VP of Security Operations

Posted 2 Days Ago
Be an Early Applicant
Dallas, TX, USA
In-Office
Expert/Leader
Artificial Intelligence • Cloud • Machine Learning • Infrastructure as a Service (IaaS)
The Role
Leads the company’s Security Operations organization and owns incident response, vulnerability management, threat intelligence, GRC and privacy, and offensive security. The role develops SecOps strategy, platforms, budgets, SOC and detection engineering capabilities, operating metrics, and domain leadership. It oversees security tooling including SIEM, SOAR, and EDR; drives risk-based remediation, threat hunting, red teaming, compliance readiness, and measurable improvements in detection and response across HPC, cloud, GPU, and AI infrastructure.
Summary Generated by Built In

THE COMPANY

NorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients’ research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.

THE POSITION

NMC² is seeking a VP of Security Operations to lead the operational arm of the company’s security program. Reporting to the Chief Information Security Officer, this leader owns the security operations function end to end and is accountable for delivering a measurable, mature SecOps program: the investments, platforms, and teams that detect, respond to, and stay ahead of threats against NMC²’s high-performance computing and cloud infrastructure.

This role owns five operational domains: Incident Response, Vulnerability Management and Exploits, Threat Intelligence and Operations, Governance, Risk and Compliance (GRC) and Privacy, and Offensive Security. You will set the strategy, build the platforms, and run the day-to-day across all five, translating the CISO’s priorities into domain roadmaps with clear owners, metrics, and outcomes.

This is a builder’s role as much as a leader’s. You will make the tooling and platform decisions that underpin detection, response, and validation; stand up the SOC and detection engineering capability; and establish the operating cadence, service levels, and metrics that let the CISO and the business see exactly how the program is performing. You will build and empower strong domain leads, foster a culture of operational rigor and proactive security thinking, and partner closely with Infrastructure, Legal, and executive leadership to deliver a cohesive and resilient posture.

The ideal candidate brings a rare combination of operational depth and executive presence: someone who has built and run mature security operations functions at scale, understands the unique threat environment of HPC and AI infrastructure, and can represent NMC²’s security posture credibly to clients and board-level stakeholders.

RESPONSIBILITIES

  • Lead, manage, and grow the Security Operations organization across all five domains, ensuring each is well-resourced, has a strong lead, operates to defined service levels, and reports performance through clear metrics.

  • Deliver the SecOps program to the CISO: own the strategy, build plan, platform and tooling investments, and operating budget, and report progress, risk exposure, and program maturity with precision.

  • Own incident response end to end, structured to the NIST SP 800-61r2 lifecycle: preparedness and playbook development, detection engineering and SIEM operations, active response and containment, forensic preservation, and post-incident review with lessons-learned fed back into detections. Drive measurable improvement in mean time to detect and mean time to respond.

  • Run a risk-based vulnerability management and exploits program covering identification, prioritization, and SLA-driven remediation across the full stack, with particular attention to the attack surfaces unique to HPC and AI environments, including firmware, BMC and DRAC, GPU clusters, and CI/CD pipelines. Validate exploitability rather than reporting raw scanner output.

  • Build and mature the threat intelligence and operations function: actionable intelligence from OSINT, ISAC, vendor, and government sources; proactive threat hunting; insider threat and behavioral analytics; and adversary TTP analysis mapped to MITRE ATT&CK to drive defensive priorities.

  • Own the GRC and Privacy program: maintain a living risk register with owned and tracked acceptances, operationalize the company’s control framework and security baselines, run audit and assessment readiness, and embed privacy-by-design. Make decisions that preserve a future path to commercial certification rather than blocking it.

  • Lead the Offensive Security function, including red team operations, penetration testing, purple teaming, and adversarial simulation, and convert findings into closed detection gaps and strengthened controls, measured against ATT&CK technique coverage.

  • Select, deploy, and operate the security operations platform stack (SIEM, SOAR, EDR, threat intel, and vulnerability tooling), building business cases, defining program budgets, and partnering with finance and executive leadership to secure resources.

  • Establish the operating cadence and metrics for the function: service levels, detection coverage, remediation timeliness, and program maturity, using data to drive continuous improvement and demonstrate effectiveness to the CISO.

  • Develop strong domain leads and senior practitioners, fostering a leadership culture defined by accountability, craft, and continuous development.

  • Represent Security Operations in cross-functional forums, client-facing engagements, and regulatory contexts as needed, communicating NMC²’s risk posture and operational maturity to technical and non-technical audiences.

REQUIREMENTS

  • 10+ years of progressive experience in security operations, with at least 4 years in a senior leadership role managing multi-domain or multi-team security organizations.

  • Demonstrated hands-on depth across the security operations domains: incident response, vulnerability management, threat intelligence, GRC, and offensive security or red teaming, with the ability to lead each credibly rather than manage from a distance.

  • Proven experience building and running mature security operations functions in large-scale, complex infrastructure environments; experience with HPC, GPU cluster, IaaS, or AI environments is a strong advantage.

  • Direct experience standing up or substantially maturing a SOC and detection engineering capability, including selecting and operating SIEM, SOAR, and EDR platforms.

  • Working command of incident response practice, ideally structured to NIST SP 800-61r2, and of adversary behavior modeling using MITRE ATT&CK.

  • Strong track record building and scaling high-performing teams, including hiring, developing, and retaining senior practitioners and domain leads.

  • Working knowledge of risk-based and prescriptive frameworks, such as NIST CSF, the CIS Controls and CIS Benchmarks, ISO 27001, and SOC 2, and the judgment to operationalize them pragmatically in a fast-moving environment while preserving a future path to formal certification.

  • Experience leading offensive security programs and translating findings into measurable improvements in detection and defensive posture.

  • Experience driving security investment decisions: building business cases, defining program budgets, selecting and deploying enterprise security tooling, and working with finance and executive stakeholders.

  • Exceptional communication and executive presence, with the ability to distill complex threat and risk information into clear narratives for the CISO, board-level stakeholders, and clients.

  • Collaborative, strategic mindset with a bias for action, able to balance long-term risk and compliance thinking with the operational urgency of a high-growth, high-stakes infrastructure company.

  • Bachelor’s degree in Engineering, Computer Science, or a related field, or equivalent experience.

It is impossible to list every requirement for, or responsibility of, any position.  Similarly, we cannot identify all the skills a position may require since job responsibilities and the Company’s needs may change over time.  Therefore, the above job description is not comprehensive or exhaustive.  The Company reserves the right to adjust, add to or eliminate any aspect of the above description.  The Company also retains the right to require all employees to undertake additional or different job responsibilities when necessary to meet business needs.

Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Benefits & Perks:

  • Company-Paid Lunch Stipend: Lunch is provided via GrubHub

  • Company-Paid Benefits: 100% Employer-Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families, 16 weeks of Paid Parental Leave, Employee Assistance Program, Life insurance, Short-Term Disability and Long-Term Disability

  • 401(k): Company will match 100% of your contributions up to 6%

  • Optional Employee-Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.

  • Time Off:  25 days of Paid Time Off plus 12 company holidays

EQUAL OPPORTUNITY EMPLOYER

NORTHMARK STRATEGIES LLC IS AN EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER. THE COMPANY'S POLICY IS NOT TO DISCRIMINATE AGAINST ANY APPLICANT OR EMPLOYEE BASED ON RACE, COLOR, RELIGION, NATIONAL ORIGIN, GENDER, AGE, SEXUAL ORIENTATION, GENDER IDENTITY OR EXPRESSION, MARITAL STATUS, MENTAL OR PHYSICAL DISABILITY, AND GENETIC INFORMATION, OR ANY OTHER BASIS PROTECTED BY APPLICABLE LAW. THE FIRM ALSO PROHIBITS HARASSMENT OF APPLICANTS OR EMPLOYEES BASED ON ANY OF THESE PROTECTED CATEGORIES.

Skills Required

  • 10+ years of progressive experience in security operations
  • At least 4 years in a senior leadership role managing multi-domain or multi-team security organizations
  • Hands-on depth across incident response, vulnerability management, threat intelligence, GRC, and offensive security or red teaming
  • Experience building and running mature security operations functions in large-scale, complex infrastructure environments
  • Experience with HPC, GPU clusters, IaaS, or AI environments
  • Experience standing up or substantially maturing a SOC and detection engineering capability
  • Experience selecting and operating SIEM, SOAR, and EDR platforms
  • Working command of incident response practices, ideally structured to NIST SP 800-61r2
  • Working knowledge of adversary behavior modeling using MITRE ATT&CK
  • Experience building and scaling high-performing teams, including hiring, developing, and retaining senior practitioners and domain leads
  • Working knowledge of NIST CSF, CIS Controls, CIS Benchmarks, ISO 27001, and SOC 2
  • Experience leading offensive security programs and translating findings into measurable improvements
  • Experience driving security investment decisions, program budgets, enterprise security tooling, and executive stakeholder partnerships
  • Exceptional communication and executive presence with CISO, board-level, client, technical, and non-technical audiences
  • Bachelor's degree in Engineering, Computer Science, or a related field, or equivalent experience
  • Legally authorized to work in the United States without current or future employer sponsorship
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
157 Employees

What We Do

NorthMark Strategies is a strategic capital firm that combines investment capital with engineering and technology to build enduring businesses. The firm operates a High-Performance Computing platform and supports simulation, AI/ML-enabled engineering and data-driven design to accelerate portfolio companies. NorthMark deploys capital, operates complex businesses, and builds infrastructure (including compute and cloud services) to drive long‑term innovation and operational outcomes.

Similar Jobs

Hybrid
5 Locations
289097 Employees
In-Office
6 Locations
8926 Employees
155K-258K Annually

Coursera + Udemy  Logo Coursera + Udemy

Support Engineer

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
98K-123K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Solutions Engineer

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Hybrid
5 Locations
40000 Employees
137K-257K Annually

Similar Companies Hiring

Legora Thumbnail
Artificial Intelligence • Legal Tech • Software
New York, New York
700 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account