Director, Security Operations & Detection Engineering
Listed on 2026-09-21
-
IT/Tech
Cybersecurity
Enterprise IT & Security Mountain View, CA, Pittsburgh, PA, Seattle, WA
Director, Security Operations & Detection EngineeringWho we are
Aurora's mission is to deliver the benefits of self-driving technology safely, quickly, and broadly.
The Aurora Driver will create a new era in mobility and logistics, one that will bring a safer, more efficient, and more accessible future to everyone.
At Aurora, you will tackle massively complex problems alongside other passionate, intelligent individuals, growing as an expert while expanding your knowledge. For the latest news from Aurora, visit aurora.tech or follow us on Linked In .
What we are looking for
We are searching for a Director of Security Operations & Detection Engineering to lead and unify Aurora's Detection & Response (D&R) and Security Operations Center (SOC) functions under our Technical Assurance division. This role owns the strategy, roadmap, and operating rigor for how Aurora detects, triages, investigates, and responds to threats across Onboard (vehicle), Cloud, and Enterprise environments - spanning both the engineering that builds our detection capability and the 24x7 operations that run it.
This is a strategic people-leadership role. You will set direction, build and scale a multi-team organization, and represent cyber defense to executive stakeholders.
In this role you will
Own end-to-end leadership of the D&R and SOC teams, including engineers and analysts across detection engineering, incident response, and 24x7 monitoring/triage.
Own 24x7 staffing model, on-call rotations, and resource allocation across time zones to ensure continuous coverage; participate in leadership escalation on-call as needed.
Define and drive the multi-year strategy and roadmap for detection engineering, threat hunting, incident response, and security operations.
Stay close enough to the technology (SIEM, EDR, NDR, SOAR, cloud-native and vehicle/embedded environments) to make architecture and prioritization calls, review technical strategy with your leads, and step in on the highest-stakes technical problems or incidents.
Own end-to-end incident response posture - from detection through containment, eradication, recovery, and post-incident reviews. Serve as the executive point of contact for cybersecurity incidents and audits.
Oversee cloud vulnerability management: ensure findings are triaged by severity/exploitability, owners are assigned, and remediation or compensating controls are tracked to closure against SLAs.
Oversee design, development, and implementation of detections, tooling and Cross Functional projects that touch Cloud, Enterprise, and On-Vehicle D&R/SOC.
Own and report on KPIs, telemetry coverage, alert fidelity, and SOC efficiency and maturity to executive leadership.
Required qualifications
15+ years of progressive cybersecurity experience, including 6+ years leading, managing, and scaling detection engineering and security operations teams.
Current hands-on experience with detection engineering, threat hunting, or incident response sufficient to credibly guide technical strategy and support your team.
Strong working knowledge of SIEM, EDR, NDR/SOAR, and modern detection and response tooling. Strong understanding of cloud-native environments (AWS, Kubernetes) and enterprise/endpoint security (Linux, macOS, Windows).
Deep knowledge of the MITRE ATT&CK framework, NIST CSF, and modern adversarial techniques.
End-to-end incident management experience, driving cross-departmental collaboration through high-severity incidents.
Experience with vulnerability management, including triage/prioritization of findings and driving remediation across engineering teams.
Demonstrated experience building a metrics/reporting program from scratch (defining metrics,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).