Assistant Vice President, Threat Operations
Listed on 2026-08-14
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description Wedbush Securities is one of the largest securities firms and investment banks in the nation. We provide innovative financial solutions through our Wealth Management, Capital Markets, Futures and Advanced Clearing & Prime Services divisions. Headquartered in Los Angeles, California with over 100 offices and more than 80 correspondent offices, our commitment to providing relentless, customized service is the foundation of our consistent growth.
Job Description Wedbush Securities is one of the largest securities firms and investment banks in the nation. We provide innovative financial solutions through our Wealth Management, Capital Markets, Futures and Advanced Clearing & Prime Services divisions. Headquartered in Los Angeles, California with over 100 offices and more than 80 correspondent offices, our commitment to providing relentless, customized service is the foundation of our consistent growth.
Our IT team has an immediate opening for an Assistant Vice President, Threat Operations, to report to our Pasadena office. This role will lead the Firm’s security operations function and own threat monitoring, detection, incident response, and digital forensics across the enterprise. This position reports to the Chief Information Security Officer and will work a hybrid work schedule.
Responsibilities Include, But Are Not Limited To- Oversee day-to-day security operations, including threat monitoring, detection, alert triage, and escalation across the enterprise
- Lead incident response end to end (contain, mitigate, eradicate, recover), driving post-incident review and remediation to closure
- Direct digital forensic investigations to establish root cause, scope, and impact, ensuring defensible evidence collection; serve as senior escalation point and coordinate the Firm's technical response to major incidents
- Mature detection coverage through detection engineering, tuning, and false-positive reduction, integrating threat intelligence into monitoring and hunting; unify monitoring, detection, and response into a single view across threat operations
- Own the operational execution of the Firm's data protection and incident escalation obligations as a FINRA- and SEC-registered broker-dealer.
- Improve operations processes and workflows, tracking metrics such as MTTD/MTTR to drive measurable gains; champion automation and playbook development to standardize response
- Develop and execute the security operations strategy, policies, and playbooks aligned to Firm goals, risk appetite, and regulatory obligations; partner with Technology, Compliance, Legal, and leadership to communicate risk and priorities, elevate per broker-dealer obligations, support regulatory exams/audits/client notifications, and translate technical issues for technical and executive audiences
- Own workload allocation, staffing coverage, and on-call rotation; identify capability gaps and build the business case for tooling, training, or headcount
- Hire, manage, coach, and set pay for security engineers, responders, and forensic analysts
- Set goals, run performance reviews, and build development plans to strengthen team capability across monitoring, response, and forensics
- Perform other duties as required and assigned
- Bachelor's Degree from an accredited university
- CISSP (Certified Information Systems Security Professional) required
- 7+ years of relevant work experience required, with 5+ years of previous managerial experience
- GCIH (GIAC Certified Incident Handler), GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner), GCIA (GIAC Certified Intrusion Analyst), or CISM (Certified Information Security Manager) preferred
- Demonstrated ability to lead, develop, and retain technical security teams, including performance management and coaching
- Expertise in incident response, digital forensics, evidence collection and preservation, and threat intelligence
- Working command of security operations tooling, including SIEM, endpoint detection and response, and security orchestration and automation platforms
- Experience defining repeatable operational processes and documenting remediation to an auditable standard.
- Strong…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).