A

Director – Cybersecurity Operations

American Technology Services
Full-time
On-site
Atlanta, Georgia, United States

About the role


Provides strategic leadership over the Cybersecurity Operations department, encompassing Resilience Operations, and Defense & Response teams. Ensures predictive, adaptive, and intelligence-driven security services through modern SOC, SOAR, and automation strategies.


What you'll do

Primary Responsibilities:

  • Oversee and align all cybersecurity operations with organizational goals and customer SLAs.
  • Drive automation and orchestration across SIEM and SOAR platforms to reduce manual effort using modern tooling to include AI.
  • Define operational maturity goals and lead continuous improvement initiatives.
  • Manage staffing, budgets, and performance metrics across functional teams.
  • Establish cross-functional collaboration with Engineering, Development, and Customer Operations.
  • Communicate key performance and risk indicators to leadership.

Technical Skills:

  • Expertise in SIEM design and rule management.
  • Strong understanding of SOAR workflows, threat intelligence integration, and log enrichment.
  • Incident response, forensics, and root cause analysis.
  • Cloud and hybrid infrastructure security architecture.

Leadership Skills:

  • Strategic leadership and executive communication.
  • Team building, coaching, and mentoring.
  • Analytical decision-making and KPI-based reporting.

Qualifications

Minimum Requirements:

  • 8+ years of progressive leadership in cybersecurity, with direct experience managing SOCs, security engineering, or detection/response teams.
  • Demonstrated success leading SOC transformations with a focus on automation, engineering-led detection, and scalable security infrastructure.
  • Strong understanding of Continuous Threat Exposure Management
  • Hands-on experience with open-source security and SOAR tools such as Wazuh SIEM, Splunk, N8N, etc..) and cloud-native detection frameworks.

Preferred Requirements:

  • Master’s degree or professional certification (CISM, CISSP, GIAC).
  • Technical proficiency in scripting (e.g., Python) and cloud security platforms (AWS, Azure).
  • Exceptional communication skills and ability to engage with C-level executives, both internally and with client stakeholders.
  • Prior experience integrating security tools into DevOps workflows using GitHub Actions, Jenkins, or similar systems.