Senior Director, Security Threat
$168.4k - $252.6kEcolab
Job Summary: The Director of Threat Management is responsible for leading the enterprise detection and response function, owning the reactive side of security: identifying, investigating, and containing threats across a global Fortune 500 environment. This role provides leadership for the Security Operations Center (SOC), Cyber Threat Intelligence (CTI), Detection Engineering, and Incident Response (IR), and is accountable for the speed and quality of threat detection, triage, investigation, and response across the enterprise.The Director of Threat Management leads a 24x7 monitoring and response organization while advancing the detection engineering pipeline, maturing threat intelligence integration, and driving measurable improvement in mean time to detect and mean time to respond. The role combines strategic direction, operational accountability, and organizational leadership to reduce enterprise risk from active and emerging threats, partnering closely with the platform engineering team that owns the underlying security tooling.What You Will Do:Strategy, Governance, and LeadershipDefine and own the enterprise threat detection and response strategy, roadmap, and operating model aligned to cybersecurity, risk, and business objectives.Mature the threat management program through formal governance, playbooks, standards, metrics, and leadership reporting.Present detection and response posture, incident trends, risks, and investment needs to security leadership and executive stakeholders.Establish and monitor KPIs such as mean time to detect (MTTD), mean time to respond (MTTR), detection coverage, and alert quality.Lead prioritization decisions across the SOC, threat intelligence, detection engineering, and incident response functions.Security Operations and MonitoringLead a 24x7 Security Operations Center responsible for monitoring, alert triage, escalation, and initial investigation across the enterprise.Own the detection content lifecycle within the SIEM, and define data source onboarding, log storage, and retention requirements for the platform-owning team.Drive continuous improvement in alert quality, triage efficiency, and analyst workflow to reduce noise and analyst fatigue.Establish tiered operating models, shift coverage, and escalation paths that ensure consistent 24x7 response readiness.Oversee SOC performance metrics, service levels, and quality assurance across monitoring and triage activities.Detection EngineeringLead the detection engineering function responsible for building, tuning, and maintaining detection content across SIEM and security telemetry sources.Drive a detection-as-code approach with version control, testing, peer review, and measurable detection coverage mapped to MITRE ATT&CK.Prioritize detection development against threat intelligence, red team findings, incident learnings, and emerging adversary techniques.Establish metrics for detection coverage, efficacy, and false-positive rates, and drive continuous tuning based on outcomes.Partner with engineering and platform teams to ensure high-quality, well-structured log and telemetry sources feed detection pipelines.Cyber Threat IntelligenceLead the Cyber Threat Intelligence function responsible for strategic, operational, and tactical intelligence supporting detection and response.Operationalize threat intelligence by driving indicator enrichment, threat actor tracking, and intelligence-led detection and hunting priorities.Deliver executive and stakeholder threat briefings that translate the threat landscape into business-relevant risk and action.Establish threat hunting programs that proactively search for adversary activity across the environment ahead of alerting.Manage intelligence sources, sharing partnerships, and integration of intelligence into SIEM, SOAR, and detection workflows.Incident ResponseOwn the enterprise incident response process across detection, triage, containment, eradication, recovery, and post-incident review.Lead major incident coordination, serving as an escalation point and driving cross-functional response during significant events.Establish and maintain incident response playbooks, runbooks, and tabletop exercises to ensure organizational readiness.Drive post-incident reviews and lessons-learned processes that feed detection improvements and control gaps back into the program.Partner with legal, communications, IT, and business stakeholders to ensure coordinated response and regulatory notification where required.Tooling and Automation RequirementsDefine detection and response requirements, use cases, and priorities for the SIEM, SOAR, and log storage platforms owned and operated by the platform engineering team.Partner with the platform-owning team to shape roadmap, data onboarding, retention, and automation priorities that serve detection and response needs.Specify SOAR automation use cases for triage, enrichment, and response, and validate that delivered automations meet analyst workflow requirements.Provide feedback on tooling performance, gaps, and integration needs to drive a unified, efficient analyst workflow across detection, intelligence, and response.Use modern tools including AI-assisted workflows to accelerate investigation, analysis, documentation, and decision-making across the team.Organizational and People LeadershipLead and develop a distributed threat management organization consisting of managers, analysts, detection engineers, threat intelligence analysts, and incident responders.Build organizational clarity across the SOC, threat intelligence, detection engineering, and incident response functions.Provide leadership in talent development, succession planning, coaching, performance management, and team engagement.Manage staffing strategy across full-time employees, partners, and contingent resources, including managed detection and response providers where applicable.Oversee third-party vendors and consulting partners supporting threat management programs and services.Minimum QualificationsBachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline; equivalent experience may be considered.12+ years of progressive experience in cybersecurity, security operations, threat detection, incident response, or threat intelligence.5+ years of leadership experience managing multi-team security operations or threat functions at the Senior Manager or Director level.Demonstrated success leading detection and response programs across SOC operations, detection engineering, threat intelligence, and incident response.Experience managing 15+ person organizations including managers, analysts, and engineers with varied technical specializations.Experience leading major incident response and driving measurable improvement in detection coverage and response times.Experience building or standing up new detection, intelligence, or response capabilities, teams, or services.Technical and Functional QualificationsStrong knowledge of SIEM and log management platforms and log storage technologies such as Elasticsearch or Splunk, including data onboarding, retention, and detection content management.Strong knowledge of security orchestration, automation, and response (SOAR) platforms such as Swimlane or Cortex XSOAR.Strong knowledge of detection engineering practices, detection-as-code, and detection coverage mapped to MITRE ATT&CK.Experience with the cyber threat intelligence lifecycle, threat actor tracking, and intelligence-led detection and hunting.Experience with incident response frameworks, forensic investigation concepts, and major incident coordination.Understanding of threat detection across cloud (Azure, AWS, GCP), endpoint, network, and identity telemetry sources.Familiarity with security frameworks and models such as MITRE ATT&CK, NIST CSF 2.0, and the cyber kill chain.Preferred QualificationsExperience in a Fortune 500, global, manufacturing, or industrial environment with complex, heterogeneous technology estates.Prior experience standing up or transforming a SOC, threat intelligence, detection engineering, or incident response function.Experience with threat detection and response in operational technology (OT) or industrial control system (ICS) environments.Familiarity with platforms such as Elastic, Splunk, Swimlane, Cortex XSOAR, CrowdStrike, or Microsoft Sentinel.Relevant certifications such as CISSP, CISM, GCIH, GCIA, GCTI, or GCFA.Leadership CompetenciesStrategic thinker with the ability to set direction and translate strategy into operational execution.Decisive leader who operates effectively under pressure and makes sound calls during active incidents and competing priorities.Delivery-oriented leader with a strong focus on accountability, measurable outcomes, and service quality.Effective communicator able to translate complex threat and incident topics for executives, stakeholders, and technical teams.Strong collaborator with the ability to influence across infrastructure, cloud, application, legal, and business teams.Proven people leader with the ability to coach talent, build teams, and develop future leaders.Additional InformationThe role leads a 24x7 operation and may require off-hours availability for major incidents, escalations, and key initiatives.Travel up to 10% may be required for site assessments, team collaboration, and vendor engagements.The role may require coordination across global teams, including off-hours support for key initiatives, escalations, or major incidents.Annual or Hourly Compensation RangeThe base salary range for this position is $168,400.00 - $252,600.00. This position is eligible for annual bonus and long-term incentives based on performance, per plan terms. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.BenefitsEcolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families. Click here to see our benefits. If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working-here.Potential Customer Requirements NoticeTo meet customer requirements and comply with local or state regulations, applicants for certain customer-facing roles may need to:- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.Americans with Disabilities Act (ADA)Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process, please visit the Recruiting Support link in the footer of each page of our career website. SummaryLocation: USA - Minnesota - Saint Paul; USA - Illinois - NapervilleType: Full time
$105.4k - $207.8k
...Deloitte’s Cyber Services help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilities. Our Cyber Risk... ...development From entry-level employees to senior leaders, we believe there’s always room to...SeniorLocal areaVisa sponsorship$163.4k - $322.1k
...help our clients navigate the ever-changing threat landscape. Through powerful solutions and... ...confidence, and proactively manage to secure success. Recruiting for this role ends on... ...2026. Work you'll do As a Cloud Security Senior Manager, Azure Infrastructure & AI on the...SeniorWork at officeLocal areaVisa sponsorship- ...Division of a larger group supporting the Food, Beverage and health/nutrition sector. Reporting to the CEO, this role forms part of the senior leadership team responsible for driving best in class operational performance across the business unit. Responsibilities Provide...SeniorFull time
$137.4k - $206.2k
Job Summary: The Director of Identity is responsible for maturing the enterprise Identity... ...operations, architecture, and emerging identity security capabilities. This role provides... ...managing multi-team IAM functions at the Senior Manager or Director level.Demonstrated...SuggestedHourly payMinimum wageFull timeLocal area- ...a Warehouse Operations Manager to oversee 80% management duties across logistics, warehousing, and inventory, ensuring safety and security. Reports to Regional Operations Manager and leads Supervisors, drivers, and office staff. You will optimize warehouse processes, develop...SeniorWork at office
$143.91k - $169.3k
...at—all from Day One.Job DescriptionThe Corporate Audit Services Senior Audit Manager (SAM) is primarily responsible for leading staff... ...completion of audit engagements and managing the assigned Information Security audit portfolio. The SAM is responsible for providing oversight...SeniorFull timeWork experience placementWork at officeLocal area3 days per week- ...The Minnesota Department of Employment and Economic Development is seeking a Security and Safety Coordinator to lead long-range security and safety strategies. You will develop agency-wide policies, planning frameworks, and measures to guide leadership, reduce risk, and...Remote work
$120k
...Director Information Security, Risk & Compliance We are seeking a focused and diligent Director Information Security, Risk & Compliance to own Bridgewater... ...monitoring, vulnerability management, and reporting. Lead threat intelligence, including recurring review of internal/...Temporary workLocal area$140.97k - $188.72k
...Senior Director of Operations Location: St. Paul, MN, US, 55128. Murata Viosis is a global medical device company dedicated to creating a paradigm shift in the way healthcare is delivered. Through the utilization of our internet‑of‑things medical‑grade sensors and virtual...SeniorLocal areaRemote workShift work- ...agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default. AI agents are changing how everyone works — not just...SeniorLocal areaRemote workHome officeShift work
$137.4k - $206.2k
Job Summary: The Director of Security Engineering is responsible for leading enterprise security architecture... ...that harden the environment before threats land.The Director of Security... ...managing multi-team security functions at the Senior Manager or Director level.Demonstrated...Hourly payMinimum wageFull timeLocal area$170k
Please see the below requirements for a Senior or Principal Electrical Engineer to join a growing class III medical device organization in the Northeast Twin Cities Metro. This role will play a critical part in supporting an implantable electromechanical system in a late...Senior$44.8 - $64.46 per hour
...Operations Manager Job Class: State Program Administrator, Manager Senior Agency: MN Department of Natural Resources Job ID: 95655... ..., leasing, site and custodial maintenance, and site safety and security so that business units and divisions can operate in facilities...SeniorHourly payFull timeTemporary workPart timeH1bWork at officeLocal areaRemote workRelocationWork visaMonday to FridayFlexible hoursShift workDay shift- ...Pearson in Minnesota seeks an Advanced Specialist, Bid Management (Senior Proposal Analyst) to partner with Business Development, Solutions, SMEs, and the proposals team to craft high-quality proposals in a fast-paced environment. You will manage the full proposal lifecycle...Senior
$139.3k - $250.7k
...our core capabilities, the team enables secure, highly performant, and cost-effective infrastructure... ...cloud growth. Partner with the best As a Senior Product Manager for Core Compute, define... ...performance. Security : Neutralizing threats before they ever reach your data. Content...SeniorWork experience placementWork at office- ...Suite Living Senior Care is seeking a Regional Maintenance Technician to support 4-5 assisted living communities in the eastern Twin Cities Metro. This role is ideal for a skilled, self-directed maintenance professional who enjoys variety, takes pride in preventative...Senior
$180.5k - $227.85k
...platform engineers love and enterprises trust. We help teams build, secure, and operate modern cloud applications using real programming... ...technical instincts with the ability to work closely with senior engineers and reason about architectural tradeoffs. Proven ability...SeniorFull timeLive inLocal areaRemote workFlexible hours$111.3k - $207.8k
...the Individual Life market. The Life Competitive Intelligence Senior Consultant serves as the strategic owner of life insurance... ...position will identify market opportunities, evaluate competitive threats, influence product and business decisions, and ensure Securian...SeniorFull timeWork at officeFlexible hoursShift work3 days per week- ...A leading healthcare organization is seeking a Senior Counsel to advise on complex legal matters in support of senior-focused primary care. Responsibilities include drafting and negotiating arrangements, collaborating on agreements, and ensuring compliance across operations...SeniorRemote work
- Cushman & Wakefield in Saint Paul is seeking a Project Design Manager to lead a team of design professionals from concept through construction documentation. The role focuses on implementing workplace standards, coordinating design deliverables, and guiding project designers...Senior
- Job description Insurance Business Analyst Who are we looking for? Insurance Business Analyst Skills. Key Skills: 8+ years of overall IT experience. 1 Hands-on expertise in business-capability modelling and value-stream/process analysis 2. Proven skill in functional overview...Senior
- AtBluum,webelieveeverystudentdeservesaccesstotechnologythatenablesbetterlearningoutcomes.Formorethan50years,we'vepartneredwithK–12schoolsacrossNorthAmericatodeliverinnovativetechnologysolutionsthatsupportteachingandlearning. We'relookingforastrategicandcollaborative SeniorManager...Senior
- ...Bon Appetit Management Company in Saint Paul, MN seeks a Senior Sous Chef for education account operations. You will supervise and assist in preparation, cooking, menu development, and garnishment under the guidance of the Executive Chef. The role includes cost control...Senior
$116.9k - $175.4k
Mortenson Construction is looking for a Planning and Scheduling Manager to join their team in Minnesota. This role involves leading project scheduling efforts for large, complex projects and requires a minimum of eight years of construction experience. The ideal candidate...Senior$80k - $115k
...Mitchell Hamline School of Law in Saint Paul, Minnesota, is hiring a full-time Staff Attorney or Senior Staff Attorney. The role focuses on public health and involves providing legal assistance and training in commercial tobacco control. Candidates need a Juris Doctor...SeniorFull time$62.78k - $83.03k
...Clayton Homes (New) is seeking a Senior HR Generalist in Redwood Falls, MN, to lead core HR functions, including employee relations, recruitment, and compliance. The role requires strong HR experience along with the ability to influence and coach leaders. This full-time...SeniorFull time- Senior Principal Quality ScientistTwin Cities, MN (Hybrid)About the OpportunityWe are seeking an experienced Senior Principal Quality Scientist to provide quality leadership and oversight for research and development activities supporting regulated healthcare products....Senior
$72k - $108k
A national blended health organization is seeking an experienced sales professional to identify and cultivate new business opportunities in the health insurance space. The role involves prospecting for new group business, maintaining relationships with key consultants, ...SeniorRemote work$147.4k - $336.8k
...Ernst & Young Oman is seeking a Real Estate Tax Senior Manager to lead tax planning projects and provide advisory services across real estate, hospitality, and construction sectors. This role requires strong experience in tax, management and teamwork. With a competitive...Senior- A leading travel management company is seeking a Travel Consultant to provide exceptional service to defense and government travelers in Saint Paul, Minnesota. The ideal candidate will have over five years of experience and expertise in native GDS (Sabre). Responsibilities...SeniorFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Director, Security Threat. Be the first to apply!
- director information security Saint Paul, MN
- security manager Saint Paul, MN
- surveillance manager Saint Paul, MN
- security systems manager Saint Paul, MN
- corporate security manager Saint Paul, MN
- security operations manager Saint Paul, MN
- senior business analyst Saint Paul, MN
- senior manager tax Saint Paul, MN
- senior devops Saint Paul, MN
- senior associate vice president Saint Paul, MN

