Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
K
KLDiscovery
Director, Cybersecurity Operations
Career Insights for Cyber Security Manager / Administrator
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Minnesota data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Manager or Administrator monitors, controls, and maintains systems that protect the security of large databases, including databases with customer information and patient files. Manages and administers the examination of client computer systems, identification of weak points in security, development and implementation of new systems, and monitoring and response to security issues.
$125,923 / year median in Minnesota
+2% projected growth
Job Description
Director, Cybersecurity Operations KLDiscovery United States, Minnesota, Eden Prairie 9023 Columbine Road (Show on map) Aug 26, 2026 Role overview The Director, Cybersecurity Operations leads Security Operations and Incident Response, Security Engineering, Vulnerability Management, and Threat Intelligence. This is a player-coach leadership role reporting directly to the CISO, partnering with the Director, Cyber GRC as one unified cyber team. The Director will bring hands-on technical depth, strong leadership capability, and the ability to modernize security operations through MDR deployment, AI-informed detection, and a security engineering team organized around functional specialization. Key responsibilities Security operations and incident response Security operations and incident response Own the MDR relationship, including SLA management, escalation accountability, detection tuning, and quarterly threat hunt reviews Lead the incident response function: IR runbooks, major incident coordination, executive communication during active incidents, and post-incident root cause analysis Oversee SOC detection engineering, ensuring SIEM rules, SOAR playbooks, and automated response actions are maintained, tested, and tuned to the current threat landscape Direct and develop the security analyst pool, redeploying analyst capacity from frontline triage toward MDR validation, threat hunt support, and stakeholder reporting Security engineering Oversee four specialized engineering lanes [endpoint, identity, cloud, and application security], ensuring each lane has clear ownership, defined scope, and measurable outcomes Drive security architecture reviews and engineering decisions for large or complex IT projects, ensuring security requirements are built in rather than bolted on Shape the security tooling stack strategy, evaluating, selecting, and retiring tools across endpoint, identity, cloud, and application security Enforce automation-first engineering practices, including IaC security gates, CI/CD pipeline security, CSPM auto-remediation, and SOAR-driven response workflows Threat intelligence, vulnerability management, and control validation Lead the operationalization of threat intelligence, translating MDR findings and external threat data into detection rule updates, architecture decisions, and risk register inputs for the GRC team Own the vulnerability management lifecycle: scanning coverage, risk-based prioritization, remediation tracking, and SLA enforcement Own the purple team and control validation program, confirming that deployed controls operate as intended and that detection capabilities fire correctly against known attack techniques Drive threat modeling across the engineering function, identifying attack paths before they are exploited and feeding findings into remediation prioritization AppSec, cloud, and AI security Oversee the AppSec function: secure SDLC, code review gates, SAST/DAST tooling, and security collaboration with the Product and Engineering teams Own cloud security posture management: CSPM, cloud workload protection, cloud IAM governance, and cloud-native security architecture Set the team-wide AI security posture, overseeing AI security controls across all engineering lanes, including model security, prompt injection testing, and AI tool access governance in partnership with cyber leadership MDR, automation, and tooling modernization Lead the ongoing maturation of the MDR deployment, expanding coverage, improving response fidelity, and integrating MDR outputs with internal SIEM, IAM, and compliance evidence workflows Champion security automation across the team, reducing manual toil in detection, response, vulnerability tracking, and reporting through SOAR, scripting, and platform integrations Evaluate emerging security technologies and make build/buy/partner recommendations to the CISO with clear business and risk rationale Team leadership and CISO partnership Lead, develop, and performance-manage a lean engineering team Partner with the Director, Cyber GRC as one unified cyber function, feeding operational threat intelligence into the risk register, supporting compliance evidence for technical controls, and jointly presenting security posture Provide regular metrics and reporting to the CISO on incident trends, control coverage, MDR performance, vulnerability posture, and team development Build a team culture of continuous improvement, automation-first execution, and proactive security, where threat hunting and control validation are protected activities rather than aspirational ones Qualifications Experience 15+ years of progressive experience in information security, including at least 7 years in a security leadership role Demonstrated ownership of a security operations or engineering function at the Director or equivalent level Experience operating and maturing an MDR deployment (CrowdStrike Falcon Complete, Arctic Wolf, Expel, or equivalent) in a corporate environment Hands-on background in at least two of the following: security engineering, penetration testing/offensive security, cloud security, application security, or incident response; this is not a purely strategic role Demonstrated experience deploying or maturing security automation, such as SOAR playbooks, detection engineering, IaC security, or CI/CD pipeline security Familiarity with cloud-native security (AWS, Azure, or GCP), including CSPM, cloud IAM, and workload protection Technical knowledge Working knowledge of cybersecurity frameworks such as