Jobs and Careers
UN

Director, Security Operations

University of Delaware
United Statesfull_timeVerifiedPosted 3 Mar 2026

About the role

Pay Grade: 33S   Context of Job The Director of Security Operations is a senior cybersecurity leader responsible for designing, executing, and continually improving the institution’s security operations capabilities. This role provides strategic and hands-on leadership across the Security Operations Center, incident response, digital forensics, vulnerability management, endpoint detection and response (EDR/XDR), firewall and network security, and coordination with Managed Detection and Response (MDR) providers.

The Director works closely with central IT, schools and colleges, legal counsel, privacy, compliance, and external investigators to ensure effective detection, response, investigation, and recovery from cybersecurity incidents in a complex higher-education environment that includes on-premises, cloud, and research systems. This role is accountable for ensuring cybersecurity operations balance risk reduction with usability and operational needs across academic, administrative, research, and affiliated units.

The Director, Security Operations and SOC, reports to the Chief Information Security Officer (CISO).
Major Responsibilities:
Security Operations & SOC Leadership
  • Establish and lead a mature, outcomes-driven SOC operating model aligned with higher education risk, academic openness, and regulatory requirements.
  • Define SOC strategy, operating procedures, escalation models, and service maturity roadmap.
  • Lead, mentor, and develop SOC analysts, incident responders, and security engineers across distributed campus environments.
  • Provide operational leadership supporting multiple schools, colleges, research units, and administrative systems.
  • Ensure technical security controls, processes, and services operate effectively to support prevention, detection, response, and recovery capabilities.
  • Act as a change agent, driving the adoption of new security technologies and operational processes to improve cyber resilience.
  • Lead multiple security operations teams and initiatives concurrently, prioritizing service improvement projects based on risk and value.
  • Threat Detection, MDR & EDR/XDR
  • Own threat detection and response across networks, endpoints, servers, cloud platforms, and SaaS environments.
  • Serve as the primary institutional owner for MDR services, ensuring alignment with internal SOC workflows, SLAs, and escalation paths.
  • Oversee EDR/XDR platforms, detection tuning, threat hunting, and response automation.
  • Validate detection coverage using frameworks such as MITRE ATT&CK.

Incident Response, Forensics & Investigations
  • Lead security incident response activities, including containment, eradication, recovery, and post-incident analysis.
  • Develop, maintain, and regularly test incident response plans (IRP), playbooks, and tabletop exercises.
  • Oversee digital forensics investigations, including endpoint, network, log, and cloud-based forensic analysis.
  • Coordinate litigation holds, evidence preservation, and chain-of-custody requirements in collaboration with Legal, Compliance, and Privacy offices.
  • Act as the primary security liaison with external investigators, law enforcement, cyber insurance carriers, and third-party forensic firms when required.
  • Ensure proper documentation and reporting for regulatory, legal, and institutional requirements.
  • Oversee digital forensics activities, including endpoint, network, cloud, and application-level investigations.
  • Coordinate with Legal, Privacy, and Compliance teams to support litigation holds, evidence preservation, and regulatory inquiries.
  • Engage and manage external investigators, cyber insurance partners, and third-party forensic firms during major incidents.
  • Ensure incident response activities support post-incident reporting, lessons learned, and operational improvements.
  • Cloud & Modern Infrastructure Security
  • Lead security operations for cloud platforms (e.g., Azure, GCP, AWS), including incident response and forensic investigations in cloud-native environments.
  • Partner with system, network, HPS, infrastructure, and enterprise application teams to integrate security logging, monitoring, and response into cloud and hybrid architectures.
  • Oversee security operations for SaaS platforms commonly used in higher education.
  • Provide oversight for application and platform security testing, including secure development practices and DevSecOps integration.
  • Support cloud-native forensic investigations and security monitoring across IaaS, PaaS, and SaaS platforms.
  • Ensure security operations integrate with modern application delivery pipelines and enterprise platforms.
<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

University of Delaware

View company profile →