Director, Security Operations
Core
Lead day-to-day operations for a geographically dispersed Security Operations team to protect Gartner's reputation, customers, and IT infrastructure against, detect, and respond to threats.
Role type
Director, Security Operations (Hands-on IC with leadership responsibilities)
Builds
Operational security response capabilities, automated detection workflows, and incident response processes for Gartner's IT environment.
Domain
Cybersecurity / Information Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SOC leadership, incident response management, security event analysis, SIEM/EDR tool expertise, project management, team mentorship, automation strategy, threat detection framework alignment (ATT&CK/Cyber Kill Chain), scripting/programming (Python/PowerShell/Bash), cloud platform experience (AWS/Azure/GCP)
Preferred skills
CISSP/GCIH/GCFA certifications, transformation of security teams, proactive innovation mindset
Technologies
SIEM, EDR, web proxy, email security tools, AWS, Azure, GCP, Python, PowerShell, Bash
Responsibilities
Drive operational excellence of a geographically dispersed Security Operations team; Serve as the Incident Commander during the incident response process; Continuously seek out opportunities to improve the team's ability to rapidly and effectively respond to security incidents; Work with key business stakeholders to detect, respond to, and remediate security issues; Provide mentorship and guidance to team members; Drive automation initiatives, enhancing analyst capabilities and workflows while eliminating monotonous tasks; Develop innovative and cutting-edge detection content aligned with ATT&CK, Cyber Kill Chain, and various other cyber security frameworks; Ensure smooth handover of alerts and incidents between team members located in various geographic locations
Seniority
Director, strategic leadership with hands-on technical execution