SAP NS2 Director, Cyber Security Operation Center (CSOC) - Hybrid
Herndon, VA, US, 20171
Full Time Executive-level / Director USD 164K - 280K
SAP
Explore market-leading software and technology from SAP. Become an intelligent, sustainable enterprise with the best in cloud, platform, and sustainability solutions – no matter your industry or size.We help the world run better
At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from.
Company Description:
SAP is the global market leader for business software and related services. SAP National Security Services Inc.® (SAP NS2®) is an independent U.S. subsidiary, offering SAP solutions with specialized levels of security and support to meet the requirements of U.S. national security and critical infrastructure customers.
Must be a US Citizen on US soil; this position requires access to customer data.
All internals must have Manager’s approval to transfer.
Candidates must be within a commutable distance to Herndon, VA with the expectation to be in office 3 days per week.
Position Overview:
Reporting directly to the Senior Director, Security Operations within Enterprise Security, the Director of the Cyber Security Operations Center (CSOC) leads intelligence gathering, security monitoring, incident response, and forensic analysis operations. The Director collaborates closely with Security Operations vulnerability management teams, Security Engineering, Governance, Risk, and Compliance, and applicable Operations Teams to uphold cyber hygiene standards, mitigate security risks, and enable business intelligence.
Key Responsibilities:
- Lead and coordinate the Security Operations Center’s 24x7 monitoring and response activities for corporate and customer cloud environments.
- Direct and manage intelligence collection, threat analysis, incident response, and forensic investigative efforts.
- Provide comprehensive cybersecurity posture and incident response updates to senior executives, including the Chief Information Security Officer, Chief Security Officer, C-Suite, and executive Insider Threat Team as appropriate.
- Develop and implement a threat driven detection capability incorporating continuous improvements in cybersecurity operational processes, incident management practices, and risk mitigation strategies that affords an appreciating investment for SAP NS2.
- Oversee technical and operational analysis during cyber events and/or incidents, ensuring alignment with applicable governance requirements, organizational Information Security Policies and industry best practices.
- Manage a team of cybersecurity professionals responsible for threat analysis, reporting, executive briefings, and coordination of remediation efforts.
- Define and validate technical requirements for incident response tools and ensure these technologies support and enhance operational workflows.
- Recommend and oversee configuration enhancements to improve cybersecurity analysis tools’ effectiveness and usability.
- Maintain expertise in cybersecurity trends and threats through active participation in industry task forces, professional networks, and continuous monitoring of security advisories.
- Proactively communicate and manage the potential impacts of emerging cyber threats and vulnerabilities to key business stakeholders.
- Oversee device security management, including timely upgrades and patches, ensuring comprehensive remediation and threat eradication capabilities.
Qualification Requirements:
- Applicants must be U.S. citizens residing within the United States.
- Minimum of 4 years' experience leading or managing functions within a Security Operations Center (SOC).
- At least 10 years' experience in security operations management, incident response, threat analysis, vulnerability management, and security monitoring.
- Demonstrated proficiency in cybersecurity incident response processes, including the capability to oversee detailed incident analysis.
- Extensive experience managing cybersecurity teams responsible for threat analysis, incident reporting, executive briefings, and remediation coordination.
- Strong familiarity with industry-standard cybersecurity frameworks such as NIST, ISO, and PCI.
- Hands-on experience and comprehensive understanding of Security Information and Event Management (SIEM) systems.
- Expertise in unified threat management, antivirus solutions, threat intelligence, vulnerability management, cybersecurity investigations, and forensic analysis.
- Advanced knowledge of best practices related to information systems security, data security, and infrastructure protection.
- Exceptional organizational, leadership, and time-management skills, with the ability to prioritize effectively and drive high-quality results.
- Strong networking fundamentals and comprehensive security knowledge.
- Proven ability to manage complex tasks and projects, set appropriate stakeholder expectations, and maintain rigorous standards for security operations.
- Ability to apply analytical techniques when gathering information from stakeholders, define problems, design technical solutions, develop procedures to solve problems, and implement for execution. Demonstrated integrity and professional judgment, with experience managing sensitive and confidential information appropriately.
- Expertise in measuring operational performance using defined key performance indicators (KPIs) specific to SOC environments that serves compliance, risk, and business intelligence needs.
- Outstanding verbal and written communication skills, emphasizing clear, prompt, and accurate information dissemination, particularly during security events and/or incidents to stakeholders with varying levels of technical acumen.
- Ability for infrequent travel for meetings as required.
Desired Education and Certifications:
- Bachelor's degree preferred; relevant experience may substitute for educational requirements.
- Professional certifications such as CISSP, CISSP-ISSEP, CISSP-ISSAP, CISSP-ISSMP, ITIL, CISM, GSEC, GCIA, GCED, SEC503, CCNA, RHCE, or specific SIEM certifications are highly desirable.
We win with inclusion
SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better world.
SAP is committed to the values of Equal Employment Opportunity and provides accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careers@sap.com.
For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.
Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability, in compliance with applicable federal, state, and local legal requirements.
Compensation Range Transparency: SAP believes the value of pay transparency contributes towards an honest and supportive culture and is a significant step toward demonstrating SAP’s commitment to pay equity. SAP provides the annualized compensation range inclusive of base salary and variable incentive target for the career level applicable to the posted role. The targeted combined range for this position is 164700 - 280100(USD) USD. The actual amount to be offered to the successful candidate will be within that range, dependent upon the key aspects of each case which may include education, skills, experience, scope of the role, location, etc. as determined through the selection process. Any SAP variable incentive includes a targeted dollar amount and any actual payout amount is dependent on company and personal performance. Please reference this link for a summary of SAP benefits and eligibility requirements: SAP North America Benefits.
Tags: Antivirus Business Intelligence C CISM CISO CISSP Cloud Compliance CSOC GCED GCIA Governance GSEC Incident response ITIL KPIs Monitoring NIST SAP SIEM SOC Threat intelligence Vulnerabilities Vulnerability management
Perks/benefits: Career development Equity / stock options Flex hours Health care Team events Transparency
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.