1

Director Logrhythm Siem Jobs (NOW HIRING)

... SIEM platforms (Splunk, Sentinel, LogRhythm, etc.), EDR suites (CrowdStrike, Defender), and network security tools. • Familiarity with cloud-security architectures (Azure, AWS, Google) and ...

Direct Contractor staff and subcontractors in the execution of NOC or SOC-related responsibilities ... SIEM Tools: Splunk, QRadar, Sentinel, LogRhythm * Firewall/IDS/IPS: Palo Alto, Cisco Firepower ...

New

Reporting to the Director of Technology Operations, this full-time, fiscal-year position is ... SIEM platforms (e.g., Splunk, LogRhythm) to detect and mitigate threats. * Advanced System ...

Director Logrhythm Siem information

What cities are hiring for Director Logrhythm Siem jobs? Cities with the most Director Logrhythm Siem job openings:
What are the most commonly searched types of Logrhythm Siem jobs? The most popular types of Logrhythm Siem jobs are:
What states have the most Director Logrhythm Siem jobs? States with the most job openings for Director Logrhythm Siem jobs include:
Infographic showing various Director Logrhythm Siem job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 83% Full Time, 14% Part Time, 1% Temporary, and 1% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution.

Director I, Security Operations

NEOGOV

La Plata, MD • On-site

Full-time

Re-posted 18 days ago


Job description

Job Summary:
The College of Southern Maryland (CSM) is a two-time Aspen Award-winning institution committed to student success. The Security Operations Director is responsible for leading the College's cybersecurity program, overseeing the Security Operations Center, and collaborating with various stakeholders to enhance the institution's security posture.
Responsibilities:
• Design, implement, and manage a 24 × 7 security monitoring capability (internal or managed service).
• Administer and optimize SIEM, EDR, IDS/IPS, firewalls, and log-aggregation platforms.
• Assist with the development, maintenance, and enforcement of security operating procedures (SOPs), runbooks, and escalation workflows.
• Serve as the Incident Commander for cybersecurity events, coordinating containment, eradication, and recovery.
• Conduct post-incident reviews and root-cause analyses; recommend and track remediation activities.
• Maintain and routinely test the Cybersecurity Incident Response Plan and its integration with Business Continuity/Disaster Recovery plans.
• Collect, analyze, and operationalize threat intelligence relevant to higher education from MS-ISAC, REN-ISAC, CISA, and commercial feeds.
• Perform proactive threat hunting and coordinate purple-team exercises to validate controls.
• Correlate intelligence with internal telemetry to identify and mitigate emerging threats.
• Manage enterprise vulnerability scanning, penetration tests, and remediation tracking.
• Oversee secure configuration baselines using CIS Benchmarks and ensure adherence through continuous monitoring.
• Evaluate patch management effectiveness and manage risk-exception processes.
• Align security operations with NIST CSF, NIST 800-171, GLBA, FERPA, PCI-DSS, and state regulations.
• Contribute to annual risk assessments, audits, and security metrics; report on program maturity and gaps.
• Maintain evidence repositories and support external audit and accreditation activities.
• Assess emerging security technologies and recommend solutions to enhance the College’s security posture.
• Lead proofs-of-concept, integrations, and lifecycle management for new security tools.
• Coordinate campus-wide security awareness campaigns and phishing simulations.
• Deliver targeted training to IT staff, faculty researchers, and executive leadership.
• Evaluate security controls of vendors, cloud services, and research partners.
• Enforce contractual security requirements and review SOC 2, ISO 27001, and penetration-test reports.
• Develop and manage the annual security operations budget.
• Track software licenses, maintenance contracts, and renewal schedules for security tools.
• Prepare executive reports, board briefings, and compliance submissions.
• Maintain detailed incident logs, investigative evidence, and knowledge-base articles.
• Performs other related duties as assigned.
Qualifications:
Required:
• Five (5)+ years of progressive experience in security operations, incident response, or SOC management; three (3)+ years in a supervisory or lead role.
• Demonstrated experience deploying and managing SIEM, EDR, IDS/IPS, firewalls, and cloud-security controls (e.g., Microsoft 365/Azure Security Center, AWS Security Hub).
• Hands-on experience with log analysis, scripting (PowerShell, Python, Bash), packet capture, and forensic tooling.
• Experience interpreting and implementing NIST CSF/800-171, FERPA, GLBA, and/or PCI-DSS controls.
• Proven ability to develop policies, procedures, and security awareness programs.
• Deep knowledge of security operations frameworks, incident handling methodologies, and forensic techniques.
• Proficiency with SIEM platforms (Splunk, Sentinel, LogRhythm, etc.), EDR suites (CrowdStrike, Defender), and network security tools.
• Familiarity with cloud-security architectures (Azure, AWS, Google) and Kubernetes/Container security.
• Ability to conduct risk assessments, develop mitigation strategies, and present technical concepts to non-technical stakeholders.
• Strong leadership, team-building, and mentoring abilities; adept at managing cross-functional incident response teams.
• Excellent written and oral communication, analytical, and customer-service skills.
• Ability to plan and execute multiple, complex projects concurrently and adapt quickly to changing threat landscapes.
Preferred:
• Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field preferred.
• Master’s degree in Cybersecurity, Information Assurance, or Technology Management.
• Higher education or public-sector experience with research data protections (e.g., CUI, ITAR).
• Experience integrating security controls into DevOps or cloud-native environments.
• CISSP, CISM, GIAC-certified (e.g., GCIH, GCIA, GCFA), or equivalent (preferred).
• ITIL Foundations or PMP for program/process management is a plus.
Company:
NEOGOV is the leading provider of workforce management software uniquely designed for the public sector, education, and public safety. Founded in 1999, the company is headquartered in El Segundo, USA, with a team of 501-1000 employees. The company is currently Late Stage.