Role overview The Director, Cybersecurity Operations leads Security Operations and Incident ... Own the purple team and control validation program, confirming that deployed controls operate as ...
Role overview The Director, Cybersecurity Operations leads Security Operations and Incident ... Own the purple team and control validation program, confirming that deployed controls operate as ...
Senior Cybersecurity Engineer - Adversary Operations, Innovation & Purple Team Operations
Warren, MI · On-site
The Senior Cybersecurity Engineer will perform tactical purple operations, repeatable MSV-based ... This includes direct company sponsorship, entry of GM as the immigration employer of record on a ...
Senior Cybersecurity Engineer - Adversary Operations, Innovation & Purple Team Operations
Warren, MI · On-site
The Senior Cybersecurity Engineer will perform tactical purple operations, repeatable MSV-based ... This includes direct company sponsorship, entry of GM as the immigration employer of record on a ...
Cybersecurity Lead
San Jose, CA · On-site
Reporting to the Director of Cybersecurity, this leader bridges strategy and execution driving the ... Proven ability to lead incident response and purple team exercises from start to finish
Cybersecurity Lead
San Jose, CA · On-site
Reporting to the Director of Cybersecurity, this leader bridges strategy and execution driving the ... Proven ability to lead incident response and purple team exercises from start to finish
Reporting to the Director of Cybersecurity, this leader bridges strategy and execution driving the ... Proven ability to lead incident response and purple team exercises from start to finish
Reporting to the Director of Cybersecurity, this leader bridges strategy and execution driving the ... Proven ability to lead incident response and purple team exercises from start to finish
Purple Teaming & Improvement * Lead purple team exercises, facilitating collaboration between ... Compile and analyze data for management reporting and metrics as directed. * Performs other duties ...
Purple Teaming & Improvement * Lead purple team exercises, facilitating collaboration between ... Compile and analyze data for management reporting and metrics as directed. * Performs other duties ...
Director, Cyber Security
Savannah, GA · On-site
$200 - $250/hr
At WillScot, our team of nearly 5000+ people makes our company a Great Place to Work ® and we ... Reporting to the VP Infrastructure & IT Operations, the Director Cybersecurity is a critical role ...
Director, Cyber Security
Savannah, GA · On-site
$200 - $250/hr
At WillScot, our team of nearly 5000+ people makes our company a Great Place to Work ® and we ... Reporting to the VP Infrastructure & IT Operations, the Director Cybersecurity is a critical role ...
Director, Cyber Security
$103K - $139K/yr
At WillScot, our team of nearly 5000+ people makes our company a Great Place to Work and we believe ... Reporting to the VP Infrastructure & IT Operations, the Director Cybersecurity is a critical role ...
Director, Cyber Security
$103K - $139K/yr
At WillScot, our team of nearly 5000+ people makes our company a Great Place to Work and we believe ... Reporting to the VP Infrastructure & IT Operations, the Director Cybersecurity is a critical role ...
Director, Cyber Security
Campus, IL · On-site
$62.68 - $96.10/hr
The Director, Cyber Security provides strategic leadership, institutional governance, and ... Participates as a leadership team member in different committees. External & Other * Collaborates ...
Director, Cyber Security
Campus, IL · On-site
$62.68 - $96.10/hr
The Director, Cyber Security provides strategic leadership, institutional governance, and ... Participates as a leadership team member in different committees. External & Other * Collaborates ...
Cybersecurity Ops Analyst Senior
Oak Ridge, TN · On-site +1
$95K - $123K/yr
Support purple team exercises by validating alerts, reviewing adversary emulation activity ... cybersecurity operations experience supporting enterprise security monitoring, incident response ...
Cybersecurity Ops Analyst Senior
Oak Ridge, TN · On-site +1
$95K - $123K/yr
Support purple team exercises by validating alerts, reviewing adversary emulation activity ... cybersecurity operations experience supporting enterprise security monitoring, incident response ...
Cybersecurity Ops Analyst Senior
TN · Remote
$102K - $132K/yr
Support purple team exercises by validating alerts, reviewing adversary emulation activity ... cybersecurity operations experience supporting enterprise security monitoring, incident response ...
Cybersecurity Ops Analyst Senior
TN · Remote
$102K - $132K/yr
Support purple team exercises by validating alerts, reviewing adversary emulation activity ... cybersecurity operations experience supporting enterprise security monitoring, incident response ...
Cybersecurity Ops Analyst Senior
$102K - $132K/yr
Support purple team exercises by validating alerts, reviewing adversary emulation activity ... cybersecurity operations experience supporting enterprise security monitoring, incident response ...
Cybersecurity Ops Analyst Senior
$102K - $132K/yr
Support purple team exercises by validating alerts, reviewing adversary emulation activity ... cybersecurity operations experience supporting enterprise security monitoring, incident response ...
Director, Cybersecurity
Cambridge, MA · On-site
We've deliberately built a team that brings diversity of thought to all aspects of our business, to ... We are seeking a Director of Cybersecurity to own the strategy, operation, and governance of ...
Director, Cybersecurity
Cambridge, MA · On-site
We've deliberately built a team that brings diversity of thought to all aspects of our business, to ... We are seeking a Director of Cybersecurity to own the strategy, operation, and governance of ...
... Director, Cybersecurity Business Enablement Engineering. The position is onsite and based in ... Conduct purple team exercises to enhance detection coverage while strengthening incident detection ...
... Director, Cybersecurity Business Enablement Engineering. The position is onsite and based in ... Conduct purple team exercises to enhance detection coverage while strengthening incident detection ...
Director, Cyber Security
Savannah, GA · On-site
$103K - $139K/yr
At WillScot, our team of nearly 5000+ people makes our company a Great Place to Work ® and we ... Reporting to the VP Infrastructure & IT Operations, the Director Cybersecurity is a critical role ...
Director, Cyber Security
Savannah, GA · On-site
$103K - $139K/yr
At WillScot, our team of nearly 5000+ people makes our company a Great Place to Work ® and we ... Reporting to the VP Infrastructure & IT Operations, the Director Cybersecurity is a critical role ...
Director, Cyber Security
Savannah, GA · On-site
$103K - $139K/yr
At WillScot, our team of nearly 5000+ people makes our company a Great Place to Work ® and we ... Reporting to the VP Infrastructure & IT Operations, the Director Cybersecurity is a critical role ...
Director, Cyber Security
Savannah, GA · On-site
$103K - $139K/yr
At WillScot, our team of nearly 5000+ people makes our company a Great Place to Work ® and we ... Reporting to the VP Infrastructure & IT Operations, the Director Cybersecurity is a critical role ...
Director Cybersecurity
Eden Prairie, MN · On-site
$172K - $275K/yr
Develop and lead a high-performing cybersecurity team, including coaching, talent development ... Ability to influence without direct authority and drive action across complex, matrixed, and ...
Quick apply
Director Cybersecurity
Eden Prairie, MN · On-site
$172K - $275K/yr
Develop and lead a high-performing cybersecurity team, including coaching, talent development ... Ability to influence without direct authority and drive action across complex, matrixed, and ...
Cyber Security
Phoenix, AZ · On-site
... experience in cybersecurity engineering, security operations, threat detection, or platform ... Experience conducting security testing, attack simulation, validation, or purple team activities.
Cyber Security
Phoenix, AZ · On-site
... experience in cybersecurity engineering, security operations, threat detection, or platform ... Experience conducting security testing, attack simulation, validation, or purple team activities.
Director Cybersecurity
Manhattan, NY · On-site
$200 - $250/hr
The Director of Cybersecurity is responsible for developing, implementing, and overseeing the ... Team leadership and talent development**Work/Educational Experience*** Must be at least 18 years ...
Director Cybersecurity
Manhattan, NY · On-site
$200 - $250/hr
The Director of Cybersecurity is responsible for developing, implementing, and overseeing the ... Team leadership and talent development**Work/Educational Experience*** Must be at least 18 years ...
... Director, Cybersecurity Business Enablement Engineering. The position is onsite and based in ... Conduct purple team exercises to enhance detection coverage while strengthening incident detection ...
... Director, Cybersecurity Business Enablement Engineering. The position is onsite and based in ... Conduct purple team exercises to enhance detection coverage while strengthening incident detection ...
Red Team Manager
Johnston, RI · On-site
$112K - $152K/yr
... and purple team engagements across traditional and AI augmented environments drive measurable improvements to the organization's security posture. Reporting to Cyber Security leadership, this ...
Red Team Manager
Johnston, RI · On-site
$112K - $152K/yr
... and purple team engagements across traditional and AI augmented environments drive measurable improvements to the organization's security posture. Reporting to Cyber Security leadership, this ...
Director Cyber Security Purple Team information
See salary details
$37K - $48.8K
5% of jobs
$48.8K - $60.6K
6% of jobs
$60.6K - $72.5K
9% of jobs
$81.9K is the 25th percentile. Wages below this are outliers.
$72.5K - $84.3K
5% of jobs
$84.3K - $96.1K
8% of jobs
The median wage is $103.5K / yr.
$96.1K - $107.9K
25% of jobs
$115.6K is the 75th percentile. Wages above this are outliers.
$107.9K - $119.7K
24% of jobs
$119.7K - $131.5K
5% of jobs
$131.5K - $143.4K
5% of jobs
$143.4K - $155.2K
3% of jobs
$155.2K - $167K
3% of jobs
$37K
$104.5K
$167K
How much do director cyber security purple team jobs pay per year?
What does a director cyber security purple team do?
How does a director cyber security purple team typically collaborate with other security teams within an organization?
What are the key skills and qualifications needed to thrive as a director cyber security purple team, and why are they important?
What is the difference between Director Cyber Security Purple Team vs Security Operations Center (SOC) Manager?
| Aspect | Director Cyber Security Purple Team | Security Operations Center (SOC) Manager |
|---|---|---|
| Certifications | CISSP, GIAC, CEH | CISSP, GCIH, Security+ |
| Work Environment | Collaborative, offensive and defensive security testing | Monitoring, incident response, real-time security management |
| Employer & Industry Usage | Used in organizations focusing on proactive security testing | Common in organizations with dedicated security operations teams |
The Director Cyber Security Purple Team focuses on integrating offensive and defensive security strategies through collaborative testing, while the SOC Manager oversees real-time security monitoring and incident response. Both roles require security certifications but differ in their focus areas and daily activities.
What cities are hiring for Director Cyber Security Purple Team jobs?
Cities with the most Director Cyber Security Purple Team job openings:
What are the most commonly searched types of Cyber Security Purple Team jobs?
The most popular types of Cyber Security Purple Team jobs are:
What states have the most Director Cyber Security Purple Team jobs?
States with the most job openings for Director Cyber Security Purple Team jobs include:
Job description
Role overview
The Director, Cybersecurity Operations leads Security Operations and Incident Response, Security Engineering, Vulnerability Management, and Threat Intelligence. This is a player-coach leadership role reporting directly to the CISO, partnering with the Director, Cyber GRC as one unified cyber team. The Director will bring hands-on technical depth, strong leadership capability, and the ability to modernize security operations through MDR deployment, AI-informed detection, and a security engineering team organized around functional specialization.
Key responsibilities
Security operations and incident response Security operations and incident response
-
Own the MDR relationship, including SLA management, escalation accountability, detection tuning, and quarterly threat hunt reviews
-
Lead the incident response function: IR runbooks, major incident coordination, executive communication during active incidents, and post-incident root cause analysis
-
Oversee SOC detection engineering, ensuring SIEM rules, SOAR playbooks, and automated response actions are maintained, tested, and tuned to the current threat landscape
-
Direct and develop the security analyst pool, redeploying analyst capacity from frontline triage toward MDR validation, threat hunt support, and stakeholder reporting
Security engineering
-
Oversee four specialized engineering lanes [endpoint, identity, cloud, and application security], ensuring each lane has clear ownership, defined scope, and measurable outcomes
-
Drive security architecture reviews and engineering decisions for large or complex IT projects, ensuring security requirements are built in rather than bolted on
-
Shape the security tooling stack strategy, evaluating, selecting, and retiring tools across endpoint, identity, cloud, and application security
-
Enforce automation-first engineering practices, including IaC security gates, CI/CD pipeline security, CSPM auto-remediation, and SOAR-driven response workflows
Threat intelligence, vulnerability management, and control validation
-
Lead the operationalization of threat intelligence, translating MDR findings and external threat data into detection rule updates, architecture decisions, and risk register inputs for the GRC team
-
Own the vulnerability management lifecycle: scanning coverage, risk-based prioritization, remediation tracking, and SLA enforcement
-
Own the purple team and control validation program, confirming that deployed controls operate as intended and that detection capabilities fire correctly against known attack techniques
-
Drive threat modeling across the engineering function, identifying attack paths before they are exploited and feeding findings into remediation prioritization
AppSec, cloud, and AI security
-
Oversee the AppSec function: secure SDLC, code review gates, SAST/DAST tooling, and security collaboration with the Product and Engineering teams
-
Own cloud security posture management: CSPM, cloud workload protection, cloud IAM governance, and cloud-native security architecture
-
Set the team-wide AI security posture, overseeing AI security controls across all engineering lanes, including model security, prompt injection testing, and AI tool access governance in partnership with cyber leadership
MDR, automation, and tooling modernization
-
Lead the ongoing maturation of the MDR deployment, expanding coverage, improving response fidelity, and integrating MDR outputs with internal SIEM, IAM, and compliance evidence workflows
-
Champion security automation across the team, reducing manual toil in detection, response, vulnerability tracking, and reporting through SOAR, scripting, and platform integrations
-
Evaluate emerging security technologies and make build/buy/partner recommendations to the CISO with clear business and risk rationale
Team leadership and CISO partnership
-
Lead, develop, and performance-manage a lean engineering team
-
Partner with the Director, Cyber GRC as one unified cyber function, feeding operational threat intelligence into the risk register, supporting compliance evidence for technical controls, and jointly presenting security posture
-
Provide regular metrics and reporting to the CISO on incident trends, control coverage, MDR performance, vulnerability posture, and team development
-
Build a team culture of continuous improvement, automation-first execution, and proactive security, where threat hunting and control validation are protected activities rather than aspirational ones
Qualifications
Experience
-
15+ years of progressive experience in information security, including at least 7 years in a security leadership role
-
Demonstrated ownership of a security operations or engineering function at the Director or equivalent level
-
Experience operating and maturing an MDR deployment (CrowdStrike Falcon Complete, Arctic Wolf, Expel, or equivalent) in a corporate environment
-
Hands-on background in at least two of the following: security engineering, penetration testing/offensive security, cloud security, application security, or incident response; this is not a purely strategic role
-
Demonstrated experience deploying or maturing security automation, such as SOAR playbooks, detection engineering, IaC security, or CI/CD pipeline security
-
Familiarity with cloud-native security (AWS, Azure, or GCP), including CSPM, cloud IAM, and workload protection
Technical knowledge
-
Working knowledge of cybersecurity frameworks such as NIST SP 800-171, ISO 27001, and SOC 2
-
Understanding of the vulnerability management lifecycle: scanning, prioritization, remediation tracking, and SLA enforcement
-
Familiarity with AppSec disciplines: SAST/DAST tooling, secure SDLC, and security gate integration into CI/CD
-
Understanding of IAM security governance (PAM, access review programs, and SSO/MFA architecture) as distinct from IT provisioning execution
-
Experience with AI security considerations (model testing, prompt injection, AI tool access governance, and emerging AI governance frameworks such as the NIST AI RMF and ISO 42001) is a meaningful differentiator
-
Foundational awareness of CMMC requirements
General abilities
-
An exceptional communicator, able to translate complex cyber risk and compliance concepts into clear business language for executives, clients, and regulators alike
-
A natural collaborator and client-facing presence, comfortable leading enterprise client security discussions, representing KLDiscovery in due diligence meetings, and building trust with external stakeholders
-
Business-minded, balancing security requirements against commercial realities and making practical decisions without sacrificing rigor
-
A continuous learner with genuine curiosity, energized by a fast-growing company and a rapidly evolving regulatory and threat landscape
-
Discreet and trusted, exercising sound judgment, maintaining confidentiality, and operating with professionalism
Education
-
Bachelor's degree in Information Security, Computer Science, Engineering, Business, or a related field required
-
Professional certifications such as CISSP, CISM, CISA, GPEN, GCIA, or other GIAC certifications strongly preferred
-
Master's degree or MBA with a security focus preferred
Our mission and core values
We bring clarity, trust, and meaning to data for clients navigating legal matters worldwide.
Client is Always in the Room. We operate and make decisions as if the client is in the room. We anticipate their needs, consider their perspective, and prioritize their best interests.
Better Every Day. We improve our tomorrow by always striving to be better than today. We embrace curiosity, question assumptions, and raise the bar constantly.
Own the Outcome. We bring an unwavering bias for action, act with urgency, and hold ourselves accountable to our clients and each other.
Deliver Results Together. We collaborate obsessively to achieve shared success. We assume good intentions, debate ideas thoughtfully, treat each other with respect, and fully commit once decisions are made.
Our culture shapes our actions, our products, and the relationships we forge with our customers.
About KLDiscovery
Sourced by ZipRecruiter
Company size
1,001 - 5,000 Employees
Headquarters location
McLean, VA, US
Year founded
2005