Senior Director, Security Threat
$168.4k - $252.6kEcolab
Job Summary: The Director of Threat Management is responsible for leading the enterprise detection and response function, owning the reactive side of security: identifying, investigating, and containing threats across a global Fortune 500 environment. This role provides leadership for the Security Operations Center (SOC), Cyber Threat Intelligence (CTI), Detection Engineering, and Incident Response (IR), and is accountable for the speed and quality of threat detection, triage, investigation, and response across the enterprise.The Director of Threat Management leads a 24x7 monitoring and response organization while advancing the detection engineering pipeline, maturing threat intelligence integration, and driving measurable improvement in mean time to detect and mean time to respond. The role combines strategic direction, operational accountability, and organizational leadership to reduce enterprise risk from active and emerging threats, partnering closely with the platform engineering team that owns the underlying security tooling.What You Will Do:Strategy, Governance, and LeadershipDefine and own the enterprise threat detection and response strategy, roadmap, and operating model aligned to cybersecurity, risk, and business objectives.Mature the threat management program through formal governance, playbooks, standards, metrics, and leadership reporting.Present detection and response posture, incident trends, risks, and investment needs to security leadership and executive stakeholders.Establish and monitor KPIs such as mean time to detect (MTTD), mean time to respond (MTTR), detection coverage, and alert quality.Lead prioritization decisions across the SOC, threat intelligence, detection engineering, and incident response functions.Security Operations and MonitoringLead a 24x7 Security Operations Center responsible for monitoring, alert triage, escalation, and initial investigation across the enterprise.Own the detection content lifecycle within the SIEM, and define data source onboarding, log storage, and retention requirements for the platform-owning team.Drive continuous improvement in alert quality, triage efficiency, and analyst workflow to reduce noise and analyst fatigue.Establish tiered operating models, shift coverage, and escalation paths that ensure consistent 24x7 response readiness.Oversee SOC performance metrics, service levels, and quality assurance across monitoring and triage activities.Detection EngineeringLead the detection engineering function responsible for building, tuning, and maintaining detection content across SIEM and security telemetry sources.Drive a detection-as-code approach with version control, testing, peer review, and measurable detection coverage mapped to MITRE ATT&CK.Prioritize detection development against threat intelligence, red team findings, incident learnings, and emerging adversary techniques.Establish metrics for detection coverage, efficacy, and false-positive rates, and drive continuous tuning based on outcomes.Partner with engineering and platform teams to ensure high-quality, well-structured log and telemetry sources feed detection pipelines.Cyber Threat IntelligenceLead the Cyber Threat Intelligence function responsible for strategic, operational, and tactical intelligence supporting detection and response.Operationalize threat intelligence by driving indicator enrichment, threat actor tracking, and intelligence-led detection and hunting priorities.Deliver executive and stakeholder threat briefings that translate the threat landscape into business-relevant risk and action.Establish threat hunting programs that proactively search for adversary activity across the environment ahead of alerting.Manage intelligence sources, sharing partnerships, and integration of intelligence into SIEM, SOAR, and detection workflows.Incident ResponseOwn the enterprise incident response process across detection, triage, containment, eradication, recovery, and post-incident review.Lead major incident coordination, serving as an escalation point and driving cross-functional response during significant events.Establish and maintain incident response playbooks, runbooks, and tabletop exercises to ensure organizational readiness.Drive post-incident reviews and lessons-learned processes that feed detection improvements and control gaps back into the program.Partner with legal, communications, IT, and business stakeholders to ensure coordinated response and regulatory notification where required.Tooling and Automation RequirementsDefine detection and response requirements, use cases, and priorities for the SIEM, SOAR, and log storage platforms owned and operated by the platform engineering team.Partner with the platform-owning team to shape roadmap, data onboarding, retention, and automation priorities that serve detection and response needs.Specify SOAR automation use cases for triage, enrichment, and response, and validate that delivered automations meet analyst workflow requirements.Provide feedback on tooling performance, gaps, and integration needs to drive a unified, efficient analyst workflow across detection, intelligence, and response.Use modern tools including AI-assisted workflows to accelerate investigation, analysis, documentation, and decision-making across the team.Organizational and People LeadershipLead and develop a distributed threat management organization consisting of managers, analysts, detection engineers, threat intelligence analysts, and incident responders.Build organizational clarity across the SOC, threat intelligence, detection engineering, and incident response functions.Provide leadership in talent development, succession planning, coaching, performance management, and team engagement.Manage staffing strategy across full-time employees, partners, and contingent resources, including managed detection and response providers where applicable.Oversee third-party vendors and consulting partners supporting threat management programs and services.Minimum QualificationsBachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline; equivalent experience may be considered.12+ years of progressive experience in cybersecurity, security operations, threat detection, incident response, or threat intelligence.5+ years of leadership experience managing multi-team security operations or threat functions at the Senior Manager or Director level.Demonstrated success leading detection and response programs across SOC operations, detection engineering, threat intelligence, and incident response.Experience managing 15+ person organizations including managers, analysts, and engineers with varied technical specializations.Experience leading major incident response and driving measurable improvement in detection coverage and response times.Experience building or standing up new detection, intelligence, or response capabilities, teams, or services.Technical and Functional QualificationsStrong knowledge of SIEM and log management platforms and log storage technologies such as Elasticsearch or Splunk, including data onboarding, retention, and detection content management.Strong knowledge of security orchestration, automation, and response (SOAR) platforms such as Swimlane or Cortex XSOAR.Strong knowledge of detection engineering practices, detection-as-code, and detection coverage mapped to MITRE ATT&CK.Experience with the cyber threat intelligence lifecycle, threat actor tracking, and intelligence-led detection and hunting.Experience with incident response frameworks, forensic investigation concepts, and major incident coordination.Understanding of threat detection across cloud (Azure, AWS, GCP), endpoint, network, and identity telemetry sources.Familiarity with security frameworks and models such as MITRE ATT&CK, NIST CSF 2.0, and the cyber kill chain.Preferred QualificationsExperience in a Fortune 500, global, manufacturing, or industrial environment with complex, heterogeneous technology estates.Prior experience standing up or transforming a SOC, threat intelligence, detection engineering, or incident response function.Experience with threat detection and response in operational technology (OT) or industrial control system (ICS) environments.Familiarity with platforms such as Elastic, Splunk, Swimlane, Cortex XSOAR, CrowdStrike, or Microsoft Sentinel.Relevant certifications such as CISSP, CISM, GCIH, GCIA, GCTI, or GCFA.Leadership CompetenciesStrategic thinker with the ability to set direction and translate strategy into operational execution.Decisive leader who operates effectively under pressure and makes sound calls during active incidents and competing priorities.Delivery-oriented leader with a strong focus on accountability, measurable outcomes, and service quality.Effective communicator able to translate complex threat and incident topics for executives, stakeholders, and technical teams.Strong collaborator with the ability to influence across infrastructure, cloud, application, legal, and business teams.Proven people leader with the ability to coach talent, build teams, and develop future leaders.Additional InformationThe role leads a 24x7 operation and may require off-hours availability for major incidents, escalations, and key initiatives.Travel up to 10% may be required for site assessments, team collaboration, and vendor engagements.The role may require coordination across global teams, including off-hours support for key initiatives, escalations, or major incidents.Annual or Hourly Compensation RangeThe base salary range for this position is $168,400.00 - $252,600.00. This position is eligible for annual bonus and long-term incentives based on performance, per plan terms. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.BenefitsEcolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families. Click here to see our benefits. If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working-here.Potential Customer Requirements NoticeTo meet customer requirements and comply with local or state regulations, applicants for certain customer-facing roles may need to:- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.Americans with Disabilities Act (ADA)Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process, please visit the Recruiting Support link in the footer of each page of our career website. SummaryLocation: USA - Minnesota - Saint Paul; USA - Illinois - NapervilleType: Full time
$105.4k - $207.8k
...Deloitte’s Cyber Services help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilities. Our Cyber Risk... ...development From entry-level employees to senior leaders, we believe there’s always room to...SeniorLocal areaVisa sponsorship$163.4k - $322.1k
...help our clients navigate the ever-changing threat landscape. Through powerful solutions and... ...confidence, and proactively manage to secure success. Recruiting for this role ends on... ...2026. Work you'll do As a Cloud Security Senior Manager, Azure Infrastructure & AI on the...SeniorWork at officeLocal areaVisa sponsorship$201.37k - $236.9k
...expected and fully supported. Coinbase’s Physical Security (PhySec) team protects Coinbase’s people and places through proactive threat detection and mitigation, employee training... ...teams across S&P and the company The *Senior Strategic Operations Manager, Physical Security...SeniorLocal area- ...Trinnex is seeking a Senior Cyber Security Analyst in Saint Paul, Minnesota to safeguard critical software systems for water utilities. In this... ...the organization's security posture through advanced threat detection and secure development practices. You will collaborate...Senior
$137.4k - $206.2k
Job Summary: The Director of Identity is responsible for maturing the enterprise Identity... ...operations, architecture, and emerging identity security capabilities. This role provides... ...managing multi-team IAM functions at the Senior Manager or Director level.Demonstrated...SuggestedHourly payMinimum wageFull timeLocal area- ...a Warehouse Operations Manager to oversee 80% management duties across logistics, warehousing, and inventory, ensuring safety and security. Reports to Regional Operations Manager and leads Supervisors, drivers, and office staff. You will optimize warehouse processes, develop...SeniorWork at office
- ...efficient processes across facilities. The role emphasizes leadership, budget management, vendor relations and continuous improvement, with a strong focus on security and regulatory compliance. Applicants should be prepared for national travel as needed. #J-18808-Ljbffr...Senior
- ...Division of a larger group supporting the Food, Beverage and health/nutrition sector. Reporting to the CEO, this role forms part of the senior leadership team responsible for driving best in class operational performance across the business unit. Responsibilities Provide...SeniorFull time
$140.97k - $188.72k
...Senior Director of Operations Location: St. Paul, MN, US, 55128. Murata Viosis is a global medical device company dedicated to creating a paradigm shift in the way healthcare is delivered. Through the utilization of our internet‑of‑things medical‑grade sensors and virtual...SeniorLocal areaRemote workShift work$137.4k - $206.2k
Job Summary: The Director of Security Engineering is responsible for leading enterprise security architecture... ...that harden the environment before threats land.The Director of Security... ...managing multi-team security functions at the Senior Manager or Director level.Demonstrated...Hourly payMinimum wageFull timeLocal area$44.8 - $64.46 per hour
...Operations Manager Job Class: State Program Administrator, Manager Senior Agency: MN Department of Natural Resources Job ID: 95655... ..., leasing, site and custodial maintenance, and site safety and security so that business units and divisions can operate in facilities...SeniorHourly payFull timeTemporary workPart timeH1bWork at officeLocal areaRemote workRelocationWork visaMonday to FridayFlexible hoursShift workDay shift$170k
Please see the below requirements for a Senior or Principal Electrical Engineer to join a growing class III medical device organization in the Northeast Twin Cities Metro. This role will play a critical part in supporting an implantable electromechanical system in a late...Senior$80.2k - $111.3k
...Cybersecurity Incident Response Engineer, Senior leads complex incident response efforts... ...while maintaining deep technical focus on threat containment and eradication. It also drives... ...governance, and influences broader security architecture and operations based on emerging...SeniorContract workWork experience placementWork at office$102.17k
...clients across the country. Job Description Join the Trinnex Security Team as a Senior Cyber Security Analyst, where you will operate at the... ...deployed in water environments are resilient against evolving threats. You will work closely with engineering and development teams...SeniorH1b$142.5k - $237.5k
...ABB Inc. is seeking a Senior IP Attorney to join their US IP Legal team. This role involves managing complex intellectual property matters across technology and business sectors while collaborating with global teams for effective IP strategies. The successful candidate...SeniorRemote work$164.8k - $247.2k
...extraordinary. This position will be based in Mounds View, MN. The Senior Principal Electrical Engineer leads the electrical engineering... ...sensitive personal information (such as bank account or Social Security details) during early stages of the hiring process. Any such...SeniorTemporary workH1bWork at officeLocal areaImmediate startFlexible hours$139.3k - $250.7k
...our core capabilities, the team enables secure, highly performant, and cost-effective infrastructure... ...cloud growth. Partner with the best As a Senior Product Manager for Core Compute, define... ...performance. Security : Neutralizing threats before they ever reach your data. Content...SeniorWork experience placementWork at office- ...Bon Appetit Management Company in Saint Paul, MN seeks a Senior Sous Chef for education account operations. You will supervise and assist in preparation, cooking, menu development, and garnishment under the guidance of the Executive Chef. The role includes cost control...Senior
- ...A leading healthcare organization is seeking a Senior Counsel to advise on complex legal matters in support of senior-focused primary care. Responsibilities include drafting and negotiating arrangements, collaborating on agreements, and ensuring compliance across operations...SeniorRemote work
$120k - $140k
...Director Information Security, Risk & Compliance We are seeking a focused and diligent Director Information Security, Risk & Compliance to own... ...monitoring, vulnerability management, and reporting. Lead threat intelligence, including recurring review of internal/...Temporary workLocal area- ...litigation, monitor declaratory actions, and contribute to department-wide best practices while upholding ethical conduct and compliance. The role requires prior coverage experience, ideally in WI, MN, IA, IL, MI, and reports to the Senior Manager, Legal. #J-18808-Ljbffr...Senior
$111.3k - $207.8k
...the Individual Life market. The Life Competitive Intelligence Senior Consultant serves as the strategic owner of life insurance... ...position will identify market opportunities, evaluate competitive threats, influence product and business decisions, and ensure Securian...SeniorFull timeWork at officeFlexible hoursShift work3 days per week$116.9k - $175.4k
Mortenson Construction is looking for a Planning and Scheduling Manager to join their team in Minnesota. This role involves leading project scheduling efforts for large, complex projects and requires a minimum of eight years of construction experience. The ideal candidate...Senior$62.78k - $83.03k
...Clayton Homes (New) is seeking a Senior HR Generalist in Redwood Falls, MN, to lead core HR functions, including employee relations, recruitment, and compliance. The role requires strong HR experience along with the ability to influence and coach leaders. This full-time...SeniorFull time$147.4k - $336.8k
...Ernst & Young Oman is seeking a Real Estate Tax Senior Manager to lead tax planning projects and provide advisory services across real estate, hospitality, and construction sectors. This role requires strong experience in tax, management and teamwork. With a competitive...Senior$80k - $115k
...Mitchell Hamline School of Law in Saint Paul, Minnesota, is hiring a full-time Staff Attorney or Senior Staff Attorney. The role focuses on public health and involves providing legal assistance and training in commercial tobacco control. Candidates need a Juris Doctor...SeniorFull time- A leading travel management company is seeking a Travel Consultant to provide exceptional service to defense and government travelers in Saint Paul, Minnesota. The ideal candidate will have over five years of experience and expertise in native GDS (Sabre). Responsibilities...SeniorFlexible hours
- The Good Samaritan Society in Minnesota is seeking a dedicated Social Worker to provide supportive services and counseling for patients in a healthcare setting. The role involves working closely with interdisciplinary teams while addressing social, emotional, and economic...SeniorFull time
- ...Arctic Wolf Networks, Inc. in Minnesota is seeking a Business Value Senior Manager to scale our value program and clearly demonstrate how our cybersecurity solutions reduce risk and drive business outcomes. In this role you’ll own customer and prospect presentations,...Senior
- A health-focused tech company in Minnesota is looking for a passionate UX/UI Designer to create intuitive, user-centered designs that enhance mental health and wellness. The ideal candidate will have over 5 years of experience in a fast-paced environment and a strong grasp...SeniorRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Director, Security Threat. Be the first to apply!
- senior business analyst Saint Paul, MN
- senior manager tax Saint Paul, MN
- senior devops Saint Paul, MN
- senior associate vice president Saint Paul, MN
- senior director digital marketing Saint Paul, MN
- senior international accountant Saint Paul, MN
- senior vmware engineer Saint Paul, MN
- sr technical product manager Saint Paul, MN
- senior specialist Saint Paul, MN
- senior resident engineer Saint Paul, MN

