VP of Security Operations
Listed on 2026-08-31
-
IT/Tech
Cybersecurity, Security Management & Operations
North Mark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients’ research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.
THEPOSITION
NMC² is seeking a VP of Security Operations to lead the operational arm of the company’s security program. Reporting to the Chief Information Security Officer, this leader owns the security operations function end to end and is accountable for delivering a measurable, mature Sec Ops program: the investments, platforms, and teams that detect, respond to, and stay ahead of threats against NMC²’s high-performance computing and cloud infrastructure.
This role owns five operational domains:
Incident Response, Vulnerability Management and Exploits, Threat Intelligence and Operations, Governance, Risk and Compliance (GRC) and Privacy, and Offensive Security. You will set the strategy, build the platforms, and run the day-to-day across all five, translating the CISO’s priorities into domain roadmaps with clear owners, metrics, and outcomes.
This is a builder’s role as much as a leader’s. You will make the tooling and platform decisions that underpin detection, response, and validation; stand up the SOC and detection engineering capability; and establish the operating cadence, service levels, and metrics that let the CISO and the business see exactly how the program is performing. You will build and empower strong domain leads, foster a culture of operational rigor and proactive security thinking, and partner closely with Infrastructure, Legal, and executive leadership to deliver a cohesive and resilient posture.
The ideal candidate brings a rare combination of operational depth and executive presence: someone who has built and run mature security operations functions at scale, understands the unique threat environment of HPC and AI infrastructure, and can represent NMC²’s security posture credibly to clients and board-level stakeholders.
RESPONSIBILITIESLead, manage, and grow the Security Operations organization across all five domains, ensuring each is well-resourced, has a strong lead, operates to defined service levels, and reports performance through clear metrics.
Deliver the Sec Ops program to the CISO: own the strategy, build plan, platform and tooling investments, and operating budget, and report progress, risk exposure, and program maturity with precision.
Own incident response end to end, structured to the NIST SP 800-61r2 lifecycle: preparedness and playbook development, detection engineering and SIEM operations, active response and containment, forensic preservation, and post-incident review with lessons-learned fed back into detections. Drive measurable improvement in mean time to detect and mean time to respond.
Run a risk-based vulnerability management and exploits program covering identification, prioritization, and SLA-driven remediation across the full stack, with particular attention to the attack surfaces unique to HPC and AI environments, including firmware, BMC and DRAC, GPU clusters, and CI/CD pipelines. Validate exploitability rather than reporting raw scanner output.
Build and mature the threat intelligence and operations function: actionable intelligence from OSINT, ISAC, vendor, and government sources; proactive threat hunting; insider threat and behavioral analytics; and adversary TTP analysis mapped to MITRE ATT&CK to drive defensive priorities.
Own the GRC and Privacy program: maintain a living risk register with owned and tracked acceptances, operationalize the company’s control framework and security baselines, run audit and assessment readiness, and embed privacy-by-design. Make decisions that preserve a future path to commercial certification rather than blocking it.
Lead the Offensive Security function,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).