We are looking for an experienced security leader to direct and strengthen the organization’s security operations capability in Massachusetts. This position combines strategic oversight with hands-on technical execution, guiding a team while actively improving detection, response, and monitoring practices. The role is central to maintaining resilient operations in a highly regulated environment where timely, accurate security decisions carry significant operational and compliance impact.
Responsibilities:
• Lead the daily operation and long-term development of the security operations program, ensuring strong visibility, response readiness, and measurable performance across the environment.
• Manage the security operations technology portfolio, including budgeting, vendor relationships, service quality oversight, and roadmap planning for critical tools and platforms.
• Oversee a blended monitoring model by directing internal analysts and coordinating with a 24/7 managed detection partner to maintain service levels, escalation effectiveness, and comprehensive coverage.
• Build and refine detection capabilities through rule creation, alert tuning, telemetry onboarding, and structured mapping of coverage against recognized threat frameworks.
• Direct incident response activities from initial triage through containment, investigation, recovery, and post-incident improvement, while partnering with legal, executive, and external response stakeholders as needed.
• Drive proactive threat hunting initiatives and convert threat intelligence into actionable detections, investigation methods, and operational improvements.
• Expand automation and orchestration within security operations by developing repeatable workflows, response playbooks, and investigation runbooks that improve speed and consistency.
• Partner with manufacturing, engineering, and OT stakeholders to strengthen monitoring and response coverage for operational technology environments and related telemetry sources.
• Mentor and develop security engineers and analysts by providing technical guidance, performance coaching, and opportunities for growth within the team.• 10+ years of experience in security operations, incident response, detection engineering, or a related cybersecurity discipline.
• 2+ years of experience leading technical security teams, with a track record of coaching, developing, and managing high-performing professionals.
• Strong hands-on expertise in SIEM, detection engineering, incident investigation, and operational security tooling.
• Demonstrated experience managing a managed detection or co-managed security operations relationship with accountability for outcomes and service quality.
• Proven ability to lead incident response efforts across the full lifecycle and communicate effectively with technical teams, executives, legal partners, and external stakeholders.
• Solid understanding of network security, enterprise security, application security, and structured detection methodologies such as ATT& CK-based coverage models.
• Experience working in regulated or compliance-driven environments; exposure to defense, manufacturing, critical infrastructure, or OT security settings is strongly preferred.
• Excellent written and verbal communication skills, including the ability to present technical risk clearly to senior leadership and board-level audiences.