1

Director Security Operations Center Jobs in Raleigh, NC

Security Operations Center (SOC) Manager Durham, NC The Senior Manager, Security Operations (SOC), will lead Incident Handlers and Incident Responders while playing a key role in evolving Labcorp ...

Security Operations Center (SOC) Manager Durham, NC The Senior Manager, Security Operations (SOC), will lead Incident Handlers and Incident Responders while playing a key role in evolving Labcorp ...

Senior Director, Security Operations Role Overview The Manager, Security Operations is responsible for the operational delivery, governance, and assurance of cybersecurity services provided to ...

The role involves providing 24/7 monitoring and analysis of security event alerts, identifying potential security threats, and documenting incidents within a Security Operations Center environment.

We put them at the center of everything we do and empower them to grow, explore new possibilities ... The Opportunity We are seeking an experienced Data Security Operations Lead to spearhead our ...

next page

Showing results 1-20

Director Security Operations Center information

See Raleigh, NC salary details

$33.1K

$104.7K

$174.5K

How much do director security operations center jobs pay per year?

As of May 30, 2026, the average yearly pay for director security operations center in Raleigh, NC is $104,674.00, according to ZipRecruiter salary data. Most workers in this role earn between $73,400.00 and $131,700.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Director Security Operations Center, and why are they important?

To thrive as a Director Security Operations Center, you need deep expertise in cybersecurity, threat management, incident response, and a relevant degree or certifications such as CISSP or CISM. Familiarity with SIEM platforms, intrusion detection systems, and security automation tools is typically required. Leadership, strategic thinking, and strong communication skills set exceptional candidates apart in this role. These skills are vital for effectively managing teams, protecting organizational assets, and ensuring a rapid and coordinated response to security threats.

What are the main challenges faced by a Director of Security Operations Center in managing complex security incidents?

A Director of Security Operations Center often faces the challenge of responding quickly and effectively to sophisticated cyber threats while ensuring coordination across multiple teams. Balancing the need for immediate action with thorough incident analysis can be demanding, especially in high-pressure situations. Additionally, keeping the team motivated and updated with the latest tools and protocols, while managing resource constraints and compliance requirements, requires strong leadership and communication skills.

What does a Director of Security Operations Center do?

A Director of Security Operations Center (SOC) oversees the team and processes responsible for monitoring, detecting, and responding to cybersecurity threats within an organization. They set strategic direction for the SOC, manage incident response, ensure compliance with security standards, and coordinate with other departments to protect company assets. The role also involves leading staff, optimizing technologies, and developing policies to improve the organization's overall security posture.

What is the difference between Director Security Operations Center vs Security Operations Manager?

AspectDirector Security Operations CenterSecurity Operations Manager
CertificationsCISSP, CISM, GIAC certificationsCISSP, Security+
Work EnvironmentOversees entire SOC, strategic planningManages daily security operations, team supervision
ResponsibilitiesSets security policies, directs incident responseMonitors security alerts, manages security staff

The Director Security Operations Center focuses on strategic leadership and policy development for the SOC, while the Security Operations Manager handles daily operations and team management. Both roles require relevant certifications and work within the same industry environment, but differ in scope and level of responsibility.

What are the most commonly searched types of Security Operations Center jobs in Raleigh, NC? The most popular types of Security Operations Center jobs in Raleigh, NC are:
What are popular job titles related to Director Security Operations Center jobs in Raleigh, NC? For Director Security Operations Center jobs in Raleigh, NC, the most frequently searched job titles are:
What job categories do people searching Director Security Operations Center jobs in Raleigh, NC look for? The top searched job categories for Director Security Operations Center jobs in Raleigh, NC are:
What cities near Raleigh, NC are hiring for Director Security Operations Center jobs? Cities near Raleigh, NC with the most Director Security Operations Center job openings:
Director, Security Operations Center

Director, Security Operations Center

First Citizens Bank

Raleigh, NC • On-site

Full-time

Posted 20 days ago


First Citizens Bank rating

7.6

Company rating: 7.6 out of 10

Based on 102 frontline employees who took The Breakroom Quiz

80th of 141 rated banks


Job description

Overview

The Director, Security Operations Center (SOC) leads a 24/7/365 physical security operations function responsible for enterprise-wide situational awareness, threat detection, incident triage and dispatch, crisis coordination, and executive/business traveler support. In partnership with the Security Center of Excellence (CoE), the Director defines the SOC strategy and co-develops objectives, a multiyear roadmap, and business continuity goals aligned with enterprise security priorities and global regulatory obligations—while building highperforming teams, operationalizing intelligence, and ensuring resilient monitoring and response across access control, alarms, video surveillance, and mass notification platforms.


Responsibilities

Leadership & Strategy 

  • Partner with the Security Center of Excellence (CoE) to define the SOC vision and codevelop the objectives, multiyear roadmap, and business continuity goals, aligned with enterprise security priorities.
  • Build and lead a highperforming team composed of internal staff and a contracted workforce of analysts, dispatchers, and incident managers, fostering a culture of accountability, psychological safety, and continuous improvement.
  • Work with the CoE to assist in the RFP process for a new SOC contractor—including requirements definition, SLAs and KPIs, evaluation criteria and scoring, vendor due diligence, and transition/onboarding planning.
  • Define the SOC operating model (tiering, roles, SLAs, RACI) and maintain robust SOPs, playbooks, communication and escalation paths for differing threat scenarios (life safety, workplace violence, protests, theft, natural disasters, geopolitical disruptions, supply chain incidents, and executive protection support).
  • Manage the security vendor’s performance through compliance with contract requirements, key performance indicators, service level agreements (SLA), and defined measures.
  • Champion security convergence with IT/Cyber, EHS, Legal, HR, Comms, and Facilities to ensure cohesive response and a unified risk posture.
  • Work with Regional Security Coordinators (RSCs), the Security Center of Excellence (CoE), and Technology to maintain relationships with public safety, guarding providers, systems integrators, and external monitoring partners. 
  • Maintain the contracted SOC security vendor business relationship.
Threat Detection & Incident Response 
  • Oversee continuous monitoring of alarms, access control events, video surveillance, duress/perimeter systems, environmental sensors, and open-source/geospatial intelligence feeds.
  • Ensure timely triage, verification (e.g., video confirmation), dispatch, escalation, and documentation for incidents, with clear criteria by severity and asset class.
  • Direct crisis activation from the SOC (incident command support), including mass notification, stakeholder communications, incident logging, and after-action reviews.
  • Support executive protection and travel risk operations—including pre-travel advisories, active monitoring, route/venue risk checks, real-time alerting, and monitoring of executives’ residences (in coordination with Residential Security and in compliance with privacy requirements).
  • Maintain a “detect to protect” approach—minimizing false alarms while improving signal fidelity and time to action.
Operations & Performance

Establish, track, and publish performance metrics and SLAs, including:

  • Time to Acknowledge (TTA), Time to Triage (TTT), Time to Dispatch (TTDsp), Time to Resolution (TTR)
  • False alarm rate, verification rate, SOP adherence rate, QA score per shift
  • Case closure timeliness and documentation completeness
  • System availability for critical monitoring platforms
  • Drive workflow optimization and automation (orchestrated workflows, case management, playbook automation, event correlation).
  • Manage budgets, staffing models, vendor SLAs, and capacity planning; build a resilient staffing plan (supervisors, leads, tiered analysts) for 24/7 coverage.
  • Ensure a disciplined quality program (call handling standards, evidence handling, report writing, and professional conduct).
Threat Intelligence & Risk Management 
  • Integrate internal and external intelligence (OSINT/geopolitical/crime/weather/infrastructure disruptions) into daily operations, situational awareness dashboards, and decision support.
  • Work with Executive Protection, Regional Security Directors, and the Security Center of Excellence (CoE) to establish and continuously monitor risk profiles for facilities, routes, events, and executives, and to set thresholds for proactive posture changes (e.g., guard posture, access control changes, camera presets).
  • Collaborate with Enterprise Risk, Compliance, Legal/Privacy, and Business Continuity to mitigate emergent risks and ensure consistent risk reporting.
  • Support vulnerability management and physical security assessments, feeding remediation priorities into the roadmap.
  • Brief executives during significant incidents and produce daily/weekly intel summaries.
Technology & Systems 
  • Partner with the Technology organization (under the CoE) to define operational requirements and support the development, deployment, and continuous improvement of new systems and integrations.
  • During system implementations, ensure uninterrupted SOC operations—while identifying any gaps or items that need to be rectified as the migration proceeds, and track them to closure in partnership with Technology and the CoE.
  • Define SOC use cases, data flows, integrations, and SLAs; lead user acceptance testing, change management, training, and adoption for new systems and workflows.
  • Specify operational resilience requirements (redundancy, failover, disaster recovery) and participate alongside Technology in tabletop and live failover testing to validate SOC readiness.
  • Maintain clean configuration standards and operational documentation for SOC tools and playbooks; ensure alignment with enterprise architecture and data governance led by Technology.
Compliance, Privacy & Governance
  • Ensure operations comply with applicable laws and policies related to surveillance, audio/video recording, personal data retention, and cross-border data transfers.
  • Maintain documentation for audits and uphold standards (e.g., ASIS best practices, NIMS/ICS usage, privacy-by-design for monitoring).
  • Enforce evidence handling, chain-of-custody, and secure data management.

Qualifications

Bachelor's Degree and 10 years of experience in Retail Bank or Corporate Security, including management OR High School Diploma or GED and 14 years of experience in Retail Bank or Corporate Security, including management

Preferred Skills:

  • 10+ years in physical security operations with 5+ years leading a SOC/PSOC or equivalent 24/7 command center at scale.
  • Demonstrated experience with alarm monitoring, access control, video management/CCTV, incident management, mass notification, and case management platforms.
  • Proven crisis leadership under time pressure with excellent judgment, communication, and stakeholder management.
  • Experience managing guard force providers, systems integrators, and technology vendors with strict SLAs.
  • Strong data-driven operations mindset (SLAs, KPIs, dashboards, QA programs).
  • Knowledge of national and global privacy/recording considerations and evidence handling standards.
  • Familiarity with NIMS/ICS and coordination with public safety.
  • Professional certifications: ASIS CPP, PSP, or CEM (Emergency Management); ITIL a plus.
  • Experience with security convergence (IT/OT/Cyber) and cross-functional incident management.
  • Global operations experience across multiple regions and regulatory environments.

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Qualifications:

Bachelor's Degree and 10 years of experience in Retail Bank or Corporate Security, including management OR High School Diploma or GED and 14 years of experience in Retail Bank or Corporate Security, including management

Preferred Skills:

  • 10+ years in physical security operations with 5+ years leading a SOC/PSOC or equivalent 24/7 command center at scale.
  • Demonstrated experience with alarm monitoring, access control, video management/CCTV, incident management, mass notification, and case management platforms.
  • Proven crisis leadership under time pressure with excellent judgment, communication, and stakeholder management.
  • Experience managing guard force providers, systems integrators, and technology vendors with strict SLAs.
  • Strong data-driven operations mindset (SLAs, KPIs, dashboards, QA programs).
  • Knowledge of national and global privacy/recording considerations and evidence handling standards.
  • Familiarity with NIMS/ICS and coordination with public safety.
  • Professional certifications: ASIS CPP, PSP, or CEM (Emergency Management); ITIL a plus.
  • Experience with security convergence (IT/OT/Cyber) and cross-functional incident management.
  • Global operations experience across multiple regions and regulatory environments.

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Education:UNAVAILABLEEmployment Type: FULL_TIME

What First Citizens Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom