Dir Security Operations & Engineering

EmpowerUnited StatesRemoteFull-timeStaff, 8–12 yearsListed 45 minutes ago

Apply now

About this role

Our vision for the future is based on the idea that transforming financial lives starts by giving our people the freedom to transform their own. We have a flexible work environment, and fluid career paths. We not only encourage but celebrate internal mobility. We also recognize the importance of purpose, well-being, and work-life balance. Within Empower and our communities, we work hard to create a welcoming and inclusive environment, and our associates dedicate thousands of hours to volunteering for causes that matter most to them.

Chart your own path and grow your career while helping more customers achieve financial freedom. Empower Yourself.

Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time, including CPT/OPT.

The Director Security Operations & Engineering will lead security operations and engineering teams responsible for protecting the organization’s information systems and technology environment. This role will serve as a security advocate and trusted partner to key stakeholders and service owners, providing guidance on security operations, engineering, and the effective balance of security and business requirements. The Director will be accountable for the performance and results of multiple related teams responsible for security monitoring, event analysis, incident response, security engineering, and security controls. This role will provide input into security policies, procedures, and departmental priorities and translate broader information security objectives into actionable plans for assigned teams.

What you will do:

- Lead the day to day management and performance of multiple security operations and engineering teams, including subordinate managers and professional level security staff, establishing priorities, objectives, and performance expectations.
- Provide input into annual departmental goals, objectives, policies, procedures, and priorities, and develop departmental plans and resource allocations that support broader Information Security objectives.
- Oversee cybersecurity monitoring, event analysis, identification, escalation, investigation, reporting, and incident response processes.
- Direct analysis of security logs and other relevant data to identify unauthorized access, malicious activity, intrusion attempts, potential compromises, and emerging threats.
- Oversee security services and technologies including SIEM, IDS/IPS, firewalls, web application firewalls, security event correlation capabilities, and related security platforms.
- Ensure external threat intelligence, vulnerability assessment information, and other relevant security data are effectively incorporated into monitoring, investigation, and response processes.
- Develop and monitor operational metrics and reporting related to security events, trends, vulnerabilities, mitigation activities, service performance, and departmental effectiveness, and present findings and risks to senior security leadership and stakeholders.
- Oversee the development and execution of standard operating procedures, job aids, security hardening standards, and processes that support consistent security operations and engineering activities.
- Ensure security devices and controls are appropriately designed, implemented, maintained, monitored, tested, and improved in accordance with established architecture and change control processes, including cryptographic controls within assigned areas of responsibility.
- Identify security risks, direct the development of remediation strategies or mitigating controls, and oversee or approve application and system change requests requiring security review.
- Provide subject matter expertise and departmental leadership for enterprise information security initiatives, strategies, projects, policies, regulatory inspections, and internal and external audits.
- Lead or oversee Information Security and Risk projects, coordinating with internal teams, subject matter experts, business and technology stakeholders, and third parties to resolve complex security issues and apply appropriate security strategies, policies, frameworks, and recommendations.
- Assign teams and staff to projects, monitor project status, schedules, budgets, resource constraints, and departmental issues, and escalate significant risks or issues to senior security leadership as appropriate.
- Participate in departmental budget planning, manage assigned resources and expenditures, forecast staffing requirements, and make recommendations regarding workforce needs and priorities.
- Hire, develop, coach, mentor, and evaluate managers and professional staff; support performance and personnel decisions; develop leadership capability; and promote talent management, succession planning, knowledge sharing, professional development, and productive relationships across Information Technology, Risk, Audit, Compliance, and business functions. Perform other duties and responsibilities as assigned.

What you will bring:

- Significant experience in information technology security operations, engineering, security architecture, or related information security disciplines.
- 6 to 8 years of related management experience, consistent with the career level expectations for this role.
- Demonstrated experience leading multiple teams of security professionals and/or subordinate managers.
- Experience with security operations and monitoring, incident response, security system design, deployment, and delivery.
- Demonstrated experience managing or providing leadership for a Security Operations Center and/or security engineering function.
- Strong knowledge of information security technologies, tools, controls, and industry practices, including SIEM, IDS/IPS, firewalls, web application firewalls, security event correlation, and related security platforms.
- Demonstrated knowledge of information systems security standards and practices, including access controls, system hardening, audit and log monitoring, security policies, vulnerability management, and incident handling.
- Experience working with third party service providers as part of a comprehensive security program.
- Project management experience, including demonstrated ability to organize, plan, prioritize, resource, and deliver assignments through direct and indirect reports.
- Demonstrated ability to identify and resolve complex security problems within assigned disciplines and areas of responsibility.
- Ability to translate security risks and technical issues into clear business language for technical and non technical audiences, including senior leaders, auditors, clients, end users, and IT staff.
- Strong organizational and prioritization skills with demonstrated ability to adapt departmental plans and resources in a fast paced, changing environment.
- Demonstrated ability to manage professional staff, subordinate managers, indirect resources, and vendors.
- Proven analytical, problem solving, and critical thinking skills.
- Strong written and verbal communication skills with the ability to collaborate with and influence stakeholders across multiple levels of the organization.

What will set you apart:

- Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity, or a related discipline, or equivalent applicable experience.
- Security certifications such as CISSP, CISM, SANS GCIH (Certified Incident Handler), GCIA (Certified Intrusion Analyst), CEH (Certified Ethical Hacker), GIAC certification, or comparable industry certifications.
- Experience in a complex technical environment, with financial services or another highly regulated industry preferred.

This job operates in a professional office environment.

This job description is not intended to be an exhaustive list of all duties, responsibilities and qualifications of the job. The employer has the right to revise this job description at any time. You will be evaluated in part based on your performance of the responsibilities and/or tasks listed in this job description. You may be required to perform other duties that are not included on this job description. The job description is not a contract for employment, and either you or the employer may terminate employment at any time, for any reason, as per terms and conditions of your employment contract.

What we offer you

We offer an array of diverse and inclusive benefits regardless of where you are in your career. We believe that providing our employees with the means to lead healthy balanced lives results in the best possible work performance.

- Medical, dental, vision and life insurance
- Retirement savings – 401(k) plan with generous company matching contributions (up to 6%), financial advisory services, potential company discretionary contribution, and a broad investment lineup
- Tuition reimbursement up to $5,250/year
- Business-casual environment that includes the option to wear jeans
- Generous paid time off upon hire – including a paid time off program plus ten paid company holidays and three floating holidays each calendar year
- Paid volunteer time — 16 hours per calendar year
- Leave of absence programs – including paid parental leave, paid short- and long-term disability, and Family and Medical Leave (FMLA)
- Business Resource Groups (BRGs) –  BRGs facilitate inclusion and collaboration across our business internally and throughout the communities where we live, work and play. BRGs are open to all.

Base Salary Range
$138,000.00 - $200,100.00

The salary range above shows the typical minimum to maximum base salary range for this position in the location listed. Non-sales positions have the opportunity to participate in a bonus program. Sales positions are eligible for sales incentives, and in some instances a bonus plan, whereby total compensation may far exceed base salary depending on individual performance. Actual compensation offered may vary from posted hiring range based upon geographic location, work experience, education, licensure requirements and/or skill level and will be finalized at the time of offer.

Equal opportunity employer •  Drug-free workplace

We are an equal opportunity employer with a commitment to diversity.  All individuals, regardless of personal characteristics, are encouraged to apply.  All qualified applicants will receive consideration for employment without regard to age (40 and over), race, color, national origin, ancestry, sex, sexual orientation, gender, gender identity, gender expression, marital status, pregnancy, religion, physical or mental disability, military or veteran status, genetic information, or any other status protected by applicable state or local law.

***For remote and hybrid positions you will be required to provide reliable high-speed internet with a wired connection as well as a place in your home to work with limited disruption. You must have reliable connectivity from an internet service provider that is fiber, cable or DSL internet. Other necessary computer equipment, will be provided. You may be required to work in the office if you do not have an adequate home work environment and the required internet connection.***

Job Posting End Date at 12:01 am on:
10-16-2026

Want the latest money news and views shaping how we live, work and play? Stay in the know with The Currency  and sign up for Empower’s free newsletter.