Accommodations Plus International is seeking a Director of Cybersecurity to lead API’s global cyber defense program. Reporting to the SVP and CISO, this onsite role in Melville, NY 11747 focuses on security operations, threat detection, and incident response across applications, infrastructure, networks, and cloud environments.
Role overview
The Director of Cybersecurity owns the strategy and execution of API’s cyber defense across threat intelligence, detection, incident response, and product fraud and abuse. You will also drive resilient defenses and manage cloud security posture in both AWS and Azure, while leading the SOC MSSP partnership to ensure continuous monitoring and effective response.
Key responsibilities
- Own API’s cyber defense strategy spanning threat intelligence, detection, incident response, and product fraud and abuse.
- Translate adversarial research into actionable controls, detection rules, and response procedures.
- Lead and manage the SOC MSSP, ensuring 24x7x365 monitoring, investigation, and response.
- Set performance standards, drive operational accountability, and continuously improve SOC effectiveness.
- Manage cloud security posture across AWS and Azure, applying defense-in-depth to protect cloud-native and hybrid environments.
- Partner with engineering to embed security into product development using secure-by-default practices for cloud-hosted workloads and applications.
- Lead containment, recovery, and postmortem activities for security incidents.
- Establish measurable benchmarks to track program maturity and drive continuous improvement.
- Apply NIST, MITRE ATT&CK, and the Cyber Kill Chain to guide security architecture, detection strategy, and response procedures.
- Maintain current security architecture diagrams and documentation.
- Develop and maintain scorecards that measure SOC effectiveness and organizational risk.
- Report regularly to security and business leadership with clear, actionable insights.
- Identify and implement automation technologies to improve threat detection, prevention, and response at scale.
- Empower and develop SOC analysts and team members, fostering accountability, continuous learning, and strong cybersecurity practice.
Requirements
- 7–10+ years of progressive cybersecurity experience, including leadership in security operations, threat detection, and incident response.
- Proven experience managing a SOC or MSSP relationship with 24x7 operational oversight and performance management.
- Hands-on experience with AWS and Azure, including cloud security posture management and securing cloud-native and hybrid environments.
- Strong background in threat intelligence and adversarial techniques using frameworks such as NIST, MITRE ATT&CK, and the Cyber Kill Chain.
- Experience developing security metrics and scorecards for operational teams and executive leadership.
- Proven ability to lead incident response from containment through postmortem, with measurable program improvement benchmarks.
- Background in security engineering and architecture, especially designing defensible systems, is a plus.
- Working knowledge of CASB, SASE, firewalls, VPN, IDS, endpoint security, DLP, EDR/AV, and SIEM.
- Strong experience with Microsoft O365 security capabilities and administration.
- Familiarity with automation technologies supporting threat detection, prevention, and response.
- Proven ability to lead, develop, and motivate technical teams, including SOC analysts.
- Communicates effectively at staff and executive levels by translating complex security risks into business context.
- Bachelor’s degree in Cybersecurity, Computer Science, MIS, or equivalent experience (Master’s degree desirable).
- Preferred certifications (not required): GSEC, GCIA, GCIH, GCFE, GCFA, CISSP, CISM, or CISA.
Success metrics
- SOC performance metrics demonstrate measurable improvements in mean time to detect (MTTD) and mean time to respond (MTTR).
- Cloud security posture scores improve consistently in AWS and Azure.
- Security is embedded into the product development lifecycle with no critical vulnerabilities at release.
- Incident response playbooks are documented, tested, and continuously refined.
- High team engagement and SOC analyst capability development.
- Security risks are communicated clearly to executive leadership with actionable recommendations.
Compensation
$170,000 - $190,000 USD per year, commensurate with experience.
Additional information
- Standard professional office environment.
- Duties may change based on business needs.
- Additional responsibilities may apply if designated as a Data Protection Champion (DPC), Senior Information Risk Owner (SIRO), or Information Assurance Accounting Officer (IAAO).
- Equal Opportunity Employer: Accommodations Plus International does not discriminate based on protected characteristics under applicable federal, state, or local laws.
- Privacy: API may use contact information provided to communicate about the role, including via text message. See the company’s Privacy Policy for details; applying via Rippling requires agreeing to Rippling’s Terms of Service / User Privacy Notice.
Onsite location: Melville, NY 11747
Technologies: AWS, Azure, NIST, MITRE ATT&CK, Cyber Kill Chain, CASB, SASE, firewalls, VPN, IDS, endpoint security, DLP, EDR/AV, SIEM, Microsoft O365, automation technologies, SOC MSSP