight teams of the world’s best bull riders competing for a new championship expanding to 10 teams in 2024—as well as the PBR Challenger Series with more than 60 annual events nationwide. The organization’s digital assets include PBR RidePass on Pluto TV, which is home to Western sports. PBR is a subsidiary of TKO Group Holdings, Inc. (NYSE: TKO), a premium sports and entertainment company. For more information, visit PBR.com, or follow on Facebook at Facebook.com/PBR, X at X.com/PBR, and YouTube at YouTube.com/PBR.
About On Location On Location is a global leader in premium experiential hospitality, offering ticketing, curated guest experiences, live event production and travel management across sports, entertainment, fashion and culture. On Location provides unrivaled access for corporate clients and fans looking for official, immersive experiences at marquee events, including the Olympic and Paralympic Games, FIFA World Cup 2026, Super Bowl, NCAA Final Four, and more. An official partner and/or service provider to over 150 iconic rights holders, such as the IOC (the Milano Cortina 2026 and Los Angeles 2028 Olympic Games), FIFA, NFL, NCAA, UFC, WWE, and PGA of America, the company also owns and operates a number of its own unique experiences. On Location is a subsidiary of TKO Group Holdings, Inc. (NYSE: TKO), a premium sports and entertainment company.
About Zuffa Boxing Zuffa Boxing is a joint venture between TKO Group Holdings, Inc. (“TKO”) (NYSE: TKO) and Sela, the entertainment conglomerate. TKO serves as managing partner, providing day‑to‑day operational expertise, management, and oversight of the promotion, with executive leadership anchored by UFC President and CEO Dana White and WWE President and TKO Board Member Nick Khan. The promotion aims to reimagine the sport of boxing by evolving the current model to restore the sport’s rightful place in the forefront of the global sports ecosystem. For more information, follow @Zuffa_Boxing on X; and @ZuffaBoxing on Snapchat, Instagram, Threads, and TikTok.