> Markdown version of [/jobs/ext/2069199-director-it-ot-security-operations](https://www.wearedevelopers.com/jobs/ext/2069199-director-it-ot-security-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, IT & OT Security Operations... - **Company:** Southwire Company, LLC - **Location:** Carrollton, GA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Performance Tuning, Remote Access Technology, Phishing, Mttr, Vulnerability Analysis - **Published:** August 15, 2026 - **Apply:** https://www.juju.com/job/00000000gmzrzz ## About the Role Bachelor's Degree 8-11 Years of Experience Field(s) of Expertise: Progressive experience in cybersecurity, including IT security operations and/or OT/ICS security Preferred Education & Experience Master's degree 12-14 Years of Experience Licenses and Certifications: CISSP, CISM, CRISC, or equivalent. OT/ICS security certifications (e.g., GICSP, IEC 62443), Domestic - up to 25% of time Physical Requirements Moving - 5% of time Standing - 5% of time Sitting - 90% of time Working Conditions Office Plant/Warehouse Floor Equipment Computer/Keyboard Safety Glasses Safety Shoes Safety Vest Competencies Business Insights Communicates Effectively Drives Results Manages Ambiguity Manages Complexity Values Differences Skills Cyber Risk ## Description The Director, IT/OT Security Operations & Governance leads day-to-day cybersecurity operations across enterprise IT and manufacturing operational technology (OT) environments while establishing governance, risk oversight, and measurable security performance. The role partners closely with IT, plant engineering/operations, and business leaders to reduce cyber risk, strengthen resilience, and ensure security controls, policies, and processes are consistently implemented without compromising safety, quality, or uptime. The position owns the managed detection and response (MDR) service and internal processes that support 24x7 monitoring and response and supports internal and external audit activities through evidence collection, control testing coordination, and remediation tracking., + Own and mature security monitoring, detection, response, and recovery processes across IT and OT; manage the MDR provider to ensure 24x7 coverage, defined playbooks/runbooks, clear escalation paths, and measurable outcomes aligned to risk and manufacturing operations. + Lead and coordinate major incident response, including triage, containment, eradication, forensics engagement, executive communications, and post-incident lessons learned. + Partner with plant/operations engineering to implement practical OT security controls (asset visibility, segmentation, remote access, patching strategy, and compensating controls) aligned to safety, uptime, and operational constraints. + Govern vulnerability scanning, prioritization, and remediation for IT and OT; manage exception process, risk acceptance, and time-bound remediation plans. + Establish and maintain security policies, standards, procedures, and control objectives; drive alignment to recognized frameworks (e.g., NIST CSF/800-53, ISO 27001) and OT guidance (e.g., IEC 62443) as applicable. + Define, produce, and continuously improve operational and risk metrics (KPIs/KRIs) such as MTTD/MTTR, alert fidelity, patch/vulnerability SLAs, phishing performance, endpoint coverage, OT asset coverage, and control effectiveness; deliver dashboards and executive-ready reporting. + Support internal audit and external assessments by coordinating evidence collection, facilitating walkthroughs, assisting with control testing, and tracking remediation plans to closure; maintain an audit-ready evidence repository for key controls. + Maintain the security operations tool stack; drive use-case development, tuning, automation/orchestration, integrations, and lifecycle management to improve efficiency and outcomes. + Collaborate on awareness and behavior-change initiatives; ensure operational teams understand procedures for reporting, response, and secure-by-design practices. + Facilitate security risk decisions for operational constraints, maintain risk register inputs for SecOps/GRC domains, and ensure compensating controls and timelines are documented. + * Performs other duties as assigned + Complies with all policies and standards + Manages staff performance and development, coaching team members to achieve their full potential incontributing to the department's goals. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager)