Director, Security Operations

Agilysys, Inc
Alpharetta, GA

Description

Director of Security Operations

This is an In-Office Role. Local Candidates Only.

Overview

The Director of Security Operations is responsible for leading and maturing the organization’s cyber defense capabilities, including Security Operations (SOC), Incident Response, and Vulnerability Management. This role ensures rapid detection, investigation, containment, and recovery from security incidents while proactively reducing risk through identification of vulnerabilities

Reporting to CISO, this leader drives a risk-based security operations strategy aligned with business objectives, regulatory requirements, and industry best practices.

Key Responsibilities

Security Operations, Incident Response Leadership & Threat Hunting

  • Lead and oversee 24x7 security operations and enterprise incident response capabilities.
  • Own the Incident Response (IR) program, including policies, playbooks, escalation paths, and communication protocols.
  • Ensure rapid identification, containment, eradication, and recovery from security incidents.
  • Act as executive incident commander for high-severity incidents, coordinating technical, legal, privacy, communications, and business stakeholders.
  • Conduct and oversee post-incident reviews, root cause analysis, and corrective action plans.
  • Ensure lessons learned are translated into improved detections, controls, and preventive measures.
  • Lead tabletop exercises and simulate cyber incidents to validate readiness and executive decision-making.
  • Establish and mature a structured threat hunting program focused on identifying advanced, persistent, and evasive threats not detected by automated controls.
  • Direct hypothesis-driven threat hunts using adversary TTPs, threat intelligence, and MITRE ATT&CK mappings.
  • Ensure threat hunting outcomes drive improvements in detection logic, alert fidelity, and preventive controls.

Vulnerability & Exposure Management

  • Own the enterprise vulnerability management program across infrastructure, endpoints, applications, containers, and cloud platforms.
  • Establish risk-based vulnerability prioritization using exploitability, business impact, asset criticality, and threat intelligence.
  • Oversee vulnerability scanning, validation, remediation tracking, and executive reporting.
  • Drive continuous improvement in remediation SLAs and vulnerability reduction metrics.

Threat Detection & Security Engineering Enablement

  • Guide development and tuning of threat detection use cases aligned to the MITRE ATT&CK framework.
  • Ensure comprehensive telemetry coverage across endpoint, identity, network, cloud, and SaaS environments.
  • Integrate vulnerability, misconfiguration, and threat intelligence to improve exposure-based detection and response.
  • Partner with Security Architecture and Engineering teams to operationalize secure-by-design and preventive controls.

Governance, Metrics & Executive Reporting

  • Define and track operational SLAs, KPIs, and KRIs for SOC performance, incident response effectiveness, vulnerability management, and configuration security.
  • Provide clear, concise, risk-based reporting to executive leadership and the Board.
  • Support regulatory, audit, and customer assurance activities (SOC 2, PCI, SOX, etc.), including incident response evidence and reporting.

People, Program & Vendor Leadership

  • Build, mentor, and lead high-performing SOC, IR, and vulnerability management teams.
  • Establish on-call, escalation, and follow-the-sun operational models.
  • Manage security operations vendors, MDR providers, and tooling investments to maximize coverage and efficiency.
  • Drive automation through SOAR and workflow orchestration to improve response speed and consistency.

Qualifications

Required

  • 10+ years of progressive experience in cybersecurity, including deep expertise in Security Operations and Incident Response.
  • 5+ years of experience leading SOC and IR teams in enterprise or SaaS environments.
  • Extensive experience leading and working with international cyber teams
  • Strong hands-on knowledge of:
    • Incident response frameworks and playbooks
    • MITRE ATT&CK and D3FEND frameworks
    • SIEM, SOAR, EDR/XDR technologies
    • Vulnerability management and exposure reduction
    • Cloud security and configuration management
  • Proven experience serving as incident commander for high-severity cyber incidents.

Preferred

  • Experience with breach response coordination involving legal, privacy, and communications teams.
  • Familiarity with regulatory notification requirements and customer communications.
  • Industry certifications such as CISSP, CISM, GIAC (GCIH, GCED), or equivalent.

Key Competencies

  • Proactive threat mindset and adversary-focused thinking
  • Crisis leadership and executive presence
  • Risk-based decision making
  • Operational excellence and continuous improvement
  • Clear, confident communication under pressure
  • Automation and scale mindset

Posted 2026-01-09

Recommended Jobs

Community Front Desk Receptionist

Town of Jupiter Inlet Colony
Atlanta, GA

Position Summary: Perform front desk clerical duties as assigned by the Clinic Director. Provide coverage of other administrative responsibilities when Administrative Assistant is out of office. …

View Details
Posted 2025-09-17

Night Shift Server / Wait Staff

Waffle House, Inc.
Augusta, GA

At Waffle House, we are not in the food business. We are in the People Business and we are hiring immediately for full time and part time servers for the Night Shift. Being in the People Business, w…

View Details
Posted 2026-01-13

Senior Data Analyst

RaceTrac
Atlanta, GA

The Senior Data Analyst plays a critical role within Enterprise Data, helping drive strategic, data-informed decisions across the organization. This role partners closely with business stakeholders…

View Details
Posted 2025-11-13

Quality Assurance Specialist

VenU eLearning Solutions
Smyrna, GA

The Quality Assurance Specialist position ensures that client projects are free from errors and defects through extensive testing. And, when assigned to oversee development projects, the Quality Assur…

View Details
Posted 2025-11-27

Senior Lead Network Engineer

Intercontinental Exchange Holdings, Inc.
Atlanta, GA

Overview Job Purpose Intercontinental Exchange, Inc. (ICE) presents a unique opportunity to work on cutting-edge technology and business challenges in the financial sector. The ICE Senior Lea…

View Details
Posted 2025-11-10

Loader

RightStone
Mableton, GA

We are looking for a dedicated  Loader Forklift Operator in Mableton, GA 30126 with $19.00/hr. pay for a 1-month contract, temp to per opportunity. In this role, you will be responsible for effici…

View Details
Posted 2025-12-26

Systems Engineering Lead - remote

jobgether
Georgia

This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Senior Systems Engineer - REMOTE. In this role, you will be pivotal in enhancing the performance an…

View Details
Posted 2026-01-11

Project Manager - Service

System One
Atlanta, GA

Project Manager – Construction Location: Southwest Atlanta, GA Schedule: Monday–Friday | 7:00 AM – 4:00 PM Pay Rate: $46–$50/hour Experience Required: 3–5 years Top 3 Skills # Str…

View Details
Posted 2025-11-18

Respiratory Therapist, RRT - Internal Agency

Piedmont Healthcare Inc.
Atlanta, GA

Responsibilities: Respiratory Therapist Work that works for you! Continue your respiratory career by joining Piedmont’s Travel Agency, First Call Staffing Solutions! Piedmont Healthcare has laun…

View Details
Posted 2025-11-04

Experienced Automotive Technician

Southern Motors Honda
Savannah, GA

Automotive Technician Southern Motors Honda is seeking a skilled and detail-oriented Automotive Technician to join our team. The ideal candidate will be responsible for diagnosing, repairing, and m…

View Details
Posted 2025-10-14