1

Director Security Operations Center Jobs in Colorado

Director: Security

Fountain, CO ยท On-site

$281 - $355/hr

... operations. Responsibilities * Lead the development and execution of comprehensive security ... Direct the evaluation, deployment, and management of security technologies and tools. * Foster a ...

Partner with the Security Operations Center (SOC) and Managed Security Service Providers (MSSPs) to improve alert quality, detection coverage, and response processes. * Develop, maintain, and enhance ...

Partner with the Security Operations Center (SOC) and Managed Security Service Providers (MSSPs) to improve alert quality, detection coverage, and response processes. * Develop, maintain, and enhance ...

next page

Showing results 1-20

Director Security Operations Center information

What are the main challenges faced by a director security operations center in managing complex security incidents?

A Director of Security Operations Center often faces the challenge of responding quickly and effectively to sophisticated cyber threats while ensuring coordination across multiple teams. Balancing the need for immediate action with thorough incident analysis can be demanding, especially in high-pressure situations. Additionally, keeping the team motivated and updated with the latest tools and protocols, while managing resource constraints and compliance requirements, requires strong leadership and communication skills.

What does a director security operations center do?

A Director of Security Operations Center (SOC) oversees the team and processes responsible for monitoring, detecting, and responding to cybersecurity threats within an organization. They set strategic direction for the SOC, manage incident response, ensure compliance with security standards, and coordinate with other departments to protect company assets. The role also involves leading staff, optimizing technologies, and developing policies to improve the organization's overall security posture.

What are the key skills and qualifications needed to thrive as a director security operations center, and why are they important?

To thrive as a Director Security Operations Center, you need deep expertise in cybersecurity, threat management, incident response, and a relevant degree or certifications such as CISSP or CISM. Familiarity with SIEM platforms, intrusion detection systems, and security automation tools is typically required. Leadership, strategic thinking, and strong communication skills set exceptional candidates apart in this role. These skills are vital for effectively managing teams, protecting organizational assets, and ensuring a rapid and coordinated response to security threats.

What is the difference between Director Security Operations Center vs Security Operations Manager?

AspectDirector Security Operations CenterSecurity Operations Manager
CertificationsCISSP, CISM, GIAC certificationsCISSP, Security+
Work EnvironmentOversees entire SOC, strategic planningManages daily security operations, team supervision
ResponsibilitiesSets security policies, directs incident responseMonitors security alerts, manages security staff

The Director Security Operations Center focuses on strategic leadership and policy development for the SOC, while the Security Operations Manager handles daily operations and team management. Both roles require relevant certifications and work within the same industry environment, but differ in scope and level of responsibility.

What are the most commonly searched types of Security Operations Center jobs in Colorado?

The most popular types of Security Operations Center jobs in Colorado are:

What are popular job titles related to Director Security Operations Center jobs in Colorado?

For Director Security Operations Center jobs in Colorado, the most frequently searched job titles are:

What job categories do people searching Director Security Operations Center jobs in Colorado look for?

The top searched job categories for Director Security Operations Center jobs in Colorado are:

What cities in Colorado are hiring for Director Security Operations Center jobs?

Cities in Colorado with the most Director Security Operations Center job openings:

Director, Security Operations -- Cipher Digital

The Bitcoin Street Journal

Denver, CO โ€ข On-site

$180 - $280/hr

Other

Medical, Dental, Vision, Life, Retirement

Posted 11 days ago


Job description

We are an industrial-scale data center construction and operations company. We allocate data center opportunities between bitcoin mining and other high performance computing services, such as AI. We continue to develop our pipeline of power capacity at high quality data center sites, either for bitcoin mining or HPC. Our best-in-class management team leverages expertise from the technology, fintech, energy, and finance domains, as well as deep experience related to cryptocurrencies and blockchain.

Position Overview

Cipher Digital (NASDAQ: CIFR) is building the physical infrastructure the AI era runs on. In little over a year, we have gone from one of the largest Bitcoin miners in the US to a hyperscale HPC and AI data center developer, with a multi-gigawatt pipeline across Texas and Ohio powering the compute behind the worldโ€™s leading AI platforms.

It is one of the fastest pivots the data center industry has seen, and everyone building it has a stake in what comes next. Securing that infrastructure is a founding opportunity, and this is a greenfield role. You will stand up Security Operations as a function, build out managed detection and response, and own how Cipher detects, responds to, and recovers from security incidents across IT, OT, cloud, and tenant environments.

Security at Cipher is organized around clear ownership: security governance sets the policy and standards, security engineering builds the controls and the platform, and security operations runs and defends them. You own that third part: you maintain the posture, coordinate the managed detection and response function, and make sure the whole business is ready to respond. We own these functions; how we deliver them, whether by hiring, contracting, or subcontracting, is a deliberate choice we make in line with our regulatory and contractual requirements.

This is a leadership role for someone who has been in the room for major incidents and knows how to command them: you run a multi-party response across regions and time zones and get the right people in the right room when it matters. When an incident hits, you are the quarterback: you coordinate the whole business into one response, hold the line on Cipherโ€™s security policy, and drive an outcome that meets or beats our contractual and regulatory obligations.

Key Responsibilities Security Operations and 24ร—7 Monitoring
  • Stand up and own security monitoring and detection across IT, OT, cloud, and tenant-boundary traffic. Cipher owns the function and controls its own detection content.
  • Maintain the security posture the organization defines, operating the security tooling the engineering team builds.
  • Own the metrics that prove coverage (time to acknowledge, time to respond) and the detection coverage map against recognized adversary frameworks for both IT and I&CS.
  • Partner with security engineering on the detection handoff: they build detection-as-code, you operationalize and run it.
Incident Response Leadership & Automation
  • Build the incident response plan into a tested, audit-defensible capability and own it end to end. Define the response operating model, escalation paths, and the responsibility map across Cipher, tenants, and vendors.
  • Coordinate the response across peer functions, Data Center Operations, Physical Security,GRC, Security Engineering, IT, and Networking. Set the interface and handoff with each ahead of an incident, so a live response runs to plan and meets or exceeds Cipherโ€™s notification timelines.
  • Leverage modern Security Orchestration, Automation, and Response (SOAR) capabilities to automate containment, enrich alerts, and reduce manual analyst fatigue. Empower the SOC to continuously build and refine visual playbooks to streamline response.
  • Lead live incident response, including multi-party incidents that cross regions, tenants, and time zones.
  • Author and sign joint incident-response run books with tenants and partners ahead of go-live, meeting or exceeding contractual notification timelines.
  • Run regular security drills across IT and OT and feed the lessons back into the plan.
Detection and Response Delivery
  • Own detection and response delivery end to end. Where we contract or subcontract, select and manage the providers, enforce SLAs with financial credits on miss, and hold them accountable to delivery and transparency.
  • Drive consolidation and reduce concentration risk so detection and response do not rest on a single provider.
  • Coordinate the function so it operates as an extension of Cipher, not a black box, regardless of who delivers it.
Vulnerability and Posture Management
  • Run the vulnerability management program as a shared lifecycle: GRC defines the policy, risk tolerance, and severity model; security engineering implements the scanning and remediation tooling; operations maintains the program and responds. You own the cadence, the enforced remediation SLAs, and the reporting, with risk-based prioritization rather than raw scores.
  • Keep the three functions feeding each other: surface what you see in operation back to GRC and engineering so the policy and the tooling sharpen, rather than each working in isolation.
  • Maintain continuous awareness of the attack surface as the footprint scales across sites and tenants.
Team Leadership and Reporting
  • Build and lead the Security Operations function, growing capability as the footprint scales.
  • Communicate operational posture, incident readiness, and response outcomes clearly to theCISO and executive leadership.
  • Make security a capability the whole business shares: educate teams, run exercises, and help them respond well. Be a partner, not a blocker.
Qualifications And Experience
  • Deep experience leading security operations or incident response, including time spent running major incidents under real pressure. Operations as a lived discipline, not a recent addition to a broader role.
  • Demonstrated command of multi-party, multi-region incident response, with strong stakeholder communication under pressure.
  • Experience standing up and running detection and response, including managing providers and subcontracted services with SLA negotiation and enforcement.
  • Strong knowledge of SOC operations, SIEM, EDR, SOAR, and detection engineering, and how they combine into effective detection and response.
  • OT/ICS incident response or critical-infrastructure operational exposure is a strong plus.
  • Familiarity with SOC 2, ISO 27001, NIST 800-53, SOX, and partner notification obligations as they shape operational evidence and timelines.
  • Relevant certifications (CISSP, GIAC such as GCIH or GCIA, CISM) strongly preferred.
Key Skills And Competencies
  • Incident Response Leadership
  • Security Operations & SOAR
  • Detection and Response Delivery
  • Vulnerability Management
  • Cross-functional Command
  • Ownership and Bias for Action
  • 401K Retirement Plan with match
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • And other perks!
  • Full Time Employees
#J-18808-Ljbffr