Expoint - all jobs in one place

Finding the best job has never been easier

Limitless High-tech career opportunities - Expoint

SAP SAP NS2 Director Cyber Security Operation Center CSOC - Hybrid 
United States, Virginia 
728581702

17.04.2025

:

Position Overview:

Key Responsibilities:

  • Lead and coordinate the Security Operations Center’s 24x7 monitoring and response activities for corporate and customer cloud environments.
  • Direct and manage intelligence collection, threat analysis, incident response, and forensic investigative efforts.
  • Provide comprehensive cybersecurity posture and incident response updates to senior executives, including the Chief Information Security Officer, Chief Security Officer, C-Suite, and executive Insider Threat Team as appropriate.
  • Develop and implement a threat driven detection capability incorporating continuous improvements in cybersecurity operational processes, incident management practices, and risk mitigation strategies that affords an appreciating investment for SAP NS2.
  • Oversee technical and operational analysis during cyber events and/or incidents, ensuring alignment with applicable governance requirements, organizational Information Security Policies and industry best practices.
  • Manage a team of cybersecurity professionals responsible for threat analysis, reporting, executive briefings, and coordination of remediation efforts.
  • Define and validate technical requirements for incident response tools and ensure these technologies support and enhance operational workflows.
  • Recommend and oversee configuration enhancements to improve cybersecurity analysis tools’ effectiveness and usability.
  • Maintain expertise in cybersecurity trends and threats through active participation in industry task forces, professional networks, and continuous monitoring of security advisories.
  • Proactively communicate and manage the potential impacts of emerging cyber threats and vulnerabilities to key business stakeholders.
  • Oversee device security management, including timely upgrades and patches, ensuring comprehensive remediation and threat eradication capabilities.

Qualification Requirements:

  • Applicants must be U.S. citizens residing within the United States.
  • Minimum of 4 years' experience leading or managing functions within a Security Operations Center (SOC).
  • At least 10 years' experience in security operations management, incident response, threat analysis, vulnerability management, and security monitoring.
  • Demonstrated proficiency in cybersecurity incident response processes, including the capability to oversee detailed incident analysis.
  • Extensive experience managing cybersecurity teams responsible for threat analysis, incident reporting, executive briefings, and remediation coordination.
  • Strong familiarity with industry-standard cybersecurity frameworks such as NIST, ISO, and PCI.
  • Hands-on experience and comprehensive understanding of Security Information and Event Management (SIEM) systems.
  • Expertise in unified threat management, antivirus solutions, threat intelligence, vulnerability management, cybersecurity investigations, and forensic analysis.
  • Advanced knowledge of best practices related to information systems security, data security, and infrastructure protection.
  • Exceptional organizational, leadership, and time-management skills, with the ability to prioritize effectively and drive high-quality results.
  • Strong networking fundamentals and comprehensive security knowledge.
  • Proven ability to manage complex tasks and projects, set appropriate stakeholder expectations, and maintain rigorous standards for security operations.
  • Ability to apply analytical techniques when gathering information from stakeholders, define problems, design technical solutions, develop procedures to solve problems, and implement for execution. Demonstrated integrity and professional judgment, with experience managing sensitive and confidential information appropriately.
  • Expertise in measuring operational performance using defined key performance indicators (KPIs) specific to SOC environments that serves compliance, risk, and business intelligence needs.
  • Outstanding verbal and written communication skills, emphasizing clear, prompt, and accurate information dissemination, particularly during security events and/or incidents to stakeholders with varying levels of technical acumen.
  • Ability for infrequent travel for meetings as required.

Desired Education and Certifications:

  • Bachelor's degree preferred; relevant experience may substitute for educational requirements.
  • Professional certifications such as CISSP, CISSP-ISSEP, CISSP-ISSAP, CISSP-ISSMP, ITIL, CISM, GSEC, GCIA, GCED, SEC503, CCNA, RHCE, or specific SIEM certifications are highly desirable.

We win with inclusion


Washington DC