Director of Security Operations
Listed on 2026-08-06
-
IT/Tech
Cybersecurity
Director of Security Operations Cyber 429
· Kansas City
Company: Cyber 429 ()
Location: Kansas City metro area. Hybrid, with time on-site for SOC work and campus operations.
Reports to: Founder/CEO, working day-to-day with the COO.
Type: Full-time.
About usCyber 429 protects the organizations that get hit hardest and defend the worst. A lot of this industry runs on fear. Sell the scary headline, sell the shelfware, move on. We don’t work that way. We think security should be honest and within reach for the people who need it.
We’re a small, senior team, and we move like one. Beyond our commercial managed-security work, our CIPHER partnership and related higher-education initiatives are helping us stand up student-run SOCs that train the next generation of defenders on real environments. This is an early, senior leadership hire, and you’ll feel it.
What this job isYou run security operations. Our own managed-security operations for our clients and our student-SOC programs both sit under you. You’ll own the 429 SOC, lead the team that builds and runs our student SOCs, take point on incident response when things go sideways, and own the data and engineering that detection depends on.
This is a player/coach job, not a manager who sits above the work, because we are all rolling up our sleeves to build something that matters together. You’ll build the team and set the direction, but you’ll also be in the console tuning detections and working incidents alongside your analysts. In a SOC this size, the people doing the work won’t follow someone who can’t do it too.
You also own how well our student SOCs run. These are campus-based programs that will expand across Kansas, Missouri, and beyond, and you keep the program work and our commercial work cleanly separated where funding and compliance require it.
What you’ll ownThe 429 SOC. This is yours end to end: monitoring, detection engineering, triage, escalation, on-call, and the quality of what your analysts produce. You write the runbooks and set the coverage model, and you answer for what clients actually experience.
The student SOC. You lead the team that builds and runs our student SOCs. That means setting how students can safely work in real environments, developing the people who coach and mentor them, and turning the whole thing into a pipeline that feeds our own team. The teaching and talent-development mindset isn’t a nice-to-have here. It’s a big chunk of the job, and you need to actually want it.
Incident response. When something’s burning, you’re the one running it, with our team of senior experts who pitch in when we need help: containment, investigation, and talking clients through it while it’s happening. You’ll also build the IR playbooks and readiness so the team can handle most of it without you having to be on every call.
Data and engineering. Detection is only as good as the data feeding it. You own the pipelines and tooling: log ingestion, normalization, SIEM and EDR integration, the plumbing across client and program environments. You should be able to build this yourself where it matters, and you’ll lean on our contracted architects where that’s the smarter call.
What the first year should look likeA few things we’d expect to be true twelve months in:
- The 429 SOC runs on real, written standards for coverage, runbooks, detection quality, and on-call, and the founder is no longer in the loop on daily operations.
- The student SOC exists and works: students safely contributing to live monitoring, a mentorship model that holds up, and new talent coming through it.
- Incident response is faster and more consistent than it is today, with playbooks in place and clients kept through incidents we handled well.
- Data integration has stopped being a bottleneck. Pipelines are reliable, detection inputs are clean, and there’s less manual grinding across environments.
These are the must-haves. If you don’t meet most of them, this probably isn’t the right role, and that’s okay. We’d rather be clear now than waste your time.
- At least 5 years in security operations, incident response, or detection engineering, in a hands-on technical capacity.…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).