Director, Cybersecurity Operations Center
Brentwood, TN, US, 37027
Are you looking for a career in a dynamic and innovative company that values versatility, growth, and teamwork? Look no further than Delek US Holdings!
WHAT IS DELEK? WHAT DO WE DO?
We are a boutique-sized diversified downstream energy company with a range of assets, including petroleum refining and logistics.
-
Our refineries in Texas, Arkansas, and Louisiana have a combined crude capacity of 302,000 barrels per day
-
Our logistics business currently owns and operates 720 miles of crude and product pipelines, a 600-mile crude oil gathering system, and storage tanks and terminals.
DELEK BENEFITS:
We offer fantastic benefits that include up to a 10% match on 401K on your hire start, with a vesting timeline of only one year, along with medical benefits that start on day one with a 30% premium rebate annually! We value your well-being and all employees now have access to the Calm app for FREE, which is used for meditation, stress management, and better sleep. Through our performance management program, you can earn additional annual incentives as you set and achieve goals. Our pay for performance culture motivates our employees to improve Delek’s year-over-year company, business unit, and individual results. With some of the highest bonus payouts in recent years, we know that our success is due to our talented and dedicated team. We are looking for individuals like you to help us continue this momentum and bring new ideas to the table. At Delek, you will have the opportunity to make an impact and grow your career in a supportive and innovative environment.
JOB SUMMARY
Leads Security Operations with primary responsibility for running the Security Operations Center (SOC), directing 24x7x365 monitoring, detection, triage, investigation, escalation, and response activities across Information Technology (IT), Operational Technology (OT), cloud, identity, network, endpoint, and third-party environments. Serves as a decisive incident commander during cyber security events by rapidly assessing severity, establishing priorities, assigning ownership, coordinating cross-functional response teams, briefing executive leadership, and driving incidents through containment, eradication, recovery, and post-incident improvement. Ensures that cyber security monitoring, detection, response, incident management, threat intelligence, threat hunting, and SOC processes are aligned with IS standards, cyber security standards, and overall cyber risk management objectives. Identifies cyber threats, suspicious activity, security incidents, and operational exposures; determines the scope, severity, and business impact of cyber events; and coordinates procedures to contain incidents, restore normal operations, and improve future detection and response capabilities. Develops techniques and procedures for conducting cyber security monitoring, alert triage, incident investigation, threat analysis, threat hunting, digital evidence collection, cyber readiness exercises, and post-incident reviews. Leads investigation and resolution of cyber security incidents such as intrusions, malware activity, unauthorized access, fraud, attacks, data loss events, or leaks.
EDUCATION AND EXPERIENCE
-
4 year / Bachelor's Degree (Required)
-
In lieu of the above education requirements, an equivalent combination of education and experience may be considered.
-
Four (4) or more years management experience (Required)
-
Four (4) or more years experience leading a SOC, MDR function, incident response team, or cyber defense analysts with direct accountability for monitoring, detection, escalation, incident command, and response execution (Required)
-
Ten (10) or more years experience of relevant related field of Security Operations, Monitoring & Detection, Incident Response, Threat Intelligence, Threat Hunting, Digital Forensics, or Cyber Defense (Required)
-
Preferred Certifications/Licensures: (Cyber security related certifications such as CISSP, GSEC, etc)
JOB REQUIREMENTS
-
Proven experience serving as incident commander for complex cyber incidents across IT and OT, including executive coordination, business impact assessment, response decision-making, regulatory reporting, and post-incident corrective action
-
Skilled in using SIEM, SOAR, EDR/XDR, NDR, forensic, threat intelligence, and security monitoring tools, with a strong grasp of frameworks like NIST, MITRE ATT&CK, and ISA/IEC-62443
-
Strong organizational skills and ability to set priorities and handle multiple projects concurrently
-
Knowledge of cyber threat and/or intelligence analysis
-
Knowledge of cyber incident response, threat hunting, detection engineering, malware investigation, and digital forensics practices
-
Solid understanding of cyber security and ability to analyze incident reporting, investigation results, response actions, and follow-up with reporting sites
-
Strong knowledge of incident management, problem management and change management best practices
-
Lead operational engagements with internal teams, managed security providers, incident response partners, and technology vendors to support security monitoring, threat detection, and cyber response services
-
Program Management: Partner with PMO team to oversee portfolio of cyber security operational services and pipeline of projects/tasks to create, evolve, and improve monitoring, detection, and response capabilities
-
Responsible for developing, maintaining, and continuously improving the Security Operations operating model, including SOC coverage, alert intake, triage, escalation, investigation, response coordination, performance measures, and integration.
-
Ensure monitoring services are being fulfilled 24x7x365
-
Provide direct leadership, oversight, direction, scheduling, quality control, and performance management for SOC activities, analysts, service providers, and escalation processes
-
Establish and enforce incident command structure, escalation criteria, communication cadence, decision logs, action tracking, and after-action review practices for cyber security events
-
Perform review and validation of all deliverables for SOC, Incident Response, Threat Intelligence, Threat Hunting, Detection Engineering, and other assigned activities
-
Develop policies, instructions, standards, and procedures around security operations functions
-
Provide Metrics and Artifacts supporting audit activities
-
Brief executives about current cyber threats, incidents, operational readiness, and pertinent information
-
Ensure timely and accurate reporting to all relevant stakeholders (Internal & External)
-
Responsible for overall use of resources and initiation of corrective action where required for Security Operations Center activities
-
Perform threat management, identify threat vectors, monitor relevant threat actors, and develop use cases for security monitoring
-
Develop, tune, validate, and maintain security monitoring use cases, detection content, alert logic, response workflows, and escalation procedures
-
Lead threat hunting activities to identify indicators of compromise, anomalous activity, and previously undetected threats
-
Translate cyber threat intelligence into actionable monitoring, detection, hunting, and response procedures
-
Coordinate with Cybersecurity Architecture, Infrastructure, Applications, Governance, Risk & Compliance, and business teams to ensure effective operational response to identified threats, vulnerabilities, and incidents
-
Conduct cyber readiness exercises, tabletop exercises, and incident response simulations to validate operational preparedness
-
While this job description aims to provide a comprehensive overview of the role, it may not detail every task or responsibility required.
CORE COMPETENCIES
CHANGE AGILITY (LEVEL 4 LEADING)
Identifies, initiates, and adapts to organizational changes that foster enhanced effectiveness, efficiency, safety, and ultimately business results.
COLLABORATION (LEVEL 4 LEADING)
Sees connection points across the organization and partners effectively with others to achieve common goals.
DECISION MAKING (LEVEL 4 LEADING)
Selects a course of action to reduce risk and uncertainty and create optimal outcomes.
DRIVE FOR RESULTS (LEVEL 4 LEADING)
Drives to achieve challenging performance objectives.
TEAM BUILDING (LEVEL 4 LEADING)
Builds trust, fosters openness, and provides support. As the manager of a team, selects and motivates a strong team.
#LI-MG1
We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or national origin, disability status, protected veteran status, or any other characteristic protected by law. Equal Opportunity Employer/Disabled/Veterans.
Nearest Major Market: Nashville
Job Segment:
Operations Manager, Pipeline, Engineer, Change Management, Manager, Operations, Energy, Engineering, Management