> Markdown version of [/jobs/ext/145393-director-digital-defense-center](https://www.wearedevelopers.com/jobs/ext/145393-director-digital-defense-center). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, Digital Defense Center - **Company:** Southern Company - **Location:** Atlanta, GA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Supervisory Control and Data Acquisition (SCADA), Modbus, OLE for Process Control, Security Information and Event Management, Mttr, Cyber Threat Analysis, Data Lakes, Information Technology, Cybercrime, Cyber Warfare, Security Orchestration, Automation & Response - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=cfb92531f6a3ca2f ## About the Role Technical Experience * 10+ years in cybersecurity, with at least 5 years leading security operations in a critical infrastructure, energy, utility, or other highly regulated industry context. * Proven experience transforming SOCs or standing up new cyber defense capabilities at scale. * Deep familiarity with OT protocols (e.g., DNP3, Modbus, OPC, IEC 61850), ICS/SCADA environments, and control network segmentation practices. * Experience with SIEM, SOAR, EDR/XDR, UEBA, and security data lake technologies. Leadership & Industry Understanding * 5+ years in senior leadership roles, with a record of managing cross-functional teams and influencing C-level stakeholders. * Understanding of utility-specific threat landscape, operational constraints, and the convergence challenges between IT and OT security. * Experience engaging with regulatory bodies and adhering to NERC CIP, TSA, FERC, DOE, or PHMSA standards is highly preferred. Certifications & Education * Bachelor's or Master's in Cybersecurity, Engineering, Computer Science, or a related field. * Relevant certifications highly desirable: CISSP, CISM, GICSP, GIAC GRID, GCFA, GSOM, or equivalent. ## Description We are seeking a visionary and operationally grounded Cyber Defense Operations Leader to architect and lead the transformation of our Security Operations Center (SOC)-evolving it from current state into a unified, forward-looking, real-time cyber defense capability that spans both IT and OT environments across our business with a focus on our electric and gas utility operations. In this pivotal leadership role, you will own the strategy and execution of a multi-year roadmap to enhance cyber resilience across generation, transmission, distribution, gas pipeline, and corporate environments. You will serve not only as a technologist and strategist, but as a culture builder and inspirational leader who brings people along on the journey toward a more secure, adaptive, and empowered organization., SOC Transformation & Operational Excellence * Overhaul the existing SOC into a 24/7, highly adaptive cyber defense operation that aligns with energy sector best practices and threat models. * Deploy modern detection and response capabilities, including XDR, SOAR, AI/ML analytics, threat hunting, and incident correlation across cloud, endpoint, identity, and potentially select SCADA/ICS systems. * Define and track operational KPIs (e.g., MTTD, MTTR, threat coverage, dwell time, false positive rates) to drive continuous improvement and accountability. Integrated IT/OT Security Operations * Develop a unified SOC model that provides deep visibility into both IT and OT systems, enabling seamless detection, triage, and response across business and operational networks. * Collaborate with SCADA, EMS/DMS, pipeline control, and field operations teams to align cyber defense with safety, reliability, and operational integrity. * Lead all cybersecurity incident response activities from detection through recovery and post-incident review * Ensure compliance with NERC CIP, TSA Pipeline Security Guidelines, and other critical infrastructure regulations. * Evolve, grow and mature technical insider threat capabilities while working across key business organizations (Physical Security, Legal, Compliance, HR and Audit) to ensure a holistic approach Strategic Leadership & Capability Maturation * Lead the development and execution of a 3-5 year security operations roadmap aligned to enterprise risk, digital transformation, and regulatory evolution. * Partner with architecture, engineering, and enterprise risk teams to implement secure telemetry pipelines, data lakes, and AI-enhanced detection logic. * Manage third-party services and technology partners critical to SOC operations. Threat Intelligence, Crisis Response & Resilience * Integrate threat intelligence platforms, industry sharing mechanisms (e.g., E-ISAC, ONG-ISAC), and internal telemetry to anticipate emerging threats. * Lead or support cyber crisis simulations, incident response exercises, and coordination with state and federal emergency response partners. * Enhance organizational resilience through advanced detection, rapid containment, and robust recovery capabilities. People Leadership & Culture Building * Inspire, coach, and develop SOC analysts, engineers, and threat hunters into a mission-driven, high-performance team. * Create an inclusive, psychologically safe environment where team members are empowered to learn, innovate, and take ownership. * Foster deep collaboration with other departments: Infrastructure, SCADA/OT, Physical Security, Compliance, Legal, and Executive Leadership. ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Optimizing Land-Based Fish Feeding with Node-RED](https://www.wearedevelopers.com/videos/2032-optimizing-land-based-fish-feeding-with-node-red) - [Empowering Retail Through Applied Machine Learning](https://www.wearedevelopers.com/videos/976-empowering-retail-through-applied-machine-learning) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production)