Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
BWE

Director of Security Operations

BWE

. Lead a three-person security team as a player-coach and remain a hands-on technical contributor .

Posted 9/17/2026full-timeColumbus • Ohio • United StatesLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in cybersecurity leadership, incident response, and security engineering, with a strong focus on regulatory compliance and automation. Proficient in managing security tool stacks and implementing data protection controls across various platforms.

Highest-signal resume keywords
Cybersecurity LeadershipIncident Response ManagementSecurity Tool ConfigurationVulnerability ManagementRegulatory Compliance

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Cybersecurity EngineeringIncident ResponseVulnerability ManagementSecurity ArchitectureData Protection ControlsEDRCloud SecuritySIEMDetection EngineeringSecure SDLC
Soft Skills
Team LeadershipCollaborationCommunicationProblem-SolvingMentoring
Tools & Technologies
PowerShellPythonAPIsMDRMSSPExpelCrowdStrikeWizCyberArkMicrosoft Purview
Certifications & Qualifications
CISSPGCIHGCFAOSCP
Industry Keywords
Financial ServicesGSECommercial Real Estate FinanceMortgage BankingData Loss MonitoringNIST CSFCIS Controls

Tech Stack

Tools & technologies
CloudCyber SecurityPythonSDLC

About the role

Key responsibilities & impact
  • Lead a three-person security team as a player-coach and remain a hands-on technical contributor
  • Own, configure, tune, troubleshoot, and rationalize BWE’s security tool stack
  • Own detection and response outcomes, including alert quality, escalation, and MDR/vendor accountability
  • Set detection, logging, telemetry, and security architecture standards across cloud, SaaS, endpoint, identity, application, infrastructure, and data platforms
  • Lead incident response from triage through recovery and post-incident review, including playbooks and on-call participation
  • Drive vulnerability management from discovery and prioritization through remediation and verification
  • Implement data protection controls for confidential financial information, including classification, encryption, retention, and data loss monitoring
  • Maintain secure SDLC practices, code scanning standards, software supply chain security, and application security assessments
  • Assess and monitor third-party/vendor security and contractual requirements
  • Lead cyber risk assessments, penetration tests, tabletop exercises, control reviews, identity reviews, and social engineering exercises
  • Partner with the Chief Digital Officer and Compliance on information security policies, standards, and procedures
  • Maintain alignment to NIST CSF and CIS Controls and track control gaps to closure
  • Implement, operate, and evidence technical controls for Fannie Mae, Freddie Mac, HUD, FHA, rating agencies, and clients
  • Automate detection, response, investigation, and reporting using scripting, APIs, playbooks, and AI
  • Partner with Technology Operations to test and improve cyber resilience and recovery
  • Own the security awareness program and operational security metrics
  • Serve as a security partner to Legal, Compliance, HR, and business teams and support client, rating agency, and GSE security representation
  • Set patching standards and govern exceptions with Technology Operations
  • Lead security triage, investigation, forensics, and corrective actions while Technology Operations handles service restoration
  • Own vulnerability discovery, prioritization, and validated closure while Technology Operations performs remediation

Requirements

What you’ll need
  • 10+ years of cybersecurity experience with significant recent hands-on security engineering and operations responsibilities
  • 3+ years leading technical security professionals while continuing to contribute technically
  • Hands-on depth across most of: EDR, cloud security, email security, data security, privileged access, SIEM and detection engineering, and vulnerability management
  • Direct experience managing an MDR or MSSP and holding the provider accountable for measurable detection and response outcomes
  • Experience serving as technical lead for security incidents from triage through remediation and post-incident review
  • Experience implementing, operating, and evidencing technical security controls against financial services regulatory and contractual requirements
  • Ability to automate security work using PowerShell, Python, APIs, or equivalent technologies
  • Bachelor’s degree in a related field or equivalent practical experience
  • Applicants must be currently authorized to work in the United States on a full-time basis
  • No immigration sponsorship available
  • Preferred: Experience working with Fannie Mae, Freddie Mac, or another GSE
  • Preferred: Experience in commercial real estate finance, multifamily or mortgage banking, or another lending environment
  • Preferred: Secure SDLC and application security experience in custom-development environments, including securing enterprise AI platforms
  • Preferred: Demonstrated use of AI and automation to improve security operations, and hands-on certifications such as CISSP, GCIH, GCFA, or OSCP
  • Preferred: Familiarity with platforms such as Expel, CrowdStrike, Wiz, Abnormal AI, Varonis, CyberArk, BeyondTrust, Recorded Future, Veeam, and Microsoft Purview

Benefits

Comp & perks
  • Hybrid work arrangement
  • Full-time employment