Director of Cyber Security Operations

executive
OtherSecurity Operations
0 views0 saves0 applied

Quick Summary

Overview

OVERVIEW The Company U.S. Financial Technology (U.S. FinTech) is seeking an experienced Director of Cyber Security Operations to join our team of talented professionals.

Technical Tools
OtherSecurity Operations

 

 

U.S. Financial Technology (U.S. FinTech) is seeking an experienced Director of Cyber Security Operations to join our team of talented professionals. This is a full-time remote opportunity. 

 

U.S. FinTech built and operates the largest and most advanced mortgage securitization platform in the world, supporting the Uniform Mortgage-Backed Security (UMBS) of Fannie Mae and Freddie Mac.

 

Supporting 70% of the mortgage-backed securities in the market, U.S. FinTech provides best-in-class single-family issuance, bond administration, disclosure, and tax services. We support a broad portfolio of products for our clients with full lifecycle management.

 

Our market-leading, cloud-based, end-to-end platform executes transactions on an extraordinary scale which has bolstered liquidity in the secondary mortgage market, one of the largest and most important financial markets in the world. Our unique approach to securitization combines the best minds in financial services with the know-how, flexibility, and innovation of leading technologists.

Responsibilities

~1 min read

 

The Director of Cyber Security Operations leads enterprise-wide security operations that protect the organization’s cloud-native and hybrid infrastructure, data, employee, and digital assets. This position is accountable for end-to-end cybersecurity monitoring, incident response, digital forensics, and supporting risk-reduction programs that preserve resilience and regulatory compliance. The role oversees advanced security architecture and tooling (SIEM, SOAR, AI/ML analytics), defines and reports organizational risk posture to executive leadership and regulators, and drives continuous innovation through process automation and technology modernization. This leader develops high-performing teams across monitoring, response, engineering, and cloud disciplines while integrating cybersecurity operations with enterprise IT and infrastructure functions to maintain audit-ready, financial-grade defenses. 

 

  • Lead and mature enterprise-scale monitoring operations, including 24×7 Security Operations Center (SOC) oversight, real-time detection and alerting programs, telemetry optimization, and automation to reduce mean time to detect and respond.

     

  • Direct incident response and forensics programs, coordinating containment, eradication, and recovery across infrastructure and application domains while managing executive and regulatory communications during major security events.

     

  • Support risk-reduction initiatives encompassing vulnerability management, secure configuration baselines, patch governance, system integrity/authorized change, and compliance alignment for reduction in residual enterprise risk.

     

  • Architect and operationalize security platforms and analytics, implementing SIEM, SOAR, and AI/ML-driven tooling that enhance detection, automation, and response at enterprise scale.

     

  • Support cloud-native, hybrid and associated security operations, embedding DevSecOps practices, workload segmentation, and identity governance across cloud environments (AWS, Azure, GCP).

     

  • Define and report cyber-risk posture to executive leadership and regulatory bodies, aligning operational practices with enterprise risk frameworks and audit requirements.

     

  • Drive innovation and process automation in cybersecurity operations, evaluating emerging technologies to enhance predictive detection, orchestration, and operational efficiency.

     

  • Build, mentor, and lead high-performance cybersecurity teams across monitoring, response, engineering, and cloud disciplines, ensuring accountability and professional growth.

     

  • Integrate cybersecurity operations with infrastructure and IT processes, enforcing secure configuration standards, consistent baselines, and unified incident management workflows.

     

  • Represent the organization in audits, examinations, and crisis events, ensuring compliance with federal, financial, and industry-specific regulatory requirements.

     

Requirements

~1 min read

 

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field required; Advanced degrees (MS, PhD) strongly preferred.
  • Industry Certification required, e.g. GSOM, GSOC, CISSP, CISA, CISM or equivalent designation.
  • Minimum of 10 years experience: 
    • Leading enterprise-scale monitoring operations, including 24×7 Security Operations Center management, real-time detection and alerting programs, “eyes-on-glass” analyst oversight, telemetry and log pipeline optimization, and the development of automated response processes to reduce mean time to detect and respond. 
    • Directing comprehensive incident response and forensics functions, encompassing major incident handling, digital evidence collection, post-mortem analysis, executive and regulator engagement during breaches, and coordination with infrastructure and engineering teams to ensure containment and eradication of threats.
    • Architecting and operationalizinge advanced security platforms and tooling, including implementation of SIEM/SOAR systems, integration of AI/ML analytics into detection and response workflows, deployment of new enterprise-wide security solutions, and definition of long-term technical roadmaps for operational resilience.
  • Minimum of 6-10 years experience: 
    • Managing enterprise-level risk-reduction programs, covering vulnerability management, compliance alignment, secure configuration baselining, patch governance, and audit remediation—driving measurable decreases in residual risk and ensuring adherence to regulatory and cybersecurity control frameworks.  
    • Overseeing cloud-native cybersecurity operations, ensuring protection of workloads across cloud providers (AWS, Azure, GCP); embedding DevSecOps practices; maintaining compliance within virtualized and hybrid infrastructures; and governing identity, access, and workload isolation in dynamic cloud environments. 
  • Applicants must be authorized to work in the US without requiring employer sponsorship currently or in the future. U.S. FinTech does not offer sponsorship for this position.

 

  • Deep expertise in Security Operations Center (SOC) design and management, including tiered analyst structures, alert triage workflows, and automated incident response orchestration.
  • Advanced proficiency in incident response leadership, including containment, eradication, digital forensics, and crisis communications with executive and regulatory stakeholders.
  • Proven ability to architect and maintain SIEM and SOAR platforms (e.g., Splunk, Power Automate, Scripting, KQL), optimizing correlation logic, enrichment pipelines, and playbook automation.
  • Strong knowledge of AI/ML integration in cybersecurity, including behavior-based analytics, anomaly detection, and large language model applications for threat hunting and automation.
  • Expertise in vulnerability management and risk reduction, including threat-based prioritization, patch lifecycle governance, secure configuration baselines, and exposure, and leveraging that information to drive threat and compromise detection.
  • Advanced understanding of secure cloud architecture and DevSecOps practices across AWS, Azure, and GCP, including workload isolation, zero-trust principles, and continuous compliance monitoring.
  • Proficiency in digital forensics and evidence preservation, including memory, disk, and network artifact analysis aligned to legal and regulatory standards.
  • Demonstrated capability to lead cybersecurity risk governance, mapping technical controls to NIST CSF, ISO 27001, SOC 2, and FHFA/Fed examination requirements, combined with strong understanding of regulatory and audit frameworks impacting fintech operations and enterprises.
  • Strong command of cybersecurity automation and orchestration frameworks, integrating endpoint, identity, and network telemetry into cohesive operational pipelines.
  • Strong knowledge in identity and access management (IAM), least-privilege enforcement, privileged-access controls, and integration with cloud-native identity providers.
  • Experience implementing and tuning data loss prevention (DLP), insider risk, and threat intelligence programs to detect anomalous user and data activity.
  • High fluency in security metrics and KPI development, including incident trends, dwell time analysis, patch compliance, and automation ROI reporting to executives.
  • Significant skills in cross-functional program leadership, aligning cybersecurity operations with IT, infrastructure, compliance, and product engineering teams.
  • Expertise in vendor and third-party risk management, including integration of external threat intelligence and performance monitoring.
  • Ability to design and execute enterprise cybersecurity testing and validation programs, including tabletop exercises, red team coordination, and control assurance.
  • Strong communication and executive presentation skills, translating technical risk into business impact for boards, regulators, and senior stakeholders.
  • Track record of innovation and continuous improvement, leveraging automation, ML/AI, and analytics to modernize cybersecurity operations at scale.
  • Exceptional leadership and team-building acumen, with the ability to recruit, mentor, and retain top technical talent across multiple cybersecurity domains.

 

Pay Range $208,500 to $235,750

 

U.S. FinTech's pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) a candidate’s qualifications, skills, competencies, and experience, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. U.S. FinTech offers a competitive total compensation package, which includes a performance bonus, 401k match, healthcare coverage, PTO, and a broad range of other benefits.

 

As a condition of employment with U.S. Financial Technology, any successful job applicant will be required to  successfully complete a background investigation, which may also include a credit check for positions in some areas of our business.   

     

U.S. Financial Technology is an Equal Opportunity Employer.

 

##LI-Remote

Location & Eligibility

Where is the job
—
Location terms not specified

Listing Details

Posted
September 28, 2026
First seen
September 29, 2026
Last seen
September 29, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
55%
Scored at
September 29, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Director of Cyber Security Operations