DIRECTOR – CYBERSECURITY OPERATIONS
Job Details:-
DIRECTOR – CYBERSECURITY OPERATIONS
Industry: Software Product / Technology
Function: IT & Information Security
Role Category: Cybersecurity / IT Security
Location: Noida / Pune / Bengaluru
Experience: 12+ Years in Cybersecurity
Leadership Experience: 5+ Years leading Security Operations
Employment Type: Full-Time, Permanent
Open Position: 1
About the Role
We are looking for an accomplished Director – Cybersecurity Operations to lead and own the organization's cybersecurity operations function.
The role will have end-to-end responsibility across four key pillars:
- Security Operations Center (SOC) – 24/7 monitoring, threat detection, triage and incident response
- SOC Engineering – SIEM/SOAR, EDR/NDR, detection engineering, automation and telemetry management
- Vulnerability & Exposure Management – CTEM, enterprise-wide exposure identification, risk prioritization and remediation governance
- Red Team / Offensive Security – Adversary emulation, offensive testing and purple-team collaboration
The Director will be responsible for people, technology platforms, budgets, vendors and security outcomes, working closely with the CISO and executive leadership.
Key Responsibilities
Strategy & Leadership
- Own the multi-year cybersecurity operations strategy, roadmap and budget.
- Lead SOC, SOC Engineering, Vulnerability Management and Red Team functions.
- Manage senior security leaders, managers and large cybersecurity teams.
- Build succession plans, career paths and a strong security talent pipeline.
- Hire, develop, mentor and retain senior cybersecurity professionals.
- Report cybersecurity posture, operational metrics and major incidents to the CISO and executive leadership.
- Translate complex technical risks into clear business impact.
Security Operations & Incident Response
- Drive continuous improvement in threat detection and incident response.
- Reduce MTTD, MTTR, dwell time, false positives and alert fatigue.
- Lead major and Severity-1 incident response activities.
- Coordinate with IT, Engineering, Legal, Communications and customer-facing teams during major incidents.
- Conduct post-incident reviews and ensure lessons learned are implemented.
- Establish measurable SOC maturity targets and maintain a multi-year transformation roadmap.
- Develop threat-informed detection engineering aligned with MITRE ATT&CK.
- Standardize incident-response playbooks and increase SOAR-based automation.
- Develop outcome-based security metrics and use them to guide investments.
SOC Engineering & Security Platforms
- Own the strategy for SIEM, SOAR, EDR and NDR platforms.
- Optimize telemetry coverage, log pipelines and security monitoring.
- Establish standards for detection engineering, testing, version control and CI/CD.
- Drive automation-first workflows and measurable security processes.
- Evaluate responsible adoption of AI and agentic capabilities within security operations while maintaining appropriate human oversight.
Vulnerability & Exposure Management
- Transform traditional vulnerability management into a risk-based Continuous Threat Exposure Management (CTEM) approach.
- Drive attack-surface discovery and attack-path analysis.
- Prioritize vulnerabilities based on exploitability and business impact.
- Establish and monitor remediation SLAs.
- Track and report exposure reduction to senior leadership.
- Manage security exposure across cloud, SaaS, on-premise infrastructure, endpoints, identities and containers.
- Work closely with Product Security and Application Security teams.
Red Team & Offensive Security
- Establish and manage an annual adversary-emulation and Red Team programme.
- Define scenarios based on threat intelligence and business risks.
- Establish appropriate rules of engagement and legal/safety controls.
- Institutionalize Purple Teaming to convert Red Team findings into improved detections and defensive controls.
- Extend offensive-security testing across cloud, identity/SSO, CI/CD supply chains and AI/LLM environments.
- Ensure findings are converted into actionable remediation plans.
Governance & Stakeholder Management
- Align cybersecurity operations with frameworks such as NIST CSF, ISO 27001 and SOC 2.
- Manage strategic cybersecurity vendors, MSSPs and MDR providers.
- Monitor vendor performance, contracts and service quality.
- Partner with Product, Engineering, IT and Customer Success teams.
- Support customer security and trust requirements.
- Monitor regulatory and industry developments relevant to cybersecurity.
- 12+ years of experience in Cybersecurity.
- Minimum 5+ years of leadership experience in security operations, SOC, Incident Response, Vulnerability Management or Offensive Security.
- Experience managing managers and cybersecurity teams of 20+ professionals.
- Proven experience transforming and maturing a SOC from reactive operations to proactive, threat-informed and engineering-driven security.
- Strong experience across all four pillars: SOC, SOC Engineering/Detection, Vulnerability Management and Red Team.
- Proven experience as an incident commander for major / Severity-1 cybersecurity incidents.
- Strong technical understanding of:
- SIEM / SOAR
- EDR / NDR
- Detection Engineering
- MITRE ATT&CK
- Threat Intelligence
- Cloud Security Operations
- AWS / Azure / GCP
- Identity and access-related attacks
- Experience modernizing vulnerability management toward CTEM or an equivalent exposure-driven model.
- Experience leading Red Team / adversary-emulation programmes.
- Strong executive communication and stakeholder-management skills.
- Experience managing cybersecurity budgets covering people, technology, tools and MSSP/vendor contracts.
- Experience working in a Software Product / Technology organization.
- Experience with AI-enabled cybersecurity operations, including AI-assisted triage and LLM-supported investigations.
- Knowledge of securing and testing AI/LLM systems.
- Familiarity with OWASP LLM Top 10 and MITRE ATLAS.
- Experience managing globally distributed cybersecurity teams.
- Knowledge of SOC 2, ISO 27001 and enterprise customer-security requirements.
- FedRAMP exposure would be an advantage.
- Certifications such as CISSP, CISM, GIAC, GCIH, GSOC, GSOM, OSCP, CRTO or equivalent are valued but not mandatory.
- Relevant cloud-security certifications are an advantage.
Required Qualifications & Experience
Preferred Qualifications
Key Skills
Cybersecurity | Security Operations | SOC | SOC Engineering | Incident Response | SIEM | SOAR | EDR | NDR | Detection Engineering | Vulnerability Management | CTEM | Red Team | Purple Team | Threat Intelligence | MITRE ATT&CK | Cloud Security | AWS | Azure | GCP | AI Security | Risk Management | Governance | Cybersecurity Leadership
How to Apply
Interested and suitable candidates are requested to share their updated CV at:
Subject Line: Director – Cybersecurity Operations
Rachana
MME
07-10-2026 17:11:52