Director, Cybersecurity Operations Center
Manager
Cyber Security
Cybersecurity Tools
Endpoint Security
Incident Response
Information Security
Information Technology (IT)
InfoSec
Management
Ndr
NIST
Risk Management
Security
Security Automation
Security Information And Event Management
Security Monitoring
Security Operations
Security Operations Center
Security Standards
SOAR
Threat Hunting
Threat Intelligence
Job Description
Delek US is looking for a leader to drive security operations with direct ownership of a 24x7x365 Security Operations Center (SOC). In this onsite role in Brentwood, TN (near Nashville), you will lead incident response and oversee monitoring, detection, triage, investigation, escalation, and response across IT, OT, cloud, identity, network, endpoint, and third-party environments.
What you’ll do
- Lead Security Operations and run the SOC, directing 24x7x365 monitoring, detection, triage, investigation, escalation, and response across IT, OT, cloud, identity, network, endpoint, and third-party environments.
- Serve as incident commander for cyber security events by assessing severity, setting priorities, assigning ownership, coordinating cross-functional response teams, briefing executive leadership, and driving incidents through containment, eradication, recovery, and post-incident improvements.
- Ensure monitoring, detection, response, incident management, threat intelligence, threat hunting, and SOC processes align to IS standards, cyber security standards, and overall cyber risk management objectives.
- Identify cyber threats, suspicious activity, security incidents, and operational exposures, then determine scope, severity, and business impact; coordinate procedures to contain incidents, restore operations, and strengthen future detection and response.
- Develop techniques and procedures for monitoring, alert triage, incident investigation, threat analysis, threat hunting, digital evidence collection, cyber readiness exercises, and post-incident reviews.
- Lead investigations and resolution for intrusions, malware activity, unauthorized access, fraud, attacks, data loss events, and leaks.
- Translate cyber threat intelligence into actionable monitoring, detection, hunting, and response procedures.
- Develop, tune, validate, and maintain security monitoring use cases, detection content, alert logic, response workflows, and escalation procedures.
- Lead threat hunting activities to surface indicators of compromise, anomalous activity, and previously undetected threats.
- Partner with internal teams and external partners (managed security providers, incident response partners, technology vendors) to support security monitoring, threat detection, and cyber response services.
- Oversee continuous improvement of the Security Operations operating model, including SOC coverage, alert intake, triage, escalation, investigation, response coordination, performance measures, and integration. Ensure monitoring services are fulfilled 24x7x365.
- Establish and enforce incident command structure, escalation criteria, communication cadence, decision logs, action tracking, and after-action review practices.
- Perform review and validation of deliverables for SOC, Incident Response, Threat Intelligence, Threat Hunting, Detection Engineering, and related assigned activities.
- Conduct cyber readiness and validation activities, including tabletop exercises and incident response simulations.
Tools and frameworks you’ll work with
You’ll use SIEM, SOAR, EDR/XDR, NDR, and forensic and threat intelligence capabilities, with a strong grasp of NIST, MITRE ATT&CK, and ISA/IEC-62443.
What you bring
- Bachelor’s degree (4 year) or an equivalent combination of education and experience.
- 10+ years of relevant experience in Security Operations, Monitoring & Detection, Incident Response, Threat Intelligence, Threat Hunting, Digital Forensics, or Cyber Defense.
- 4+ years management experience.
- 4+ years leading a SOC, MDR function, incident response team, or cyber defense analysts with direct accountability for monitoring, detection, escalation, incident command, and response execution.
- Proven experience serving as incident commander for complex incidents across IT and OT, including executive coordination, business impact assessment, response decision-making, regulatory reporting, and post-incident corrective action.
- Knowledge of cyber threat and/or intelligence analysis; cyber incident response; threat hunting; detection engineering; malware investigation; and digital forensics practices.
- Solid understanding of cyber security, with the ability to analyze incident reporting, investigation results, response actions, and follow-up with reporting sites.
- Strong knowledge of incident management, problem management, and change management best practices.
- Ability to organize, prioritize, and manage multiple projects concurrently.
- Preferred certifications such as CISSP, GSEC, and other cyber security related certifications/licenses.
- Ability to provide timely and accurate reporting to internal and external stakeholders and to brief executives on current cyber threats, incidents, and operational readiness.
Benefits
- Up to 10% match on your 401(k) on your hire start, with a vesting timeline of only one year
- Medical benefits start on day one with a 30% premium rebate annually
- Access to the Calm app for FREE
- Additional annual incentives through a performance management program
- Highest bonus payouts in recent years