Gartner logo
Gartner

We deliver actionable, objective insight that drives smarter decisions and stronger performance.

Senior Director Analyst - Security Operations, Threat Detection, Response and Automation

Security OperationsSecurity OperationsFull TimeRemoteLeadTeam 10,001+Since 1979H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

80 days ago

Salary

$172K - $202K / year

Seniority

Lead

No structured requirement data.

Job Description

Senior Director Analyst - Security Operations, Threat Detection, Response and Automation

Gartner

Senior Director Analyst - Security Operations, Threat Detection, Response and Automation What makes Gartner Research a GREAT fit for you? - You are a team player who values expert insights, bold ideas and intellectual courage. - You are always learning and looking to discover what’s next in technology. - You believe that good technology needs to be balanced with good governance, planning and process. - You pursue personal excellence through team collaboration and consensus If this describes you, Gartner is looking for you! Gartner is an upbeat culture based on collaboration, teamwork, integrity and objectivity that values creativity and innovation. As a Gartner analyst, you’ll not only help clients solve complex challenges and deliver on key initiatives, you’ll grow your career and the scope of your impact across industries. We work hard — and we reward success with exceptional opportunity. About this role: This role creates thought leading security operations, monitoring and vulnerability management research to our Gartner for Technical Professionals clients through published research, conversations with client (Inquiry), stage presentations, teleconferences, and client meetings. It is important that you have a vision for how security operations, threat detection, response and automation will evolve worldwide and at a regional level. What you’ll do: As a Gartner analyst you will meet with clients every day: on the phone, in a video-conference, from the stage at a Gartner event or face-to-face during a sales support visit. In every client interaction analysts help clients solve difficult puzzles that lead to better performance. To support these conversations you will research technology, practices and trends and produce written research for Gartner clients to download and apply. - Conduct research and analysis in specific areas of expertise targeting client’s key initiatives. - Deliver high quality actionable advice through a variety of media. - Write high quality, clear, actionable, advisory research documents. - Remain ahead of the curve on developments and issues within these specified areas as well as applicable adjacent areas. - Articulate and defend assigned topic positions during discussions, while demonstrating openness to reconsidering viewpoints and accepting consensus decisions - Respond to client questions, create materials for and deliver to clients in person, via teleconference, video conference or webinar and event presentations - Maintain the Gartner’s industry leadership reputation by responding to press inquiries - Proactively work with the wider sales organization and deliver outstanding sales support to retain and grow the business What you’ll need: It helps to be obsessed with your topic! Gartner analysts are correctly viewed as THE experts. This means you need to know your markets, vendors, trends, management practices, etc. and be able to see the forest and the trees. Most Gartner analysts have many years of experience and enjoy solving puzzles. - Subject matter expertise in security operations, threat detection, incident response and automation technologies, with the ability to demonstrate understanding of the business requirements and opportunities in that market - Knowledge of security information and event management (SIEM) systems - Knowledge of threat detection sources that contribute and integrate into the SOC ecosystem and security platforms, like SIEM and security data lakes. - Knowledge of security operations in on-premises and cloud environments - Knowledge of incident response and/or threat hunting processes and relevant technologies - Knowledge of security operations center processes, metrics and reporting to both technical and executive audiences - Knowledge security automation solutions such as AI SOC agents and security automation features in platforms like SIEM - Ability to mentor security staff at all levels for their role and personal development. - Broad understanding of operational security internally and under a commercial framework. - Knowledge of the global landscape, and the competitive interplay between incumbents, emerging providers, disruptors and outsourcers - Demonstrated superior analytical skills, applying conceptual models, recognizing patterns while drawing and defending conclusions. Strong business and financial acumen as well as analytical skills are required for this position - Articulate and succinct communication skills. Publishing and Speaking engagements an advantage - Minimum of 12 years of experience in a security architect or security operations related role - Bachelor's or equivalent experience, Master's degree preferred - Ability to conduct occasional travel, regionally and globally - Experienced public speaking and executive presence with security and business leaders #LI-AJ3 Who are we? At Gartner, Inc. (NYSE:IT), we guide the leaders who shape the world. Our mission relies on expert analysis and bold ideas to deliver actionable, objective business and technology insights, helping enterprise leaders and their teams succeed with their mission-critical priorities. Since our founding in 1979, we’ve grown to 21,000 associates globally who support ~14,000 client enterprises in ~90 countries and territories. We do important, interesting and substantive work that matters. That’s why we hire associates with the intellectual curiosity, energy and drive to want to make a difference. The bar is unapologetically high. So is the impact you can have here. What makes Gartner a great place to work? Our vast, virtually untapped market potential offers limitless opportunities – opportunities that may not even exist right now – for you to grow professionally and flourish personally. How far you go is driven by your passion and performance. We hire remarkable people who collaborate and win as a team. Together, our singular, unifying goal is to deliver results for our clients. Our teams are inclusive and composed of individuals from different geographies, cultures, religions, ethnicities, races, genders, sexual orientations, abilities and generations. We invest in great leaders who bring out the best in you and the company, enabling us to multiply our impact and results. This is why, year after year, we are recognized worldwide as a great place to work. What do we offer? Gartner offers world-class benefits, highly competitive compensation and disproportionate rewards for top performers. In our hybrid work environment, we provide the flexibility and support for you to thrive — working virtually when it's productive to do so and getting together with colleagues in a vibrant community that is purposeful, engaging and inspiring. Ready to grow your career with Gartner? Join us. Gartner believes in fair and equitable pay. A reasonable estimate of the base salary range for this role is 172,000 USD - 202,500 USD. Please note that actual salaries may vary within the range, or be above or below the range, based on factors including, but not limited to, education, training, experience, professional achievement, business need, and location. In addition to base salary, employees will participate in either an annual bonus plan based on company and individual performance, or a role-based, uncapped sales incentive plan. Our talent acquisition team will provide the specific opportunity on our bonus or incentive programs to eligible candidates. We also offer market leading benefit programs including generous PTO, a 401k match up to $7,200 per year, the opportunity to purchase company stock at a discount, and more. The policy of Gartner is to provide equal employment opportunities to all applicants and employees without regard to race, color, creed, religion, sex, sexual orientation, gender identity, marital status, citizenship status, age, national origin, ancestry, disability, veteran status, or any other legally protected status and to seek to advance the principles of equal employment opportunity. Gartner is committed to being an Equal Opportunity Employer and offers opportunities to all job seekers, including job seekers with disabilities. If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access the Company’s career webpage as a result of your disability. You may request reasonable accommodations by calling Human Resources at +1 (203) 964-0096 or by sending an email to ApplicantAccommodations@gartner.com. Job Requisition ID:108877 By submitting your information and application, you confirm that you have read and agree to the country or regional recruitment notice linked below applicable to your place of residence. Gartner Applicant Privacy Link: https://jobs.gartner.com/applicant-privacy-policy For efficient navigation through the application, please only use the back button within the application, not the back arrow within your browser.

Related Categories

Related Job Pages

More Security Operations Jobs

Full TimeRemoteTeam 11-50H1B No Sponsor

• Analysis of security-related incidents (Incident Response) • Develop concepts for prevention and defense against attacks • Coordinate the Incident Response team during a security incident • Optimize use cases and rules to identify potential threats • Onboard new colleagues and lead Incident Response teams

Germany
Apollo.io logo

Security Operations Manager

Apollo.io

Helping sales teams find their ideal buyers and convert them into customers.

Full TimeRemoteTeam 51-200Since 2015H1B No Sponsor

• Own and continuously improve end-to-end Security Operations processes • Act as senior incident leader for high-severity incidents • Lead and participate in complex security investigations • Ensure high-quality post-incident reviews

Canada
Apollo.io logo

Senior Security Operations Engineer

Apollo.io

Helping sales teams find their ideal buyers and convert them into customers.

Full TimeRemoteTeam 51-200Since 2015H1B No Sponsor

Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world's largest enterprises. Founded in 2015, the company is one of the fastest growing companies in SaaS, raising approximately $250 million to date and valued at $1.6 billion. Apollo.io provides sales and marketing teams with easy access to verified contact data for over 210 million B2B contacts and 35 million companies worldwide, along with tools to engage and convert these contacts in one unified platform. By helping revenue professionals find the most accurate contact information and automating the outreach process, Apollo.io turns prospects into customers. Apollo raised a series D in 2023 and is backed by top-tier investors, including Sequoia Capital, Bain Capital Ventures, and more, and counts the former President and COO of Hubspot, JD Sherman, among its board members. **This is a Permanent role ("Umowa o pracę") and not a B2B contract** Role OverviewThe Security Operations Engineer is a senior individual contributor responsible for detecting, investigating, and responding to security threats across Apollo’s cloud-native and SaaS environments. This role requires strong technical depth, independent judgment, and ownership of complex security investigations from intake through resolution. This role operates in a fully remote environment and emphasizes clear written communication, operational rigor, and effective collaboration. Key ResponsibilitiesIncident Detection, Investigation & Response - Monitor, triage, and investigate security alerts and events across cloud infrastructure, SaaS applications, and corporate systems. - Conduct end-to-end security investigations, including scoping, containment, eradication, recovery, and documentation. - Own investigations independently while collaborating effectively during high-severity incidents. SIEM, Detection & Workflow Engineering - Configure and maintain SIEM detections in Panther, including use cases, correlation rules, alert logic, and tuning. - Onboard, validate, and maintain log sources to ensure visibility, accuracy, and reliability. - Design and improve investigation and response workflows to streamline triage, escalation, and resolution. - Leverage AI-assisted tools to accelerate alert analysis, enrichment, and investigation efficiency. Threat Hunting & Proactive Security - Perform proactive threat-hunting activities to identify malicious or anomalous behavior not surfaced by existing detections. - Investigate abuse, fraud, account compromise, and automation misuse scenarios in close collaboration with Fraud teams. - Identify detection gaps and propose, implement, and validate improvements. Automation, Coding & Tooling - Build scripts, automations, and tools to reduce manual work and improve response speed and consistency. - Use Python extensively for analysis, automation, and internal tooling; Ruby experience is a plus. - Contribute to internal detection frameworks, tooling, and shared libraries. Documentation & Continuous Improvement - Produce clear, high-quality documentation for incidents, investigations, and post-incident reviews. - Contribute to runbooks, playbooks, and operational standards. - Share knowledge, review peer work, and mentor other engineers. Required Skills & Experience - 4+ years of experience in Security Operations or Incident Response. - Hands-on experience with SIEM platforms (experience with Panther is highly valued), log analysis, and detection engineering. - Experience investigating security incidents in cloud-native environments (GCP preferred; AWS and Azure also relevant) and SaaS applications. - Experience automating security workflows and investigations. - Proficiency in Python; familiarity with Ruby preferred. - Ability to operate independently, prioritize effectively, and make sound technical decisions under pressure. Preferred Qualifications - Experience using AI or ML-powered security tools for detection, investigation, or response. - Familiarity with vulnerability management concepts and remediation workflows. - Relevant certifications such as GCIA, GCIH, GCED, AWS / GCP Security certifications, or Security+. - Prior experience working in fully remote, distributed teams. We are AI NativeApollo.io is an AI-native company built on a culture of continuous improvement. We’re on the front lines of driving productivity for our customers—and we expect the same mindset from our team. If you're energized by finding smarter, faster ways to get things done using AI and automation, you'll thrive here. Why You’ll Love Working at ApolloAt Apollo, we’re driven by a shared mission: to help our customers unlock their full revenue potential. That’s why we take extreme ownership of our work, move with focus and urgency, and learn voraciously to stay ahead. We invest deeply in your growth, ensuring you have the resources, support, and autonomy to own your role and make a real impact. Collaboration is at our core—we’re all for one, meaning you’ll have a team across departments ready to help you succeed. We encourage bold ideas and courageous action, giving you the freedom to experiment, take smart risks, and drive big wins. If you’re looking for a place where your work matters, where you can push boundaries, and where your career can thrive—Apollo is the place for you. Learn more here!

Poland
Job Closed
Vouched logo

GTM Operations Manager (Agentic Security)

Vouched

Award-winning AI for identity verification and KYC

OtherRemoteTeam 11-50H1B Sponsor

At Vouched we are building a powerful identity verification platform to provide worldwide access to life’s most critical services, including healthcare, financial services, rentals, and more. Companies use Vouched to verify identity while onboarding and authenticating users. We make identity verification easy with a combination of machine learning and data checks. Our customers leverage our APIs, integrations, and no-code solution to onboard customers to their systems. What we do - Verify thousands of people every day across multiple countries and industries providing access to critical services - Serve fast-growing startups, unicorns, and large enterprises, with a focus on providing fast, easy integration for developers  - Run on a modern cloud infrastructure powered by automated integration and unit testing, provisioning, deployments, monitoring, and notifications  - Drive to own the market and deliver a world-changing client and end-user experience We are a small but mighty team looking for people who align with our values and have a strong sense of hustle, creative problem solving, grit and energy to help us scale! We celebrate diversity and are committed to creating an inclusive environment for all employees. As a  GTM Operations Manager you will operate in a  highly cross-functional role at the intersection of go-to-market execution, product readiness, partner development, and operational scale. You will help build the systems, workflows, and connective tissue required to successfully bring a new AI-native product to market. This role is ideal for someone who thrives in fast-paced environments, brings strong operational judgment, and enjoys translating strategy into execution. Responsibilities Support GTM Execution & Relationship Development - Partner closely with the appropriate stakeholders  to support lead generation, outbound outreach, and partner relationship development - Help manage follow-ups, meeting preparation, and relationship pipelines across strategic accounts and ecosystem partners - Build lightweight processes to ensure momentum across high-priority GTM efforts Build Launch and Funnel Infrastructure - Stand up the operational foundation required to launch and scale a new product line, including: - AI SDR workflows and tooling - Customer support motion and escalation paths - Funnel tracking, lifecycle stages, and conversion metrics - Own the day-to-day management of the GTM funnel: inbound, outbound, partner-sourced, and expansion Connect Product, Engineering, and Market Needs - Act as a bridge between engineering execution and market-facing priorities - Ensure roadmap work aligns with what’s required for successful launches, customer adoption, and partner enablement - Translate technical progress into clear GTM-ready deliverables and narratives - Establish a tight voice-of-customer loop by translating insights from prospects, partners, and customers into clear product requirements and GTM priorities Executive Communication & Enablement - Draft executive-level presentations, board-facing materials, and internal updates - Contribute to customer, partner, and industry presentations—both virtual and in-person - Help package product and market insights into clear, compelling messaging Drive Operating Cadence and Continuous Improvement (AI-native emphasis) - Establish repeatable rhythms across pipeline, launch readiness, and cross-functional execution - Own GTM analytics and funnel performance tracking, including instrumentation, conversion metrics, and rapid experimentation to improve pipeline efficiency and launch outcomes. - Identify friction points and proactively improve processes through automation and iteration - Bring an experimentation mindset to GTM: test, learn, refine, scale

United States
Job Closed