We make it easy to secure your cloud transformation. Get fast, secure, and direct access to apps without appliances.
Director, Technical Success – SecOps
Location
United States
Posted
4 days ago
Salary
$199.5K - $285K / year
Seniority
Lead
Job Description
Director, Technical Success – SecOps
Zscaler
• Develop the vision and operating structure for the SecOps Technical Success team in the Americas, India, and Israel • Collaborate with global Customer Success leadership to align SecOps goals with the corporate strategy • Build strong, lasting relationships with key stakeholders for our top customer accounts • Oversee the development of tailored customer success plans for our Strategic accounts • Use a strong technical background to address technical challenges and ensure customer value realization.
Job Requirements
- 8+ years of experience in customer success, account management, or related roles
- At least 5 years in a management role overseeing individual contributors or subordinate managers
- Bachelor's degree in a relevant field such as Computer Science, Information Technology, or Business Administration
- Experience managing customer relationships in a B2B SaaS environment
- Solid understanding of security operations, networking, security technologies, and cloud computing
- Proficiency in analyzing complex data to identify trends, forecast customer behavior, and make evidence-based decisions.
Benefits
- Various health plans
- Time off plans for vacation and sick time
- Parental leave options
- Retirement options
- Education reimbursement
- In-office perks, and more!
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
• Analyze security-related incidents (Incident Response) • Develop concepts for preventing and defending against attacks • Coordinate the Incident Response team during a security incident • Optimize use cases and detection rules to identify potential threats
Role Description As a Tier 2 Security Operations Analyst, you are the investigative backbone of Ostra's managed SOC. You take ownership of escalated alerts and incidents across our clients' environments, driving them from detection through root-cause analysis and containment. You go beyond triage: - Investigate and classify incidents. - Own escalated alerts and incidents across client environments; classify them, determine severity, and analyze data and systems to establish cause, scope, and impact. - Lead response and containment. - Act as an incident handler for sensitive and need-to-know incidents, applying CSIRT best practices and Ostra's incident response model; coordinate with clients and external parties to drive incidents to closure. - Threat hunt. - Proactively hunt for novel and evasive threats using sound hunt methodology. - Engineer and tune detections. - Understand, monitor, and optimize SIEM detection rules and SOAR playbooks; continuously improve detection accuracy, reduce false positives, and accelerate or automate response. - Author and maintain playbooks. - Develop, document, and maintain playbooks and standard operating procedures (SOPs) for recurring incidents and tasks so the SOC can respond consistently and quickly. - Produce and apply threat intelligence. - Ingest threat data from open and closed sources, correlate it against client context to produce actionable intelligence, and take appropriate action to mitigate risk. - Communicate with clients. - Clearly explain technical findings, risk, and recommended actions to client stakeholders; deliver timely, well-written incident updates and reports within SLA. - Mentor Tier 1 analysts. - Guide and upskill Tier 1 analysts, review their work, and help raise the overall quality and speed of the SOC. - Improve continuously. - Refine processes and procedures to improve speed and accuracy, and contribute to a culture of measurable improvement. - Provide on-call escalation. - Serve as an escalation point during a rotating on-call schedule, supporting a global SOC and off-hours coverage as required by the business. Qualifications - 3–5 years of hands-on experience as a SOC analyst, incident responder, or security-focused network analyst, ideally in a fast-paced or multi-client environment. - Demonstrated experience investigating and escalating security incidents beyond initial triage—establishing root cause, scope, and impact. - Working knowledge of TCP/IP and common network protocols, Windows event logs, *nix audit logs, and IDS/IPS alerting. - Hands-on experience with core security tooling categories: SIEM, SOAR, EDR/XDR, next-generation firewalls (NGFW), IDS/IPS, HIDS/HIPS, antivirus, and vulnerability scanners. - Proficiency with at least one SIEM query language and the ability to build, tune, and troubleshoot detections. - Proficiency in at least one common scripting language (PowerShell, Bash, Python, or similar) to automate analysis and response. - Solid understanding of the MITRE ATT&CK framework and experience building use cases and SOPs around relevant TTPs. - Familiarity with the NIST Cybersecurity Framework and the ability to apply its principles in practice. - Strong technical writing skills—able to document processes, procedures, and incident findings clearly for varied audiences. - Excellent problem-solving skills and comfort working through ambiguity and incomplete information. - Self-motivated, dependable, and able to deliver end-to-end results in a high-tempo environment. - Bachelor's degree in a related field, or equivalent practical experience. - Willingness to participate in a rotating on-call schedule and provide off-hours support as needed. Preferred Qualifications - Prior experience at a managed security service provider (MSSP) or in a multi-tenant SOC. - Relevant certifications (preferred, not required): CompTIA Security+, CompTIA CySA+, GIAC (GCIH, GCIA, GCFA), or CISSP. - Cloud security experience across AWS, Azure, Google Cloud, and/or Microsoft 365. - Experience developing new detection use cases and SOAR automations from scratch. - Experience working with a geographically distributed team across multiple time zones. - Expert-level understanding of common and emerging security threats, vulnerabilities, and attacker tradecraft. Benefits - A people-first culture built on trust and authenticity. - Competitive pay and comprehensive benefits. - Professional growth opportunities in a fast-evolving industry. - A mission-driven company protecting good businesses from cyber threats. Equal Opportunity Statement Ostra Security is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment decisions are made based on qualifications, merit, and business needs—without regard to race, color, religion, gender, gender identity, sexual orientation, national origin, age, disability, veteran status, or any other protected characteristic. FLSA Status Exempt Salary Grade $95,000 – $120,000 base, commensurate with experience (plus benefits) Position Type Full-time Remote Location Candidates residing in Minnesota will be given preference based on business needs and team alignment.
• Lead the Supplier Security Due Diligence & Monitoring Service and oversee day-to-day service delivery. • Manage and develop a team responsible for supplier security contracting support and risk-based decision making. • Review and interpret supplier security assessment outcomes and monitoring results to guide contractual negotiations. • Provide guidance on acceptable contractual security positions, fallback language, compensating controls, and alternative risk mitigation approaches. • Ensure consistent application of enterprise security requirements across supplier agreements. • Oversee documentation and tracking of contractual exceptions, deviations, and risk accommodations. • Escalate contractual positions that exceed established risk tolerances through appropriate governance and risk acceptance processes. • Partner closely with Legal, Procurement, Cybersecurity, Enterprise Risk Management, and business stakeholders to resolve complex supplier issues. • Establish and maintain operational metrics, service-level objectives, reporting, and quality management practices. • Lead continuous improvement efforts designed to improve scalability, consistency, and stakeholder experience.
• Serve as a primary responder for Cyber Operations client systems, taking ownership of client configuration issues and tracking through resolution • Act as a point of escalation for other Engineers (Associate Engineer) and provide guidance and mentoring. • Advise best practice on SIEM and Enterprise Security products to both technical and relatively non-technical personnel • Provide remote consulting services via interactive client sessions to assist with implementation of multiple product vendors and technologies • Implement and configure discipline software and appliance-based products in large enterprise environments • Develop and maintain content and reporting • Provide escalation support to Tier 1 and 2 for Authorized Support Customers, following processes and interacting appropriately with both customers and partners when required • Perform knowledge transfers to clients regarding security and system configuration awareness • Performs other duties as assigned • Complies with all policies and standards



