- Company Name
- PwC Canada
- Job Title
- Security Operations Director
- Job Description
-
Job Title: Security Operations Director
Role Summary: Lead the strategy, delivery, and continuous improvement of Security Operations Center (SOC) and Managed Detection & Response (MDR) services for a global client portfolio, ensuring 24/7 operational excellence, rapid incident response, and proactive threat hunting across IT and OT environments.
Expactations: Deliver a compelling security vision aligned with client business goals; maintain high‑performance, geographically dispersed cyber teams; uphold stringent SLA/SLO commitments; drive innovation through emerging threat intelligence and advanced tooling; bridge the gap between technical teams and non‑technical stakeholders with clear communication.
Key Responsibilities:
- Define and execute the strategic roadmap for SOC and MDR functions, integrating best‑practice frameworks (NIST, ISO, SANS).
- Direct and mentor cross‑regional cybersecurity teams in a 24/7 environment, fostering a culture of continuous improvement.
- Collaborate with internal practice leaders to design integrated security solutions, including threat hunting, playbook automation, and threat content delivery.
- Oversee SOC operational readiness, tool stack selection, and process optimization to maximize detection, containment, and recovery efficiencies.
- Conduct regular capability assessments, gap analyses, and action plans for SOC and MDR service enhancements.
- Engage clients in security strategy sessions, translating complex technical concepts into actionable business recommendations.
- Manage client expectations around SLA/SLO, incident response timelines, and project delivery schedules.
- Serve as subject matter expert in incident response, threat hunting, and security operations for both IT and OT environments, especially within Power and Utilities sectors.
Required Skills:
- 8–10+ years of progressive security operations leadership with proven ability to manage large, distributed teams.
- Deep expertise in SIEM, EDR, threat intelligence platforms, cloud security (AWS, Azure, GCP, OCI), and OT security.
- Strong incident response experience covering containment, eradication, and recovery across hybrid environments.
- Excellent communication and presentation skills, capable of explaining technical details to senior business stakeholders.
- Strategic thinking with the ability to translate security frameworks into practical, client‑focused solutions.
- Experience in managing client SLAs, maintaining operational reporting, and ensuring compliance with industry standards.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Certifications: CISSP, CISM, OSCP, or GCIH (GIAC Certified Incident Handler).
- Demonstrated knowledge of NIST, ISO, or SANS frameworks and proven ability to apply them in a client environment.