Director, Security Operations (Onsite)

Location: 

Longmont, CO, US

Posting Date:  Aug 20, 2026
Job ID:  14893

About our group:

Seagate Technology is a global leader in data storage solutions. The Information Technology organization enables secure, scalable, and resilient systems across a complex global enterprise spanning cloud, enterprise IT, and operational technology (OT).

 

The Information Security organization is responsible for protecting Seagate’s global technology environment and enabling secure, resilient business operations. Security Operations leads the day-to-day defense of the enterprise, including security monitoring, detection, incident response, threat intelligence, threat hunting, vulnerability management, and the operational effectiveness of security controls across enterprise IT, cloud, factory, and engineering environments.

About the role - you will:

The Director, Security Operations leads Seagate's global Security Operations capability and is accountable for a mature, measurable, and continuously improving defense program.

 

The role leads 24x7 monitoring and response and oversees the Security Operations portfolio across SOC, incident response, detection engineering, threat intelligence, threat hunting, vulnerability management coordination, firewall operations, and security control operations assigned to the function.

 

  • Lead a global Security Operations organization with clear ownership, priorities, service levels, and measurable outcomes.
  • Operate effectively across internal teams, managed security service providers, specialist partners, and retained incident-response capabilities.
  • Ensure monitoring, detection, response, and vulnerability management coverage is appropriate across enterprise IT, cloud, and OT environments, in partnership with OT Security where applicable.
  • Translate operational security signals into prioritized action and clear communication for Information Security, IT, manufacturing, engineering, and business stakeholders.
  • Build a high-accountability team culture focused on disciplined execution, continuous improvement, and risk reduction.

 

This is a people leadership role with global responsibility, including oversight of a firewall operations manager and team responsible for firewall-related service requests and operational execution.

About you:

  • You are a pragmatic, execution-oriented security leader who combines strong operational judgment with enough technical depth to challenge assumptions and make sound decisions.
  • You remain calm during high-severity incidents and communicate clearly with both technical and executive audiences.
  • You focus on outcomes over activity and use data to prioritize the work that most improves security outcomes.
  • You are comfortable operating in complex, heterogeneous environments with competing priorities and constraints.
  • You build strong partnerships while maintaining clear accountability and decision rights.

 

 

You will be responsible for the following activities:

 

Security Operations Leadership & Operating Model:

 

  • Own the Security Operations strategy, service portfolio, staffing model, priorities, and performance.
  • Set clear accountabilities across in-house teams, managed services, and specialist providers, including service levels and escalation paths.
  • Establish a risk-based operating cadence focused on the highest-impact threats, incidents, vulnerabilities, and control gaps.

 

SOC, Detection Engineering & Threat Hunting:

 

  • Lead 24x7 monitoring, triage, escalation, and advanced analysis across enterprise IT, cloud, and OT environments, including OT-related security alerts in partnership with OT Security.
  • Own the detection lifecycle: use-case strategy, rule development, testing, tuning, coverage analysis, and retirement of ineffective detections.
  • Build an intelligence-led threat hunting capability and partner with Architecture & Engineering on SIEM, EDR/XDR, telemetry, and security platform architecture.

 

Incident Response & Crisis Readiness:

 

  • Own incident response plans, playbooks, severity models, command structures, and escalation processes.
  • Lead or oversee significant incidents from investigation and containment through recovery and post-incident review, including OT-related cyber incidents in coordination with OT Security and manufacturing stakeholders.
  • Maintain enterprise and plant/engineering-specific playbooks, tabletop exercises, simulations, and forensics readiness.

 

Threat Intelligence & Vulnerability Management:

 

  • Own threat intelligence collection, analysis, prioritization, and operationalization, translating intelligence into detections, hunts, and response readiness.
  • Lead the vulnerability management program by driving scanning coverage, risk-based prioritization, tracking, escalation, and reporting, while coordinating remediation through accountable system, application, infrastructure, and OT owners.
  • Coordinate remediation with Architecture & Engineering, IT, application teams, OT Security, and business owners using exposure, exploitability, asset criticality, and threat context.

 

Security Control Operations & Service Reliability:

 

  • Oversee centralized firewall operations, including a manager-led team responsible for firewall service requests, port open and close requests, change execution, monitoring, and operational reliability.
  • Ensure EDR/XDR and related controls are used effectively for investigation, containment, and response. Partner with Architecture & Engineering on platform engineering and lifecycle management.
  • Drive automation and orchestration that improve analyst efficiency, response speed, consistency, and quality.

 

Metrics, Continuous Improvement & Partnerships:

 

  • Define operational metrics, including time to detect, time to contain/respond, detection coverage and fidelity, incident recurrence, remediation velocity, and service performance.
  • Provide clear, fact-based reporting on operational effectiveness, trends, risks, trade-offs, and constraints to Information Security and IT leadership.
  • Create a closed-loop feedback process so incident lessons, threat intelligence, control failures, and vulnerability trends inform future architecture, engineering, and risk decisions.
  • Recruit, develop, coach, and retain a high-performing global team and hold security service providers accountable for measurable outcomes.

Your experience includes:

  • Typically 12+ years of cybersecurity experience, including 7+ years leading Security Operations, SOC, incident response, or closely related teams in a large enterprise environment.
  • Demonstrated experience leading global or distributed 24x7 security operations using in-house, managed-service, or hybrid delivery models.
  • Experience overseeing firewall operations or similar security-control service teams responsible for request intake, change execution, access changes, and operational reliability.
  • Strong experience with incident response, crisis management, detection engineering, threat intelligence, threat hunting, and vulnerability management.
  • Working knowledge of modern security operations technologies, including SIEM, EDR/XDR, SOAR, threat intelligence, and vulnerability management platforms.
  • Experience establishing operational metrics and using data to improve control effectiveness, detection quality, response performance, and remediation outcomes.
  • Demonstrated ability to lead high-severity incidents and communicate technical issues, business impact, decisions, and trade-offs to senior leadership.
  • Proven people leadership experience, including organizational design, talent development, performance management, and leading through change.
  • Strong experience managing security service providers and holding third parties accountable for measurable outcomes.

 

You Might Also Have:

 

  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Engineering, or a related technical discipline and 15+ years of experience; or 12 years and a Master’s degree; or a PhD with 8 years of experience; or equivalent experience.
  • Experience in manufacturing, OT, industrial, or other environments where availability, safety, and operational continuity materially affect security decisions.
  • Experience improving security operations across complex hybrid environments spanning on-premises infrastructure, cloud services, endpoints, identity, and OT.
  • Certifications such as CISSP, CISM, GIAC incident response/detection certifications, or equivalent practical experience.
  • Experience with global incident exercises, forensics retainers, regulatory or customer security obligations, and executive-level security reporting.

 

The estimated base salary range for this position is $167,730.00 - $249,071.00. The individual salary is based on work location and additional factors, including job-related skills, experience, and relevant education or training.

 

Seagate offers comprehensive benefits to its eligible employees, including, but not limited to, eligibility to participate in a discretionary bonus program, medical, dental, vision, and life insurance, short- and long-term disability, 401(k), employee stock purchase plan, health savings account, dependent care, and healthcare spending accounts. Seagate also offers paid time off, including 12 holidays, flexible time off provided pursuant to Seagate policy, a minimum of 48 hours of paid sick leave, and 16 weeks of paid parental leave. The benefits for this position are based on a full-time schedule for a full calendar year and may differ depending on work location.

Location:

This role is an on-site position based in Longmont, CO.

 

Our Longmont product-design campus is nestled against the foothills with exceptional views of the Rocky Mountains. Here at work, you can grab breakfast and lunch in the on-site cafeteria or get an afternoon espresso, prepared by a professional barista. Our 600+ employees enjoy an active on-site experience from sporting activities (get in a few laps at lunch on our 1-mile walking path around campus, play ping-pong or volleyball, or stop in our 24-hour fitness center for a group or individual workout). We also offer opportunities for community service and participation in various employee resource groups.

 

Location: Longmont, United States
Travel: Up to 10%


 

 

 

 

 

 

 

 

 

 

About Us

With more than four decades of storage innovation, Seagate empowers humanity to thrive in the data age and helps people and businesses navigate the ever-expanding data landscape. 

We craft precision-engineered, cutting-edge solutions that help the world store and manage exponential data growth.

Seagate is powered by our talented and passionate workforce of 29,000 employees across the globe who embody our core values: integrity, innovation, and inclusion. Striving towards excellence every single day, we show up with these values for our customers, business partners, shareholders, and communities alike.

Join us and get inspired to make a difference in the datasphere!

 

 

Seagate is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, race, color, ancestry, national origin, citizenship status, physical or mental disability, genetic information, marital status, sex (which includes pregnancy, childbirth, breastfeeding, or related medical conditions), gender, gender identity, gender expression, sexual orientation, religion, military and veteran status, or other status protected by applicable law.  We will consider for employment qualified applicants with arrest and conviction records. EEO Know Your Rights Poster 

Seagate will provide reasonable accommodation with the application process upon request as required to comply with applicable laws. If you need assistance or accommodation due to a disability, you may contact us at accommodations@seagate.com. 

All Seagate jobs will remain open for a minimum of seven days.

For information on how Seagate collects and uses your personal information during the application process, please review the Applicant Privacy Statement.


Nearest Major Market: Boulder
Nearest Secondary Market: Denver