Job Description
Constellation Search Group is looking for a Director of Security for a full time direct hire opportunity. In this role, you will drive the integration and optimization of SOCaaS operations by designing, standardizing, and continuously refining end-to-end processes. Your focus will be on developing robust workflows for threat monitoring, incident response, and remediation, while ensuring compliance with critical standards such as HIPAA, SOC 2, GDPR, and FedRAMP. You will also manage vendor relationships and operational tools to support seamless data collection and coordinated response efforts.
Experience:
- Process Design: Develop, document, and standardize processes for SOCaaS operations to create efficient, repeatable workflows across threat monitoring, incident response, and remediation.
- Incident Management: Define and continually improve incident response procedures to ensure rapid, policy-driven actions and clear communication during security events.
Regulatory & Compliance Integration: Embed compliance checkpoints and automated controls within the SOC framework to consistently meet and exceed industry standards. - Tool & Vendor Management: Oversee the integration and management of key tools and vendors, ensuring effective data collection, alert triage, and coordinated responses.
- Operational Metrics & Reporting: Establish key performance indicators and reporting routines to monitor SOCaaS effectiveness, driving continuous improvement and maintaining customer trust.
- Enterprise Risk Management: Develop and govern a risk management framework that combines policy oversight with proactive risk mitigation strategies.
- Collaboration & Training: Work closely with IT, engineering, and executive leadership to align SOCaaS processes with broader business objectives, and implement ongoing training to ensure all teams are proficient in operational procedures.
Executive Engagement: Partner with leadership to integrate security policies and processes with the company's strategic goals, ensuring that operational decisions support overall business success. - Stakeholder Education & Assurance: Develop continuous training and comprehensive process documentation to foster a security-first culture, and establish transparent procedures for third-party risk assessments to reassure clients and partners about the organization's security posture.
Qualifications/Skills: - Minimum of 5 years of business experience in IT security, risk management, or information security.
- Proven executive-level business and technical acumen.
- Skilled at developing security strategies
- Deep understanding of security and writing policy/procedure around vulnerabilities, IAM, DevSecOps, Software Access, PenTesting results
- Needs to understand MDR tools and/or operationalized a SOCaaS monitoring tool
- Strong grasp of core security concepts and technologies.
Benefits : A competitive benefits package is provided.
Salary Disclaimer: Salary range is commiserated with professional experience.
Equal Opportunity Employer:
We are deeply committed to building a diverse and inclusive team. We believe that different backgrounds and life experiences make our team better. We do not discriminate against qualified employees or applicants because of race, color, religion, gender identity, sex, sexual preference, sexual identity, pregnancy, national origin, ancestry, citizenship, age, marital status, physical disability, mental disability, medical condition, military status, or any other characteristic protected by local law or ordinance.