Lead Director - Security Operations Center; SOC)
Listed on 2026-09-21
-
IT/Tech
Cybersecurity, Security Management & Operations
We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health®, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time.
PositionSummary
The Lead Director - Security Operations Center (SOC) is responsible for leading the cybersecurity operations function for a rapidly evolving healthcare business, ensuring the organization can effectively detect, investigate, respond to, and recover from cybersecurity threats. By establishing strong operational processes, actionable threat intelligence, and effective response capabilities, the position helps protect critical business operations, sensitive data, and customer trust.
Key Responsibilities Security Operations Leadership- Lead the strategy, execution, and continuous improvement of the Security Operations Center, including threat monitoring, detection, investigation, response, and threat hunting activities.
- Establish operational processes, service levels, metrics, and reporting to measure effectiveness and support informed decision-making.
- Build and mature SOC capabilities that align security operations to business priorities, risk tolerance, and growth objectives.
- Ensure operational readiness, escalation procedures, and effective coordination during cybersecurity events and incidents.
- Serve as the primary escalation point for significant cyber incidents and coordinate response efforts across technical and business stakeholders.
- Drive improvements in detection engineering, investigation processes, and response workflows to reduce risk and improve response times.
- Leverage automation, analytics, and AI-enabled capabilities to improve operational efficiency and strengthen cyber defense outcomes.
- Develop and maintain security operations standards, processes, and controls aligned with regulatory requirements and industry best practices.
- Lead initiatives that strengthen cyber resilience, incident preparedness, ransomware response readiness, and recovery capabilities.
- Provide leadership with visibility into threat activity, operational performance, emerging risks, and strategic recommendations.
- Support regulatory, audit, and risk management activities related to cybersecurity operations.
- Lead security operations across cloud, endpoint, identity, and network environments.
- Drive the effective use and continuous optimization of security technologies supporting monitoring, detection, investigation, and response functions.
- Partner with cloud, infrastructure, identity, and engineering teams to improve security visibility, response capabilities, and overall security posture.
- Ensure appropriate monitoring and threat detection coverage across critical systems, applications, and business services.
- Build, develop, and lead a high-performing team of security operations professionals.
- Foster a culture of accountability, collaboration, innovation, and continuous learning.
- Provide mentorship, coaching, and career development opportunities to strengthen team capability and succession depth.
- Align team priorities and resources to evolving business needs, threat landscapes, and organizational objectives.
- Identify opportunities to improve efficiency through process optimization, automation, and standardization.
- Establish meaningful metrics and reporting that demonstrate operational performance, effectiveness, and risk reduction.
- Drive continuous improvement initiatives that enhance the maturity, scalability, and effectiveness of security operations capabilities.
- Collaborate with stakeholders across technology and business functions to ensure security operations remains aligned with organizational priorities.
- 10+ years of progressive cybersecurity experience within medium-large scale environments.
- 5+ years leading Security Operations Center (SOC), Incident Response, Cyber Defense, or Threat Detection teams.
- 5+ years of Sexperience operating and optimizing enterprise security platforms, including SIEM, EDR/XDR, SOAR, and security automation technologies such as Microsoft Sentinel, Crowd Strike Falcon, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).