Director of Security Operations
Cipher develops and operates industrial-scale data centers for next-generation compute and HPC workloads. It combines power sourcing, construction, engineering, operations, real estate, and technology expertise.
About Cipher
Cipher develops and operates industrial-scale data centers engineered for next-generation compute. The company scales data-center infrastructure and delivers facilities purpose-built for HPC workloads, drawing on expertise in power sourcing, construction, engineering, operations, real estate, and technology.
Skills
About the Role
You will establish and lead the security operations function across IT, OT, cloud, and tenant environments. You will operate monitoring and detection capabilities, lead incident response, manage detection and response providers, run vulnerability-management activities, automate response workflows, conduct security drills, and report operational posture and outcomes to executive leadership.
Requirements
- Deep experience leading security operations or incident response and running major incidents under pressure.
- Demonstrated multi-party, multi-region incident-response leadership and stakeholder communication.
- Experience establishing and running detection and response, including provider and subcontractor management with SLA negotiation and enforcement.
- Knowledge of SOC operations, SIEM, EDR, SOAR, and detection engineering.
- Familiarity with SOC 2, ISO 27001, NIST 800-53, SOX, and partner notification obligations.
- OT or ICS incident-response or critical-infrastructure operational exposure is preferred.
- CISSP, GIAC certifications such as GCIH or GCIA, or CISM are preferred.
Responsibilities
- Establish and own security monitoring and detection across IT, OT, cloud, and tenant-boundary traffic.
- Maintain the defined security posture and operate security tooling.
- Own coverage metrics and detection coverage mapping against recognized adversary frameworks.
- Operationalize detection-as-code with security engineering.
- Build, test, and own the incident response plan, operating model, escalation paths, and responsibility map.
- Coordinate incident response across internal functions, tenants, and vendors.
- Use SOAR capabilities to automate containment, enrich alerts, and refine response playbooks.
- Lead live multi-party incident response across regions, tenants, and time zones.
- Author joint incident-response run books with tenants and partners.
- Run security drills across IT and OT and incorporate lessons into response plans.
- Select and manage detection and response providers, enforce SLAs, and ensure delivery transparency.
- Reduce provider concentration risk for detection and response.
- Own vulnerability-management cadence, remediation SLAs, risk-based prioritization, and reporting.
- Maintain awareness of the attack surface across sites and tenants.
- Build and lead the Security Operations function.
- Communicate operational posture, incident readiness, and response outcomes to executive leadership.
- Educate teams and run exercises to improve business-wide security response.
Benefits
- 401K retirement plan with match
- Medical, dental, and vision insurance
- Life and disability insurance
- Other perks
