Director, Security Operations
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Security Management & Operations
About Acrisure
A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. By bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services — and more.
In the last twelve years, Acrisure has grown in revenue from $38 million to nearly $5 billion, with over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible.
Job SummaryThe Director, Security Operations leads the day-to-day execution and delivery of enterprise security operations capabilities, including threat detection, incident response, threat hunting, security monitoring, operational security platforms, and cyber defense processes. This role is accountable for managing teams responsible for detecting, investigating, containing, and responding to cybersecurity threats while continuously improving operational effectiveness through automation, process maturity, and technology optimization.
This is an execution-focused leadership role. Success is measured by operational excellence, rapid detection and response, platform reliability, measurable risk reduction, and strong partnership with Technology, Engineering, Legal, Privacy, Human Resources, and business stakeholders. The role does not own enterprise cybersecurity strategy but is responsible for translating strategy into operational outcomes.
Success in this role means building a highly effective security operations program that rapidly detects and responds to threats, continuously reduces operational risk, and enables the business to operate securely Director establishes disciplined execution, operational reliability, and strong cross-functional partnerships while creating a culture of accountability, automation, and continuous improvement across the security operations organization.
Responsibilities Security Operations Leadership- Lead security operations teams responsible for security monitoring, alert triage, incident response, threat hunting, and cyber defense activities.
- Establish operational priorities and execution plans aligned with organizational risk reduction objectives.
- Build scalable operating models that enable efficient detection, investigation, and response across a global environment.
- Ensure consistent operational processes, documentation, escalation procedures, and service delivery standards.
- Develop and mentor managers, engineers, and analysts while fostering accountability, ownership, and continuous improvement.
- Oversee enterprise detection and response capabilities across endpoint, identity, cloud, network, email, and application environments.
- Ensure timely identification, investigation, containment, eradication, and recovery of cybersecurity incidents.
- Act as a senior escalation point for major incidents and provide executive-level situational updates when required.
- Lead operational readiness programs including playbooks, runbooks, tabletop exercises, simulations, and incident reviews.
- Drive improvements to detection coverage and response effectiveness based on emerging threats, incidents, and intelligence.
- Lead proactive threat hunting initiatives across enterprise environments.
- Ensure threat intelligence is operationalized into detection content, hunting activities, and response procedures.
- Drive maturity around adversary-focused operations utilizing frameworks such as MITRE ATT&CK.
- Partner with Engineering and Infrastructure teams to address security weaknesses identified through operational activities.
- Own operational effectiveness of security technologies including SIEM, SOAR, EDR/XDR, threat intelligence, email security, cloud security, and related security operations tooling.
- Drive automation initiatives that improve analyst efficiency, reduce response times, and minimize repetitive manual work.
- Partner with Security Engineering teams to improve telemetry, integrations, detections, and platform reliability.
- Ensure operational tooling remains scalable and aligned to business growth and acquisition activities.
- Coordinate with Legal, Privacy, Human Resources, Compliance, Internal Audit, and Technology teams during security incidents.
- Establish communication models and escalation paths for major cyber events.
- Lead post-incident reviews to identify root causes, lessons learned, and corrective actions.
- Ensure operational activities support regulatory, contractual, and reporting requirements.
- Define and maintain meaningful operational metrics and key performance indicators including:
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Detection…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).