- Location
- Columbus (Dublin), Ohio, United States of America · OH - Cleveland
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Operations
- Seniority
- Director
- Visa
- Not sponsored
- Source
- Workday
Description
As BWE’s Director of Security Operations (SecOps), you are the senior hands-on security expert accountable for the engineering and operational effectiveness of BWE’s security program. You lead a three-person security team as a player-coach, staying deep in the technology yourself, leading incident response, tuning platforms, and making the technical calls. You protect an environment of over 600 users, 700 endpoints, and 30 office locations across a best-of-breed security stack layered over Microsoft 365 and Azure and delivered with an MDR partner, in a regulated commercial real estate finance business examined by GSEs, rating agencies, and clients.
Primary Responsibilities:
● Team Leadership: Lead a team of three security professionals as an active technical contributor, setting standards, reviewing work directly, coaching, and stepping into complex technical issues.
● Security Engineering: Own, configure, tune, and troubleshoot BWE’s security stack, taking platforms beyond implementation into measurable coverage and enforced controls.
● Platform Rationalization: Evaluate the security tool portfolio for coverage, overlap, and cost, and recommend consolidation or retirement.
● Detection and Response: Own detection and response outcomes, including alert quality, tuning, escalation, and vendor accountability.
● Detection Engineering: Set detection, logging, and telemetry standards across cloud, SaaS, endpoint, identity, and data platforms, and turn threat intelligence into actionable detections and hunts.
● Incident Command: Serve as security incident commander from triage through recovery and post-incident review, building and rehearsing playbooks and taking part in the security on-call rotation.
● Vulnerability Management: Drive vulnerability management from discovery and prioritization through remediation and verification, supported by asset inventory and attack surface management.
● Security Architecture: Set security architecture standards for cloud, SaaS, infrastructure, applications, and data platforms, and define security-by-design requirements for new technology.
● Data Protection: Implement and operate data protection controls for confidential financial information, including classification, encryption, retention enforcement, and data loss monitoring.
● Application Security: Maintain secure SDLC practices for internally developed applications, including code scanning standards, software supply chain security, and application security assessments.
● Vendor Security: Assess and monitor the security of third parties based on the sensitivity of the data and access involved, including due diligence and contractual security requirements.
● Cyber Risk Assessment: Lead cyber risk assessment activities, including penetration tests, tabletop exercises, CIS control and identity reviews, and social engineering, driving findings to closure.
● Security Governance: Partner with the Chief Digital Officer and Compliance on information security policies and standards, and own the technical standards and procedures that implement them.
● Control Framework Alignment: Maintain BWE’s alignment to NIST CSF and CIS Controls, including periodic maturity assessment and tracking of control gaps to closure.
● Audit Response: Implement, operate, and evidence technical controls for Fannie Mae, Freddie Mac, HUD and FHA, rating agency, and client security requirements and examinations.
● Security Automation: Use scripting, APIs, playbooks, and AI to automate detection, response, investigation, and reporting, reducing manual effort across security operations.
● Cyber Resilience: Partner with Technology Operations to test and improve cyber resilience and recovery.
● Security Awareness: Own the security awareness program, measured on behavior change.
● Security Performance Reporting: Own operational security metrics, including control coverage, detection and response performance, and vulnerability remediation.
● Business Partnership: Serve as a visible security partner to Legal, Compliance, HR, and business teams, and support the CDO in representing BWE’s security to clients, rating agencies, and GSEs.
Shared Responsibilities (with Director of Technology Operations):
● Patching: Set patching standards, priorities, and compliance expectations and govern exceptions, with Technology Operations executing across supported platforms and endpoints.
● Incident Response and Remediation: Lead security triage, investigation, and forensics and define corrective actions, while Technology Operations leads service restoration and tracks closure.
● Vulnerability Identification and Remediation: Own discovery, prioritization, and validated closure, with Technology Operations remediating on the systems, platforms, and endpoints it manages.
Minimum Qualifications:
● 10+ years of cybersecurity experience with significant recent hands-on security engineering and operations responsibilities.
● 3+ years leading technical security professionals while continuing to contribute technically.
● Hands-on depth across most of: EDR, cloud security, email security, data security, privileged access, SIEM and detection engineering, and vulnerability management.
● Direct experience managing an MDR or MSSP and holding the provider accountable for measurable detection and response outcomes.
● Experience serving as technical lead for security incidents from triage through remediation and post-incident review.
● Experience implementing, operating, and evidencing technical security controls against financial services regulatory and contractual requirements.
● Ability to automate security work using PowerShell, Python, APIs, or equivalent technologies.
● Bachelor’s degree in a related field or equivalent practical experience.
Preferred Qualifications:
● Experience working with Fannie Mae, Freddie Mac, or another GSE, including translating GSE security requirements into evidenced technical controls.
● Experience in commercial real estate finance, multifamily or mortgage banking, or another lending environment subject to GSE, investor, and state regulatory requirements.
● Secure SDLC and application security experience in custom-development environments, including securing enterprise AI platforms.
● Demonstrated use of AI and automation to improve security operations, and hands-on certifications such as CISSP, GCIH, GCFA, or OSCP.
● Familiarity with platforms in BWE’s stack such as Expel, CrowdStrike, Wiz, Abnormal AI, Varonis, CyberArk, BeyondTrust, Recorded Future, Veeam, and Microsoft Purview.
We encourage you to explore the career opportunities we have available here at BWE!
Please note, BWE will not sponsor applicants for this position for immigration benefits, including but not limited to assisting with obtaining work permission for F-1 students, H-1B professionals, O-1 workers, TN workers, E-3 workers, among other immigration statuses. Applicants must be currently authorized to work in the United States on a full-time basis.