Lead Director - Security Operations Center (SOC)

CVS Health
Concord, NH, United States
5 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$144,200.0 - $288,400.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Data Analysis Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Digital Forensics Identity and Access Management Intrusion Detection and Prevention Microsoft Security Essentials
+11 more
Zero Trust Network Access Security Information and Event Management Software Vulnerability Management Google Cloud Cloud Platform System Malware Information Technology Cybercrime Microsoft Sentinel Cyber Warfare Security Orchestration, Automation & Response

Job description

The Lead Director - Security Operations Center (SOC) is responsible for leading the cybersecurity operations function for a rapidly evolving healthcare business, ensuring the organization can effectively detect, investigate, respond to, and recover from cybersecurity threats. By establishing strong operational processes, actionable threat intelligence, and effective response capabilities, the position helps protect critical business operations, sensitive data, and customer trust.

As the leader of the SOC function, this role is accountable for building and maturing security operations capabilities that balance security, scalability, and business agility. The Lead Director partners closely with infrastructure, cloud, identity, engineering, and business leaders to strengthen cyber resilience and prepare the organization for emerging threats. Through strong leadership, operational discipline, and continuous improvement, this position helps ensure cybersecurity remains an enabler of growth while reducing risk in a highly regulated environment., Security Operations Leadership

  • Lead the strategy, execution, and continuous improvement of the Security Operations Center, including threat monitoring, detection, investigation, response, and threat hunting activities.
  • Establish operational processes, service levels, metrics, and reporting to measure effectiveness and support informed decision-making.
  • Build and mature SOC capabilities that align security operations to business priorities, risk tolerance, and growth objectives.
  • Ensure operational readiness, escalation procedures, and effective coordination during cybersecurity events and incidents.

Threat Detection & Incident Response

  • Serve as the primary escalation point for significant cyber incidents and coordinate response efforts across technical and business stakeholders.
  • Drive improvements in detection engineering, investigation processes, and response workflows to reduce risk and improve response times.
  • Leverage automation, analytics, and AI-enabled capabilities to improve operational efficiency and strengthen cyber defense outcomes.

Cybersecurity Strategy & Resilience

  • Develop and maintain security operations standards, processes, and controls aligned with regulatory requirements and industry best practices.
  • Lead initiatives that strengthen cyber resilience, incident preparedness, ransomware response readiness, and recovery capabilities.
  • Provide leadership with visibility into threat activity, operational performance, emerging risks, and strategic recommendations.
  • Support regulatory, audit, and risk management activities related to cybersecurity operations.

Cloud, Identity & Platform Security

  • Lead security operations across cloud, endpoint, identity, and network environments.
  • Drive the effective use and continuous optimization of security technologies supporting monitoring, detection, investigation, and response functions.
  • Partner with cloud, infrastructure, identity, and engineering teams to improve security visibility, response capabilities, and overall security posture.
  • Ensure appropriate monitoring and threat detection coverage across critical systems, applications, and business services.

Leadership & Talent Development

  • Build, develop, and lead a high-performing team of security operations professionals.
  • Foster a culture of accountability, collaboration, innovation, and continuous learning.
  • Provide mentorship, coaching, and career development opportunities to strengthen team capability and succession depth.
  • Align team priorities and resources to evolving business needs, threat landscapes, and organizational objectives.

Operational Excellence & Continuous Improvement

  • Identify opportunities to improve efficiency through process optimization, automation, and standardization.
  • Establish meaningful metrics and reporting that demonstrate operational performance, effectiveness, and risk reduction.
  • Drive continuous improvement initiatives that enhance the maturity, scalability, and effectiveness of security operations capabilities.
  • Collaborate with stakeholders across technology and business functions to ensure security operations remains aligned with organizational priorities.

Requirements

  • 10+ years of progressive cybersecurity experience within medium-large scale environments.
  • 5+ years leading Security Operations Center (SOC), Incident Response, Cyber Defense, or Threat Detection teams.
  • 5+ years of Sexperience operating and optimizing enterprise security platforms, including SIEM, EDR/XDR, SOAR, and security automation technologies such as Microsoft Sentinel, CrowdStrike Falcon, and Wirespeed.
  • 3+ years of demonstrated experience building, managing, and maturing security operations capabilities, including security monitoring, threat hunting, incident response, digital forensics, and security investigations., * Experience supporting cloud-native and hybrid security operations across Microsoft Azure, Google Cloud Platform (GCP), and Amazon Web Services (AWS).
  • Hands-on experience with Microsoft Security technologies, including Sentinel, Defender XDR, Defender for Cloud, and Entra ID, as well as Google Security Command Center.
  • Experience implementing security automation, orchestration, AI-enabled security operations, or operational workflow optimization within a SOC environment.
  • Strong knowledge of Zero Trust architecture, identity security, vulnerability management, cyber resilience, and ransomware response preparedness.
  • Proven ability to lead teams, establish operational metrics, and communicate cybersecurity risks, incident impacts, and program performance to senior leadership.
  • Industry certifications such as CISSP, CISM, CCSP, GIAC certifications, Microsoft Security certifications (SC-100, SC-200), Google Professional Cloud Security Engineer, or CrowdStrike Falcon Certification, * Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field, or equivalent experience.

Benefits & conditions

$144,200.00 - $288,400.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full-time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well-being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all