372,956open jobs
9,661companies
50,233added this week
Browse all
Salary
$144k – $311k per year (Estimated)
Location
Remote (United States)
Seniority
Architect · 15+ years exp
Overview
Company
Impact
Profile match
KLDiscovery provides technology-enabled services and software to help law firms, corporations, government agencies and consumers solve complex data challenges. The company, with 1,000+ employees in 30+ locations across 18 countries, is a global leader in delivering best-in-class eDiscovery, information governance and data recovery solutions to support the litigation, regulatory compliance, internal investigation and data recovery and management needs of our clients. Serving clients for over 30 years, KLDiscovery offers data collection and forensic investigation, early case assessment, electronic discovery and data processing, application software and data hosting for web-based document reviews, and managed document review services.

Role overview

The Director, Cybersecurity Operations leads Security Operations and Incident Response, Security Engineering, Vulnerability Management, and Threat Intelligence. This is a player-coach leadership role reporting directly to the CISO, partnering with the Director, Cyber GRC as one unified cyber team. The Director will bring hands-on technical depth, strong leadership capability, and the ability to modernize security operations through MDR deployment, AI-informed detection, and a security engineering team organized around functional specialization.

Key responsibilities

Security operations and incident response Security operations and incident response

  • Own the MDR relationship, including SLA management, escalation accountability, detection tuning, and quarterly threat hunt reviews

  • Lead the incident response function: IR runbooks, major incident coordination, executive communication during active incidents, and post-incident root cause analysis

  • Oversee SOC detection engineering, ensuring SIEM rules, SOAR playbooks, and automated response actions are maintained, tested, and tuned to the current threat landscape

  • Direct and develop the security analyst pool, redeploying analyst capacity from frontline triage toward MDR validation, threat hunt support, and stakeholder reporting

Security engineering

  • Oversee four specialized engineering lanes [endpoint, identity, cloud, and application security], ensuring each lane has clear ownership, defined scope, and measurable outcomes

  • Drive security architecture reviews and engineering decisions for large or complex IT projects, ensuring security requirements are built in rather than bolted on

  • Shape the security tooling stack strategy, evaluating, selecting, and retiring tools across endpoint, identity, cloud, and application security

  • Enforce automation-first engineering practices, including IaC security gates, CI/CD pipeline security, CSPM auto-remediation, and SOAR-driven response workflows

Threat intelligence, vulnerability management, and control validation

  • Lead the operationalization of threat intelligence, translating MDR findings and external threat data into detection rule updates, architecture decisions, and risk register inputs for the GRC team

  • Own the vulnerability management lifecycle: scanning coverage, risk-based prioritization, remediation tracking, and SLA enforcement

  • Own the purple team and control validation program, confirming that deployed controls operate as intended and that detection capabilities fire correctly against known attack techniques

  • Drive threat modeling across the engineering function, identifying attack paths before they are exploited and feeding findings into remediation prioritization

AppSec, cloud, and AI security

  • Oversee the AppSec function: secure SDLC, code review gates, SAST/DAST tooling, and security collaboration with the Product and Engineering teams

  • Own cloud security posture management: CSPM, cloud workload protection, cloud IAM governance, and cloud-native security architecture

  • Set the team-wide AI security posture, overseeing AI security controls across all engineering lanes, including model security, prompt injection testing, and AI tool access governance in partnership with cyber leadership

MDR, automation, and tooling modernization

  • Lead the ongoing maturation of the MDR deployment, expanding coverage, improving response fidelity, and integrating MDR outputs with internal SIEM, IAM, and compliance evidence workflows

  • Champion security automation across the team, reducing manual toil in detection, response, vulnerability tracking, and reporting through SOAR, scripting, and platform integrations

  • Evaluate emerging security technologies and make build/buy/partner recommendations to the CISO with clear business and risk rationale

Team leadership and CISO partnership

  • Lead, develop, and performance-manage a lean engineering team

  • Partner with the Director, Cyber GRC as one unified cyber function, feeding operational threat intelligence into the risk register, supporting compliance evidence for technical controls, and jointly presenting security posture

  • Provide regular metrics and reporting to the CISO on incident trends, control coverage, MDR performance, vulnerability posture, and team development

  • Build a team culture of continuous improvement, automation-first execution, and proactive security, where threat hunting and control validation are protected activities rather than aspirational ones

Qualifications

Experience

  • 15+ years of progressive experience in information security, including at least 7 years in a security leadership role

  • Demonstrated ownership of a security operations or engineering function at the Director or equivalent level

  • Experience operating and maturing an MDR deployment (CrowdStrike Falcon Complete, Arctic Wolf, Expel, or equivalent) in a corporate environment

  • Hands-on background in at least two of the following: security engineering, penetration testing/offensive security, cloud security, application security, or incident response; this is not a purely strategic role

  • Demonstrated experience deploying or maturing security automation, such as SOAR playbooks, detection engineering, IaC security, or CI/CD pipeline security

  • Familiarity with cloud-native security (AWS, Azure, or GCP), including CSPM, cloud IAM, and workload protection

Technical knowledge

  • Working knowledge of cybersecurity frameworks such as NIST SP 800-171, ISO 27001, and SOC 2

  • Understanding of the vulnerability management lifecycle: scanning, prioritization, remediation tracking, and SLA enforcement

  • Familiarity with AppSec disciplines: SAST/DAST tooling, secure SDLC, and security gate integration into CI/CD

  • Understanding of IAM security governance (PAM, access review programs, and SSO/MFA architecture) as distinct from IT provisioning execution

  • Experience with AI security considerations (model testing, prompt injection, AI tool access governance, and emerging AI governance frameworks such as the NIST AI RMF and ISO 42001) is a meaningful differentiator

  • Foundational awareness of CMMC requirements

General abilities

  • An exceptional communicator, able to translate complex cyber risk and compliance concepts into clear business language for executives, clients, and regulators alike

  • A natural collaborator and client-facing presence, comfortable leading enterprise client security discussions, representing KLDiscovery in due diligence meetings, and building trust with external stakeholders

  • Business-minded, balancing security requirements against commercial realities and making practical decisions without sacrificing rigor

  • A continuous learner with genuine curiosity, energized by a fast-growing company and a rapidly evolving regulatory and threat landscape

  • Discreet and trusted, exercising sound judgment, maintaining confidentiality, and operating with professionalism

Education

  • Bachelor's degree in Information Security, Computer Science, Engineering, Business, or a related field required

  • Professional certifications such as CISSP, CISM, CISA, GPEN, GCIA, or other GIAC certifications strongly preferred

  • Master's degree or MBA with a security focus preferred

Our mission and core values

We bring clarity, trust, and meaning to data for clients navigating legal matters worldwide.

Client is Always in the Room. We operate and make decisions as if the client is in the room. We anticipate their needs, consider their perspective, and prioritize their best interests.

Better Every Day. We improve our tomorrow by always striving to be better than today. We embrace curiosity, question assumptions, and raise the bar constantly.

Own the Outcome. We bring an unwavering bias for action, act with urgency, and hold ourselves accountable to our clients and each other.

Deliver Results Together. We collaborate obsessively to achieve shared success. We assume good intentions, debate ideas thoughtfully, treat each other with respect, and fully commit once decisions are made.

Our culture shapes our actions, our products, and the relationships we forge with our customers.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
372,956 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$26k – $51k per year (Estimated) • In office • Full-Time • 5+ years exp • Pune
Python
SQL
Python
pySpark
AI/ML
AI Agents
Prompt Engineering
RAG
Spark
DevOps
AWS
Azure
CI/CD
GCP
Analytics
ETL/ELT
Apply
$104k – $212k per year (Estimated) • In office • Full-Time • 10+ years exp • Master's Degree • Singapore
C++
Java
Node JS
TypeScript
JavaScript
Frontend
GraphQL
React.js
DevOps
Amazon CloudWatch
AWS
Azure
CI/CD
Datadog
Docker
Kubernetes
Splunk
Terraform
Apply
$26k – $67k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bengaluru
Java
Java
Spring Boot
Spring Cloud
Databases
Apache Kafka
Snowflake
Mobile
MVP
DevOps
AWS
Azure
Chaos Engineering
Docker
GCP
Grafana
IAM
Kubernetes
OpenTelemetry
Platform Engineering
Prometheus
SLI/SLO/SLA
Terraform
Apply
$88k – $201k per year (Estimated) • In office • Full-Time • 10+ years exp • Master's Degree • Singapore
C++
Java
DevOps
AWS
Azure
Apply
Data Engineer 1 day ago
$30k – $59k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Bengaluru
Python
SQL
Python
pySpark
Databases
Amazon Redshift
Apache Kafka
DynamoDB
Snowflake
AI/ML
ChatGPT
Claude
Cline
Copilot
Spark
DevOps
Amazon EC2
AWS
AWS Lambda
CI/CD
Docker
Jenkins
Kubernetes
Terraform
Amazon Kinesis
Amazon S3
AWS Step Functions
IAM
Management
ServiceNow
Apply
In office • 6+ years exp • Bachelor's Degree
Bash
PowerShell
DevOps
Ansible
Azure
Docker
Kubernetes
Terraform
Ubuntu
VMWare
Windows Server
Cybersecurity
ISO 27001
Least Privilege
Apply
Software Engineer II 23 days ago
Remote/Hybrid • 3+ years exp
C#
SQL
TypeScript
JavaScript
C#
ASP.NET Core
Blazor
Entity Framework Core
Databases
MS SQL
AI/ML
Claude
Claude Code
Frontend
Angular
DevOps
Azure
Azure DevOps
GitHub
Cybersecurity
SonarQube
Apply
$74k – $155k per year (Estimated) • Equity • Remote • Bachelor's Degree
Management
Microsoft Project
Apply
$140k – $160k per year • In office
C#
SQL
TypeScript
JavaScript
C#
.NET
Databases
PostgreSQL
Frontend
Angular
DevOps
Azure
Azure DevOps
GitHub
Apply
$190k – $225k per year • In office • 10+ years exp • Bachelor's Degree
DevOps
CI/CD
Cybersecurity
ISO 27001
SOC 2
Apply
See all jobs
This is one of many
372,956 more open roles from verified company boards, updated every day.