1

Director Security Operations Center Jobs in Washington

next page

Showing results 1-20

Director Security Operations Center information

What does a director security operations center do?

A Director of Security Operations Center (SOC) oversees the team and processes responsible for monitoring, detecting, and responding to cybersecurity threats within an organization. They set strategic direction for the SOC, manage incident response, ensure compliance with security standards, and coordinate with other departments to protect company assets. The role also involves leading staff, optimizing technologies, and developing policies to improve the organization's overall security posture.

What are the main challenges faced by a director security operations center in managing complex security incidents?

A Director of Security Operations Center often faces the challenge of responding quickly and effectively to sophisticated cyber threats while ensuring coordination across multiple teams. Balancing the need for immediate action with thorough incident analysis can be demanding, especially in high-pressure situations. Additionally, keeping the team motivated and updated with the latest tools and protocols, while managing resource constraints and compliance requirements, requires strong leadership and communication skills.

What are the key skills and qualifications needed to thrive as a director security operations center, and why are they important?

To thrive as a Director Security Operations Center, you need deep expertise in cybersecurity, threat management, incident response, and a relevant degree or certifications such as CISSP or CISM. Familiarity with SIEM platforms, intrusion detection systems, and security automation tools is typically required. Leadership, strategic thinking, and strong communication skills set exceptional candidates apart in this role. These skills are vital for effectively managing teams, protecting organizational assets, and ensuring a rapid and coordinated response to security threats.

What is the difference between Director Security Operations Center vs Security Operations Manager?

AspectDirector Security Operations CenterSecurity Operations Manager
CertificationsCISSP, CISM, GIAC certificationsCISSP, Security+
Work EnvironmentOversees entire SOC, strategic planningManages daily security operations, team supervision
ResponsibilitiesSets security policies, directs incident responseMonitors security alerts, manages security staff

The Director Security Operations Center focuses on strategic leadership and policy development for the SOC, while the Security Operations Manager handles daily operations and team management. Both roles require relevant certifications and work within the same industry environment, but differ in scope and level of responsibility.

What are the most commonly searched types of Security Operations Center jobs in Washington?

The most popular types of Security Operations Center jobs in Washington are:

What are popular job titles related to Director Security Operations Center jobs in Washington?

For Director Security Operations Center jobs in Washington, the most frequently searched job titles are:

What job categories do people searching Director Security Operations Center jobs in Washington look for?

The top searched job categories for Director Security Operations Center jobs in Washington are:

What cities in Washington are hiring for Director Security Operations Center jobs?

Cities in Washington with the most Director Security Operations Center job openings:

Infographic showing various Director Security Operations Center job openings in Washington as of August 2026, with employment types broken down into 1% As Needed, 80% Full Time, 9% Part Time, 3% Temporary, 6% Contract, and 1% Nights. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution.

Director, Security Operations

Fairfax, VA โ€ข On-site

$180K - $250K/yr

Other

Posted 3 days ago

New


Job description

Job Description
Everforth ECS is seeking a Director of Security Operations to work remotely .
At Everforth ECS, we solve complex cybersecurity and technology challenges for commercial, government, defense, and intelligence customers.
We are seeking a Director of Security Operations to lead the people, processes, and operational disciplines that support our managed cybersecurity services. This leader will be accountable for effective security monitoring, threat detection, investigation, incident response, and continuous improvement across customer and enterprise environments.
This is a senior operational leadership role that combines security operations strategy, people leadership, customer engagement, and hands-on oversight. The Director will lead SOC analysts and detection engineers and partner closely with Security Engineering, the Project Management Office, customer teams, and enterprise stakeholders to deliver consistent, high-quality security outcomes.
Responsibilities
  • Lead, develop, and mentor a high-performing team of SOC analysts, detection engineers, red team operators, cyber threat intelligence anlaysts, and exposure management analysts.
  • Define the security operations strategy, operating standards, service model, and capability roadmap.
  • Oversee day-to-day monitoring, alert triage, investigation, escalation, and response activities across customer and enterprise environments.
  • Serve as the senior operational leader during major security incidents, coordinating investigation, containment, recovery, and executive and customer communications.
  • Lead the detection engineering program, including detection development, validation, tuning, coverage assessment, and lifecycle management.
  • Integrate cyber threat intelligence and threat hunting into SOC operations to improve detection, investigative context, and proactive defense.
  • Establish clear standards for alert analysis, case documentation, escalation quality, quality assurance, and operational reporting.
  • Identify and implement practical applications of AI across security operations to accelerate triage and investigation, improve analytical quality, automate repeatable workflows, and enhance service scalability while maintaining appropriate human oversight.
  • Develop and maintain operating procedures, investigation playbooks, escalation criteria, and incident response processes.
  • Work directly with customers and enterprise stakeholders to understand priorities, communicate risk, explain operational decisions, and resolve service concerns.
  • Partner with Security Engineering and IT teams to ensure security platforms, telemetry, integrations, and automation reliably support SOC requirements.
  • Manage operational priorities, staffing, hiring, performance, professional development, on-call coverage, and service delivery risk.
  • Support solution development, operational proposals, service transitions, and strategic customer engagements.
Salary Range: $180,000-$250,000
General Description of Benefit
Required Skills
  • 15+ years of experience in cybersecurity, security operations, incident response, detection engineering, threat intelligence, or a related discipline.
  • 5+ years of experience leading cybersecurity or security operations teams. Preference will be given to applicants who have led large SOC, MDR, or multi-customer security operations teams at the Director level or above.
  • Deep understanding of SOC operations, including monitoring, alert triage, investigation, escalation, incident response, threat hunting, and continuous improvement.
  • Demonstrated experience leading complex security incidents and coordinating technical, business, customer, and executive stakeholders through response and recovery.
  • Strong knowledge of detection engineering practices, including use-case development, detection validation, tuning, coverage analysis, and MITRE ATT&CK mapping.
  • Experience integrating cyber threat intelligence and adversary tradecraft into detection, hunting, investigation, and response activities.
  • Strong operational understanding of SIEM, EDR/XDR, identity, network, cloud, email, and other security telemetry used for detection and investigation.
  • Experience establishing SOC operating procedures, playbooks, escalation criteria, quality standards, and governance practices.
  • Experience defining and using security operations metrics to manage workload, service quality, detection effectiveness, response performance, and operational risk.
  • Proven ability to build, mentor, and lead high-performing security operations teams in demanding environments.
  • Strong ability to translate business, threat, and risk priorities into security operations priorities and execution plans.
  • Strong communication and customer-facing skills, with the ability to explain incidents, operational performance, and technical risk to analysts, technical leaders, executives, and customers.
  • Sound operational judgment, including the ability to make timely decisions under pressure, manage competing priorities, and balance risk, evidence, customer impact, and service commitments.

Desired Skills
  • Experience leading security operations within a managed security services, managed detection and response, enterprise SOC, or other multi-customer service environment.
  • Demonstrated success building, modernizing, or maturing a SOC while maintaining service continuity and operational performance.
  • Demonstrated understanding of how AI can be applied to security operations, including alert triage, investigation support, analytical quality assurance, knowledge management, reporting, and workflow acceleration.
  • Experience using SOAR platforms and operational automation to improve consistency, speed, and analyst effectiveness.
  • Experience operating security monitoring and incident response capabilities across public cloud and hybrid enterprise environments.
  • Experience establishing quality assurance, case review, and continuous improvement programs for security operations.
  • Experience managing service-level commitments, operational risk, and customer expectations in a managed services environment.
  • Experience managing relationships with security technology vendors, intelligence providers, and operational partners.
  • Demonstrated ability to lead teams successfully through organizational, process, or operational change.
  • CISSP, GCIH, GCIA, or comparable advanced cybersecurity certification preferred.