Remote job
Director, Security Engineering | Remote, USA
Job details
About this role
Role overview A director-level role leading the security engineering practice that delivers managed detection, response, and security platform services for clients. The position owns engineering direction across SIEM, EDR, SOAR, data pipelines, and related platforms while driving scale through automation and continuous improvement. It combines technical leadership, people management, practice operations, and executive client engagement in a fully remote setting.
Responsibilities - Lead the security engineering practice across SIEM, EDR, SOAR, and related platforms, including operational and strategic planning and resource allocation. - Own technical direction and quality for managed detection and response, co-managed SIEM, data engineering, and engineering triage offerings, including platform architecture, detection standards, and SOAR orchestration. - Establish metrics and processes that demonstrate continuous improvement, efficiency, and adherence to SLOs in client operational experience. - Provide practice management, offer management, and sales enablement by partnering on scoping, proposals, and offer development. - Manage financial aspects including purchasing input, budgeting, and vendor decisions, plus staffing, development, performance management, and disciplinary actions. - Serve as an executive escalation point, communicate regularly with clients and partners, and stay current on evolving risks, platform capabilities, and vendor roadmaps.
Requirements - Bachelor's degree in a related field or equivalent experience; master's degree preferred. - 10 or more years of information security and professional or managed services experience, including leadership of security engineering or SOC platform teams. - Strong platform engineering experience across SIEM, EDR, and SOAR, with additional exposure to platforms such as Wiz and Cribl. - Experience with practice management, offer or sales enablement, and delivering managed security services engagements. - Ability to participate in scheduled and on-call support across a 24x7x365 service, with occasional travel typically under 15 percent. - Ability to read technical documentation and statements of work, and to write clear runbooks, standard operating procedures, and executive communications.
Nice to have - Advanced security or leadership certifications such as CISSP or CISM, plus relevant security platform vendor certifications. - Experience driving scale through security automation and orchestration technologies.
Benefits and work setup The role is fully remote within the continental United States. The organization supports inclusive employee resource groups, professional training resources, volunteer opportunities, and the technology needed to work productively from home.