... own the cyber remediation roadmap and 90-day sprint planning. • Build strong working ... operations with business priorities. • Produce regular operational reporting (KPIs, incident ...
... own the cyber remediation roadmap and 90-day sprint planning. • Build strong working ... operations with business priorities. • Produce regular operational reporting (KPIs, incident ...
Cyber Engineer
San Antonio, TX · On-site
Oversees fiscal, operational, administrative, and human resources aspects of the project ... well planned information management environment. "Technology moving at the speed of thought ...
Cyber Engineer
San Antonio, TX · On-site
Oversees fiscal, operational, administrative, and human resources aspects of the project ... well planned information management environment. "Technology moving at the speed of thought ...
Cyber Vulnerability Test Engineer
TX · On-site
$85K - $105K/yr
Designs, develops, tests, and reports on the operational unified communication software or ... Provides tactical and strategic input to overall network planning and related projects. * Reports ...
Cyber Vulnerability Test Engineer
TX · On-site
$85K - $105K/yr
Designs, develops, tests, and reports on the operational unified communication software or ... Provides tactical and strategic input to overall network planning and related projects. * Reports ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
... operations and watch floors; mix of help desk and user support, network and systems administration, incident response, and planned maintenance; continuous learning in cyber tools, network defense ...
Cyber Operations Planner information
See Texas salary details
$4.93 - $10.20
0% of jobs
$10.20 - $15.47
0% of jobs
$15.47 - $20.75
11% of jobs
$20.75 - $26.02
2% of jobs
$26.02 - $31.29
8% of jobs
$32.28 is the 25th percentile. Wages below this are outliers.
$31.29 - $36.57
17% of jobs
The median wage is $39.62 / hr.
$36.57 - $41.84
20% of jobs
$41.84 - $47.11
14% of jobs
$50.28 is the 75th percentile. Wages above this are outliers.
$47.11 - $52.39
5% of jobs
$52.39 - $57.66
6% of jobs
$57.66 - $62.93
17% of jobs
$4
$41
$62
How much do cyber operations planner jobs pay per hour?
What does a Cyber Operations Planner do?
How does a Cyber Operations Planner typically collaborate with other teams during mission planning and execution?
What are the key skills and qualifications needed to thrive as a Cyber Operations Planner?
What is the difference between Cyber Operations Planner vs Cybersecurity Analyst?
| Aspect | Cyber Operations Planner | Cybersecurity Analyst |
|---|---|---|
| Required Credentials | Bachelor's in Cybersecurity, Computer Science, or related field; certifications like CISSP, CEH | Bachelor's in Cybersecurity, Information Technology, or related; certifications like CompTIA Security+, CISSP |
| Work Environment | Military, government agencies, defense contractors; strategic planning focus | Private sector, IT firms, security teams; operational monitoring and incident response |
| Employer & Industry Usage | Primarily in defense, intelligence, government | Across industries including finance, healthcare, tech |
| Common Search & Comparison | Often compared for strategic roles in cyber defense |
While both roles involve cybersecurity, Cyber Operations Planners focus on strategic planning and coordination of cyber defense operations, often within government or military contexts. Cybersecurity Analysts typically handle operational security, monitoring, and incident response in various industries. Understanding these differences helps in choosing the right career path or job focus.
- Clinical Operations Specialist
- Senior Debit Card Specialist
- Vendor Management Specialist
- Government Information Specialist Foia
- It Specialist Ii
- Junior Learning Specialist
- Freelance Operations Support Specialist
- Information Technology Security Specialist
- Cyber Systems Operations Specialist
- Work From Home Information Technology Specialist

Job description
Hillwood is a premier real estate investment and development company seeking a Manager of Cybersecurity Operations to lead and scale their cybersecurity operations function. This role involves overseeing monitoring, detection, incident response, and vulnerability management across all business divisions while building a high-performing team and establishing foundational processes.
Responsibilities:
• Serve as the operational leader of the cyber function, managing daily priorities, workload distribution, and team performance across monitoring, incident response, identity governance, and risk reduction workstreams.
• Mentor and develop junior analysts; set clear expectations, conduct regular 1:1s, provide technical coaching, and support career development plans.
• Establish and maintain cyber operations playbooks, runbooks, SLAs, and escalation procedures; drive continuous improvement through lessons learned and metrics review.
• Manage the on-call rotation and ensure 24/7 coverage models are sustainable and effective.
• Serve as the primary point of contact for executive communication during security events; deliver clear, concise incident briefings to SVP IT and senior leadership.
• Lead incident response activities for confirmed security events, coordinating investigation, containment, eradication, recovery, and post-incident review.
• Perform advanced threat analysis, log correlation, forensic triage, and root cause investigation across SIEM, EDR/XDR, email, identity, and cloud platforms.
• Own detection engineering: develop, tune, and maintain detection rules, correlation logic, and alerting thresholds to reduce noise and improve mean-time-to-detect (MTTD).
• Coordinate with external incident response partners, legal, and business leadership as needed during significant events.
• Maintain incident response plans and ensure alignment with NIST CSF and Hillwood’s risk framework.
• Own the IGA program operationally: manage the platform, define and maintain role-based access control (RBAC) models, entitlement catalogs, and access policies across Hillwood’s application and infrastructure landscape.
• Lead the design and execution of periodic access certification and recertification campaigns, ensuring compliance with audit requirements (ITGC, SOC 2, etc.).
• Manage joiner/mover/leaver (JML) automation workflows; identify gaps and drive continuous improvement in provisioning/de-provisioning accuracy and speed.
• Monitor and resolve IGA platform exceptions, including orphaned accounts, segregation of duties (SoD) violations, excessive privilege accumulations, and failed provisioning events.
• Serve as the functional owner for IGA vendor relationships and platform roadmap; coordinate with IT infrastructure on directory services, SSO, MFA, and Conditional Access integration.
• Ensure IGA controls satisfy NIST CSF requirements and support Hillwood’s Zero Trust architecture objectives.
• Produce IGA metrics and reporting for governance committees and audit evidence packages.
• Oversee the vulnerability management lifecycle: scanning, prioritization, remediation tracking, exception management, and reporting.
• Drive risk reduction initiatives across the environment, including security configuration hardening, attack surface reduction, and third-party risk assessment support.
• Lead phishing simulation programs and security awareness efforts in coordination with HR and communications.
• Support due diligence questionnaires and audit evidence requests, ensuring timely, accurate, and well-documented responses.
• Provide security architecture input on infrastructure, application, and cloud projects; ensure security is considered in design decisions.
• Evaluate and recommend security tools, platforms, and process improvements; manage proof-of-concept efforts and vendor assessments.
• Collaborate with the EDL/data team and IT infrastructure on log onboarding, data source integration, and security telemetry strategy.
• Support Conditional Access policy management, Intune/MDM security posture, and DLP/information protection initiatives.
• Represent the cyber function in governance forums, including the AI Steering Committee, vendor intake reviews, and data governance discussions.
• Maintain and report on NIST CSF maturity scores; own the cyber remediation roadmap and 90-day sprint planning.
• Build strong working relationships with division leaders, IT infrastructure, legal, HR, and external partners to align security operations with business priorities.
• Produce regular operational reporting (KPIs, incident trends, IGA metrics, vulnerability posture) for SVP IT and executive stakeholders.
Qualifications:
Required:
• Strong technical depth in the following areas: SIEM administration and detection engineering
• Strong technical depth in the following areas: EDR/XDR investigation and response
• Strong technical depth in the following areas: Identity and access management / IGA platforms (e.g., Microsoft Entra ID Governance)
• Strong technical depth in the following areas: Vulnerability management (e.g. Rapid7)
• Strong technical depth in the following areas: Cloud security (Azure, M365, Conditional Access, Intune)
• Working knowledge of security frameworks such as NIST CSF, NIST 800-53, and MITRE ATT&CK.
• Strong analytical and problem-solving skills with the ability to make sound decisions in high-pressure situations.
• Excellent written and verbal communication skills, with the ability to translate technical concepts for non-technical audiences.
• Demonstrated ability to handle sensitive and confidential information with discretion and integrity.
• Bachelor’s degree in IT, Computer Science or related field.
• 5–10+ years of progressive experience in cybersecurity operations, incident response, or security engineering.
• 2+ years of experience leading, mentoring, or managing a team (formal or informal).
• Experience producing executive-level security communications and incident briefings.
• Experience designing and executing access controls, RBAC models, and identity lifecycle processes.
Preferred:
• Preferred experience working with AI security monitoring (e.g. AI Agent monitors, etc.)
Company:
Hillwood is a company that invests, develops, and advises in real estate properties. Founded in 1998, the company is headquartered in Dallas, USA, with a team of 501-1000 employees. The company is currently Late Stage.
About Hillwood
Sourced by ZipRecruiter
Industry
Real estate
Company size
51 - 200 Employees
Headquarters location
Dallas, TX, US
Year founded
1998