Senior Director, Security Threat

Posted 6 Days Ago
Be an Early Applicant
2 Locations
In-Office
168K-253K Annually
Senior level
Biotech
The Role
Lead enterprise threat detection and response across SOC, detection engineering, threat intelligence, and incident response. Own strategy, 24x7 operations, tooling (SIEM/SOAR), KPIs (MTTD/MTTR), major incident coordination, and team development to reduce enterprise risk and improve detection coverage and response times.
Summary Generated by Built In

Job Summary: The Director of Threat Management is responsible for leading the enterprise detection and response function, owning the reactive side of security: identifying, investigating, and containing threats across a global Fortune 500 environment. This role provides leadership for the Security Operations Center (SOC), Cyber Threat Intelligence (CTI), Detection Engineering, and Incident Response (IR), and is accountable for the speed and quality of threat detection, triage, investigation, and response across the enterprise.

The Director of Threat Management leads a 24x7 monitoring and response organization while advancing the detection engineering pipeline, maturing threat intelligence integration, and driving measurable improvement in mean time to detect and mean time to respond. The role combines strategic direction, operational accountability, and organizational leadership to reduce enterprise risk from active and emerging threats, partnering closely with the platform engineering team that owns the underlying security tooling.

What You Will Do:

Strategy, Governance, and Leadership

  • Define and own the enterprise threat detection and response strategy, roadmap, and operating model aligned to cybersecurity, risk, and business objectives.

  • Mature the threat management program through formal governance, playbooks, standards, metrics, and leadership reporting.

  • Present detection and response posture, incident trends, risks, and investment needs to security leadership and executive stakeholders.

  • Establish and monitor KPIs such as mean time to detect (MTTD), mean time to respond (MTTR), detection coverage, and alert quality.

  • Lead prioritization decisions across the SOC, threat intelligence, detection engineering, and incident response functions.

Security Operations and Monitoring

  • Lead a 24x7 Security Operations Center responsible for monitoring, alert triage, escalation, and initial investigation across the enterprise.

  • Own the detection content lifecycle within the SIEM, and define data source onboarding, log storage, and retention requirements for the platform-owning team.

  • Drive continuous improvement in alert quality, triage efficiency, and analyst workflow to reduce noise and analyst fatigue.

  • Establish tiered operating models, shift coverage, and escalation paths that ensure consistent 24x7 response readiness.

  • Oversee SOC performance metrics, service levels, and quality assurance across monitoring and triage activities.

Detection Engineering

  • Lead the detection engineering function responsible for building, tuning, and maintaining detection content across SIEM and security telemetry sources.

  • Drive a detection-as-code approach with version control, testing, peer review, and measurable detection coverage mapped to MITRE ATT&CK.

  • Prioritize detection development against threat intelligence, red team findings, incident learnings, and emerging adversary techniques.

  • Establish metrics for detection coverage, efficacy, and false-positive rates, and drive continuous tuning based on outcomes.

  • Partner with engineering and platform teams to ensure high-quality, well-structured log and telemetry sources feed detection pipelines.

Cyber Threat Intelligence

  • Lead the Cyber Threat Intelligence function responsible for strategic, operational, and tactical intelligence supporting detection and response.

  • Operationalize threat intelligence by driving indicator enrichment, threat actor tracking, and intelligence-led detection and hunting priorities.

  • Deliver executive and stakeholder threat briefings that translate the threat landscape into business-relevant risk and action.

  • Establish threat hunting programs that proactively search for adversary activity across the environment ahead of alerting.

  • Manage intelligence sources, sharing partnerships, and integration of intelligence into SIEM, SOAR, and detection workflows.

Incident Response

  • Own the enterprise incident response process across detection, triage, containment, eradication, recovery, and post-incident review.

  • Lead major incident coordination, serving as an escalation point and driving cross-functional response during significant events.

  • Establish and maintain incident response playbooks, runbooks, and tabletop exercises to ensure organizational readiness.

  • Drive post-incident reviews and lessons-learned processes that feed detection improvements and control gaps back into the program.

  • Partner with legal, communications, IT, and business stakeholders to ensure coordinated response and regulatory notification where required.

Tooling and Automation Requirements

  • Define detection and response requirements, use cases, and priorities for the SIEM, SOAR, and log storage platforms owned and operated by the platform engineering team.

  • Partner with the platform-owning team to shape roadmap, data onboarding, retention, and automation priorities that serve detection and response needs.

  • Specify SOAR automation use cases for triage, enrichment, and response, and validate that delivered automations meet analyst workflow requirements.

  • Provide feedback on tooling performance, gaps, and integration needs to drive a unified, efficient analyst workflow across detection, intelligence, and response.

  • Use modern tools including AI-assisted workflows to accelerate investigation, analysis, documentation, and decision-making across the team.

Organizational and People Leadership

  • Lead and develop a distributed threat management organization consisting of managers, analysts, detection engineers, threat intelligence analysts, and incident responders.

  • Build organizational clarity across the SOC, threat intelligence, detection engineering, and incident response functions.

  • Provide leadership in talent development, succession planning, coaching, performance management, and team engagement.

  • Manage staffing strategy across full-time employees, partners, and contingent resources, including managed detection and response providers where applicable.

  • Oversee third-party vendors and consulting partners supporting threat management programs and services.

Minimum Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline; equivalent experience may be considered.

  • 12+ years of progressive experience in cybersecurity, security operations, threat detection, incident response, or threat intelligence.

  • 5+ years of leadership experience managing multi-team security operations or threat functions at the Senior Manager or Director level.

  • Demonstrated success leading detection and response programs across SOC operations, detection engineering, threat intelligence, and incident response.

  • Experience managing 15+ person organizations including managers, analysts, and engineers with varied technical specializations.

  • Experience leading major incident response and driving measurable improvement in detection coverage and response times.

  • Experience building or standing up new detection, intelligence, or response capabilities, teams, or services.

Technical and Functional Qualifications

  • Strong knowledge of SIEM and log management platforms and log storage technologies such as Elasticsearch or Splunk, including data onboarding, retention, and detection content management.

  • Strong knowledge of security orchestration, automation, and response (SOAR) platforms such as Swimlane or Cortex XSOAR.

  • Strong knowledge of detection engineering practices, detection-as-code, and detection coverage mapped to MITRE ATT&CK.

  • Experience with the cyber threat intelligence lifecycle, threat actor tracking, and intelligence-led detection and hunting.

  • Experience with incident response frameworks, forensic investigation concepts, and major incident coordination.

  • Understanding of threat detection across cloud (Azure, AWS, GCP), endpoint, network, and identity telemetry sources.

  • Familiarity with security frameworks and models such as MITRE ATT&CK, NIST CSF 2.0, and the cyber kill chain.

Preferred Qualifications

  • Experience in a Fortune 500, global, manufacturing, or industrial environment with complex, heterogeneous technology estates.

  • Prior experience standing up or transforming a SOC, threat intelligence, detection engineering, or incident response function.

  • Experience with threat detection and response in operational technology (OT) or industrial control system (ICS) environments.

  • Familiarity with platforms such as Elastic, Splunk, Swimlane, Cortex XSOAR, CrowdStrike, or Microsoft Sentinel.

  • Relevant certifications such as CISSP, CISM, GCIH, GCIA, GCTI, or GCFA.

Leadership Competencies

  • Strategic thinker with the ability to set direction and translate strategy into operational execution.

  • Decisive leader who operates effectively under pressure and makes sound calls during active incidents and competing priorities.

  • Delivery-oriented leader with a strong focus on accountability, measurable outcomes, and service quality.

  • Effective communicator able to translate complex threat and incident topics for executives, stakeholders, and technical teams.

  • Strong collaborator with the ability to influence across infrastructure, cloud, application, legal, and business teams.

  • Proven people leader with the ability to coach talent, build teams, and develop future leaders.

Additional Information

  • The role leads a 24x7 operation and may require off-hours availability for major incidents, escalations, and key initiatives.

  • Travel up to 10% may be required for site assessments, team collaboration, and vendor engagements.

  • The role may require coordination across global teams, including off-hours support for key initiatives, escalations, or major incidents.

Annual or Hourly Compensation Range

The base salary range for this position is $168,400.00 - $252,600.00. This position is eligible for annual bonus and long-term incentives based on performance, per plan terms. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.

Benefits 

Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families. Click here to see our benefits. 

If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working-here. 


Potential Customer Requirements Notice

To meet customer requirements and comply with local or state regulations, applicants for certain customer-facing roles may need to:

- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.


Americans with Disabilities Act (ADA) 

Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process, please visit the Recruiting Support link in the footer of each page of our career website.  

Skills Required

  • Bachelor's degree in Computer Science, Cybersecurity, IT, Engineering, or related discipline (or equivalent experience)
  • 12+ years progressive experience in cybersecurity, security operations, threat detection, incident response, or threat intelligence
  • 5+ years leadership experience managing multi-team security operations or threat functions at Senior Manager or Director level
  • Experience managing organizations of 15+ people including managers, analysts, and engineers
  • Proven success leading detection and response programs across SOC operations, detection engineering, CTI, and incident response
  • Experience leading major incident response and driving measurable improvements in detection coverage and response times
  • Experience building or standing up detection, intelligence, or response capabilities, teams, or services
  • Strong knowledge of SIEM and log management platforms and log storage technologies (e.g., Splunk, Elasticsearch) including data onboarding and detection content management
  • Strong knowledge of SOAR platforms and automation (e.g., Swimlane, Cortex XSOAR)
  • Strong knowledge of detection engineering practices, detection-as-code, version control, testing, and MITRE ATT&CK mapping
  • Experience with the cyber threat intelligence lifecycle, threat actor tracking, and intelligence-led detection and hunting
  • Experience with incident response frameworks, forensic investigation concepts, and major incident coordination
  • Understanding of threat detection across cloud (Azure, AWS, GCP), endpoint, network, and identity telemetry sources
  • Familiarity with security frameworks and models such as MITRE ATT&CK, NIST CSF 2.0, and the cyber kill chain
  • Experience in a Fortune 500, global, manufacturing, or industrial environment with complex heterogeneous estates
  • Experience with threat detection and response in OT/ICS environments
  • Familiarity with platforms such as Elastic, Splunk, Swimlane, Cortex XSOAR, CrowdStrike, or Microsoft Sentinel (explicit platform experience)
  • Relevant certifications (CISSP, CISM, GCIH, GCIA, GCTI, GCFA)

Ecolab Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Ecolab and has not been reviewed or approved by Ecolab.

  • Retirement Support Feedback suggests the company provides strong retirement programs, including a 401(k) with employer matching and a pension, alongside options like an employee stock purchase plan. Offerings such as retiree healthcare benefits and diverse investment choices reinforce long-term financial support.
  • Healthcare Strength Feedback suggests medical coverage is broad, with HSA plan options and company contributions, prescription benefits, dental and vision, and virtual care and mental health support. Company-paid wellness programs and income protection (short- and long-term disability, life and accident) further strengthen core coverage.
  • Parental & Family Support Family-focused programs include fertility support, adoption assistance, and paid parental leave, complemented by counseling and resource services. These offerings are positioned as supportive of employee well-being across different life stages.

Ecolab Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Saint Paul, MN
29,154 Employees

What We Do

A trusted partner at nearly three million customer locations, Ecolab (ECL) is the global leader in water, hygiene and infection prevention solutions and services. With annual sales of $12 billion and more than 44,000 associates, Ecolab delivers comprehensive solutions, data-driven insights and personalized service to advance food safety, maintain clean and safe environments, optimize water and energy use, and improve operational efficiencies and sustainability for customers in the food, healthcare, hospitality and industrial markets in more than 170 countries around the world. For more Ecolab news and information, visit www.ecolab.com, or follow us on twitter.com/ecolab, facebook.com/ecolab or instagram.com/ecolab_inc.

Similar Jobs

Morningstar Logo Morningstar

Visual Design Lead

Artificial Intelligence • Big Data • Enterprise Web • Fintech • Software • Financial Services
Hybrid
Chicago, IL, USA
11500 Employees
100K-500K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Senior Casualty Claims Specialist, Attorney Represented - Central Time Zone

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
6 Locations
40000 Employees
61K-126K Annually

MassMutual Logo MassMutual

Project Manager

Big Data • Fintech • Information Technology • Insurance • Financial Services
Remote or Hybrid
United States
6000 Employees
125K-164K Annually

Circle Logo Circle

Director, Product & Technology Communications

Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
In-Office or Remote
25 Locations
1050 Employees
200K-258K Annually

Similar Companies Hiring

Formation Bio Thumbnail
Artificial Intelligence • Big Data • Healthtech • Biotech • Pharmaceutical
New York, NY
150 Employees
SOPHiA GENETICS Thumbnail
Software • Healthtech • Biotech • Big Data • Artificial Intelligence
Boston, MA
450 Employees
Pfizer Thumbnail
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
New York, NY
121990 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account