Talent.com
Ecolab
Senior Director, Security ThreatEcolab • Saint Paul, MN, United States
Senior Director, Security Threat

Senior Director, Security Threat

Ecolab • Saint Paul, MN, United States
5 days ago
Job type
  • Full-time
Job description

Director Of Threat Management

The Director of Threat Management is responsible for leading the enterprise detection and response function, owning the reactive side of security: identifying, investigating, and containing threats across a global Fortune 500 environment. This role provides leadership for the Security Operations Center (SOC), Cyber Threat Intelligence (CTI), Detection Engineering, and Incident Response (IR), and is accountable for the speed and quality of threat detection, triage, investigation, and response across the enterprise.

The Director of Threat Management leads a 24x7 monitoring and response organization while advancing the detection engineering pipeline, maturing threat intelligence integration, and driving measurable improvement in mean time to detect and mean time to respond. The role combines strategic direction, operational accountability, and organizational leadership to reduce enterprise risk from active and emerging threats, partnering closely with the platform engineering team that owns the underlying security tooling.

What You Will Do:

Strategy, Governance, and Leadership

  • Define and own the enterprise threat detection and response strategy, roadmap, and operating model aligned to cybersecurity, risk, and business objectives.
  • Mature the threat management program through formal governance, playbooks, standards, metrics, and leadership reporting.
  • Present detection and response posture, incident trends, risks, and investment needs to security leadership and executive stakeholders.
  • Establish and monitor KPIs such as mean time to detect (MTTD), mean time to respond (MTTR), detection coverage, and alert quality.
  • Lead prioritization decisions across the SOC, threat intelligence, detection engineering, and incident response functions.

Security Operations and Monitoring

  • Lead a 24x7 Security Operations Center responsible for monitoring, alert triage, escalation, and initial investigation across the enterprise.
  • Own the detection content lifecycle within the SIEM, and define data source onboarding, log storage, and retention requirements for the platform-owning team.
  • Drive continuous improvement in alert quality, triage efficiency, and analyst workflow to reduce noise and analyst fatigue.
  • Establish tiered operating models, shift coverage, and escalation paths that ensure consistent 24x7 response readiness.
  • Oversee SOC performance metrics, service levels, and quality assurance across monitoring and triage activities.

Detection Engineering

  • Lead the detection engineering function responsible for building, tuning, and maintaining detection content across SIEM and security telemetry sources.
  • Drive a detection-as-code approach with version control, testing, peer review, and measurable detection coverage mapped to MITRE ATT&CK.
  • Prioritize detection development against threat intelligence, red team findings, incident learnings, and emerging adversary techniques.
  • Establish metrics for detection coverage, efficacy, and false-positive rates, and drive continuous tuning based on outcomes.
  • Partner with engineering and platform teams to ensure high-quality, well-structured log and telemetry sources feed detection pipelines.

Cyber Threat Intelligence

  • Lead the Cyber Threat Intelligence function responsible for strategic, operational, and tactical intelligence supporting detection and response.
  • Operationalize threat intelligence by driving indicator enrichment, threat actor tracking, and intelligence-led detection and hunting priorities.
  • Deliver executive and stakeholder threat briefings that translate the threat landscape into business-relevant risk and action.
  • Establish threat hunting programs that proactively search for adversary activity across the environment ahead of alerting.
  • Manage intelligence sources, sharing partnerships, and integration of intelligence into SIEM, SOAR, and detection workflows.

Incident Response

  • Own the enterprise incident response process across detection, triage, containment, eradication, recovery, and post-incident review.
  • Lead major incident coordination, serving as an escalation point and driving cross-functional response during significant events.
  • Establish and maintain incident response playbooks, runbooks, and tabletop exercises to ensure organizational readiness.
  • Drive post-incident reviews and lessons-learned processes that feed detection improvements and control gaps back into the program.
  • Partner with legal, communications, IT, and business stakeholders to ensure coordinated response and regulatory notification where required.

Tooling and Automation Requirements

  • Define detection and response requirements, use cases, and priorities for the SIEM, SOAR, and log storage platforms owned and operated by the platform engineering team.
  • Partner with the platform-owning team to shape roadmap, data onboarding, retention, and automation priorities that serve detection and response needs.
  • Specify SOAR automation use cases for triage, enrichment, and response, and validate that delivered automations meet analyst workflow requirements.
  • Provide feedback on tooling performance, gaps, and integration needs to drive a unified, efficient analyst workflow across detection, intelligence, and response.
  • Use modern tools including AI-assisted workflows to accelerate investigation, analysis, documentation, and decision-making across the team.

Organizational and People Leadership

  • Lead and develop a distributed threat management organization consisting of managers, analysts, detection engineers, threat intelligence analysts, and incident responders.
  • Build organizational clarity across the SOC, threat intelligence, detection engineering, and incident response functions.
  • Provide leadership in talent development, succession planning, coaching, performance management, and team engagement.
  • Manage staffing strategy across full-time employees, partners, and contingent resources, including managed detection and response providers where applicable.
  • Oversee third-party vendors and consulting partners supporting threat management programs and services.

Minimum Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline; equivalent experience may be considered.
  • 12+ years of progressive experience in cybersecurity, security operations, threat detection, incident response, or threat intelligence.
  • 5+ years of leadership experience managing multi-team security operations or threat functions at the Senior Manager or Director level.
  • Demonstrated success leading detection and response programs across SOC operations, detection engineering, threat intelligence, and incident response.
  • Experience managing 15+ person organizations including managers, analysts, and engineers with varied technical specializations.
  • Experience leading major incident response and driving measurable improvement in detection coverage and response times.
  • Experience building or standing up new detection, intelligence, or response capabilities, teams, or services.

Technical and Functional Qualifications

  • Strong knowledge of SIEM and log management platforms and log storage technologies such as Elasticsearch or Splunk, including data onboarding, retention, and detection content management.
  • Strong knowledge of security orchestration, automation, and response (SOAR) platforms such as Swimlane or Cortex XSOAR.
  • Strong knowledge of detection engineering practices, detection-as-code, and detection coverage mapped to MITRE ATT&CK.
  • Experience with the cyber threat intelligence lifecycle, threat actor tracking, and intelligence-led detection and hunting.
  • Experience with incident response frameworks, forensic investigation concepts, and major incident coordination.
  • Understanding of threat detection across cloud (Azure, AWS, GCP), endpoint, network, and identity telemetry sources.
  • Familiarity with security frameworks and models such as MITRE ATT&CK, NIST CSF 2.0, and the cyber kill chain.

Preferred Qualifications

  • Experience in a Fortune 500, global, manufacturing, or industrial environment with complex, heterogeneous technology estates.
  • Prior experience standing up or transforming a SOC, threat intelligence, detection engineering, or incident response function.
  • Experience with threat detection and response in operational technology (OT) or industrial control system (ICS) environments.
  • Familiarity with platforms such as Elastic, Splunk, Swimlane, Cortex XSOAR, CrowdStrike, or Microsoft Sentinel.
  • Relevant certifications such as CISSP, CISM, GCIH, GCIA, GCTI, or GCFA.

Leadership Competencies

  • Strategic thinker with the ability to set direction and translate strategy into operational execution.
  • Decisive leader who operates effectively under pressure and makes sound calls during active incidents and competing priorities.
  • Delivery-oriented leader with a strong focus on accountability, measurable outcomes, and service quality.
  • Effective communicator able to translate complex threat and incident topics for executives, stakeholders, and technical teams.
  • Strong collaborator with the ability to influence across infrastructure, cloud, application, legal, and business teams.
  • Proven people leader with the ability to coach talent,
Create a job alert for this search

Senior Director, Security Threat • Saint Paul, MN, United States

Similar jobs

ERP Program Director

ExperisSaint Paul, MN, United States
Full-time

PAUL, MN (no remote candidates).We are seeking an experienced and visionary Program Director to lead the end-to-end implementation of Microsoft Dynamics 365 ERP across our distribution business.Thi... Show more

 • Promoted

Medical Director

MedeliteFarmington, MN, United States
Full-time

Location: Farmington, MN Schedule: Contract Salary per annum: $100,000 - $120,000.Our partnership with MedElite Healthcare Management Group empowers us to focus on what matters most: providing comp... Show more

 • Promoted

Senior Director, Security Threat

EcolabSaint Paul, MN, United States
Full-time

The Director of Threat Management is responsible for leading the enterprise detection and response function, owning the reactive side of security: identifying, investigating, and containing threats... Show more

 • Promoted

Development Director

Minnesota Environmental PartnershipSaint Paul, MN, United States
Full-time

Organization: Minnesota Center for Environmental Advocacy.Position Summary: The Development Director plays a critical leadership role on the fundraising team at MCEA.In addition to managing a perso... Show more

 • Promoted

Manager

SubwayRosemount, MN, United States
Full-time +1

As part of the Subway team, you will focus on eight main things:.Providing an excellent guest experience.Ensuring that great food is prepared and served.Keeping our restaurants functional, clean, a... Show more

 • Promoted

Security Lead

Children's Hospitals and Clinics of MinnesotaSaint Paul, MN, United States
Full-time

About Children's MinnesotaChildren's Minnesota is one of the largest pediatric health systems in the United States and the only health system in Minnesota to provide care exclusively to children, f... Show more

 • Promoted

Third Party Risk Management Director (Hybrid)

Securian FinancialSaint Paul, MN, United States
Full-time

Risk Management Consulting Director.The Third Party Risk Management (TPRM) Director is accountable for leading and transforming the enterprise TPRM program to effectively manage risk across the ful... Show more

 • Promoted

Security Lead

Children's Hospital AssociationSaint Paul, MN, United States
Full-time +1

Description:About Children's MinnesotaChildren's Minnesota is one of the largest pediatric health systems in the United States and the only health system in Minnesota to provide care exclusively to... Show more

 • Promoted

Remote Product Tester - Flexible Studies

BuzzTestersChisago City, MN
Remote
Full-time

Earn up to $400/week, depending on the number and type of studies you complete.Share honest feedback on products and services from independent brands.Assignments include short online surveys (10–20... Show more

 • Promoted

Corporate Safety Director

The Contingent PlanSaint Paul, MN, United States
Full-time

The Contingent Plan is actively recruiting a corporate EHS director for its client headquartered in the Twin Cities.This is a hybrid role with the expectation that the person will be onsite at the ... Show more

 • Promoted

PREVENTION SPECIALIST

Department of the Air ForceSaint Paul, MN, United States
Full-time

Duties and responsibilities vary and may increase according to grade level.Plans, develops, organizes, implements, and directs the military and civilian human resources and fiscal programmatic acti... Show more

 • Promoted

America Votes: Minnesota Senior Strategy & Program Director

ArenaSaint Paul, MN, United States
Full-time +2

America Votes: Minnesota Senior Strategy & Program Director.America Votes is seeking a dynamic, collaborative leader with a history of successfully executing issue and electoral campaign programs a... Show more

 • Promoted

Manager in Training

Holiday Stationstores by CircleKFarmington, MN, United States
Full-time

Career Opportunity with our Holiday Franchise Group.Want to have FUN and get PAID? If so, come join our enthusiastic, results oriented team.We truly believe that by providing fast and friendly cust... Show more

 • Promoted

Assoc MDR/Vigilance Spec - Exempt

HireTalentSaint Paul, MN, United States
Full-time

Responsibilities for this role include reviewing product events from a variety of sources to determine the complaint status and create a thorough complaint record in the complaint handling system.T... Show more

 • Promoted

Manager Technical Operations and Resolution

AndersenCottage Grove, MN, United States
Full-time

Manager Technical Operations & Service Resolutions.At Andersen, we see possibility everywhere, every day and in everything we do.The possibility for our employees to achieve their full potential, f... Show more

 • Promoted

Consumer Insights Analyst

Earn HausCedar, Minnesota, United States
Part-time

We're currently seeking motivated individuals to participate in online surveys and paid gaming opportunities for well-known national brands.If you're looking for a flexible way to earn extra cash f... Show more

 • Promoted

Global Regulatory Compliance Director

Intracept by Boston ScientificSaint Paul, MN, United States
Full-time

Global Regulatory Compliance Director, Internal Audit.At Boston Scientific, we'll give you the opportunity to harness all that's within you by working in teams of diverse and high-performing employ... Show more

 • Promoted

Educational Center Director of Operations and Growth

MathnasiumSaint Paul, MN, United States
Full-time

Benefits: Competitive salary, free uniforms, opportunity for advancement, training & development.Why Work with Us: At Mathnasium of St.Paul, we're passionate about both our students and our employe... Show more

 • Promoted

Financial Advisor - Minneapolis/St Paul - North Metro

Thrivent Financial for LutheransForest Lake, MN, United States
Full-time

Make an impact providing expert financial advice with heart.Thrivent is a different kind of financial services firm, one that puts generosity at the center of saving and investing.Here, you'll make... Show more

 • Promoted

Engineering Process Director

PolarisWyoming, MN, United States
Full-time

Enterprise Business Process Owner (BPO) For Product Development And Engineering.We empower employees to take on challenging assignments and roles with an elevated level of responsibility in our agi... Show more