Director of Cybersecurity Operations
Company Information
For more than 20 years, AEG has played a pivotal role in transforming sports and live entertainment. Annually, we host more than 160 million guests, promote more than 10,000 shows and present more than 22,000 events around the world. We are committed to innovation, artistry, and community, and leverage the power of our 300+ venues, leading sports franchises, marquee music brands, integrated entertainment districts, premier ticketing platform and global sponsorship activations, to create memorable moments that give the world reason to cheer.
Our business is interwoven with the human mind and heart, and we strive to build a diverse and inclusive company that reflects the artists, athletes, and fans that we host; reach beyond traditional boundaries to support the communities in which we operate; and minimize our impact on the environment by adopting sustainable practices throughout our business operations.
If you want to be challenged to up your game and make a difference, then join us in giving the world reason to cheer!
Job Summary
The Director of Cybersecurity Operations leads the organization's global cyber operations strategy, strengthening operational resilience and maturing enterprise defense capabilities across corporate, cloud, venue, and operational technology environments. Reporting to the Chief Information Security Officer (CISO), this role provides strategic and operational leadership for Security Operations, Threat Detection and Response, Vulnerability Management, Identity and Access Management (IAM), Data Loss Prevention (DLP), Penetration Testing, and Cyber Fusion Center operations. This leader designs, builds, optimizes, and continuously evolves scalable cybersecurity operations—including Global Security Operations Centers (GSOC), advanced detection/response programs, security automation and orchestration, threat intelligence, and globally distributed cyber operations—bringing deep technical expertise, operational leadership, and strategic vision to proactively defend against evolving threats while enabling business growth and technology transformation. The Director partners closely with Information Security Engineering, Infrastructure, Compliance, Legal, HR, and business leaders to strengthen security posture, reduce operational risk, and align initiatives with organizational objectives and regulatory requirements, while developing and communicating meaningful cybersecurity metrics, KPIs, and Key Risk Indicators (KRIs) through executive reporting and briefings on cyber risk, operational maturity, incident trends, and resilience initiatives to support informed decision-making. Success requires building and maturing high-performing programs, leading through complex and fast-changing threat landscapes, communicating effectively with technical and executive stakeholders, and translating cyber risk into actionable, business-focused strategies and outcomes.
Essential Functions
- Security Operations & Cyber Fusion Center Leadership:
- Lead the strategy, design, and optimization of Global Security Operations Center (GSOC) and Cyber Fusion Center capabilities.
- Lead threat detection, monitoring, threat hunting, incident triage, and response operations across enterprise, cloud, venue, and operational technology environments.
- Develop detection engineering capabilities, operational playbooks, escalation procedures, and automation workflows to improve response effectiveness.
- Oversee implementation and optimization of cybersecurity technologies including SIEM, SOAR, EDR/XDR, threat intelligence, and security analytics platforms.
- Manage relationships with security vendors and coordinate globally distributed cyber operations activities.
- Continuously assess and improve operational maturity aligned to industry frameworks, emerging threats, and business priorities.
- Incident Response & Operational Resilience:
- Lead enterprise incident response operations, ensuring rapid identification, containment, eradication, recovery, and post-incident remediation activities.
- Direct the development, testing, and continuous improvement of incident response plans, operational playbooks, tabletop exercises, and cyber crisis simulations.
- Coordinate cross-functional response efforts involving Infrastructure, Legal, HR, Compliance, Privacy, and business stakeholders during cybersecurity incidents.
- Conduct post-incident reviews and drive lessons learned initiatives to improve operational resilience and reduce future risk exposure.
- Support cyber resilience, business continuity, and disaster recovery initiatives related to cybersecurity operations.
- Continuous Threat Exposure Management (CTEM) & Vulnerability Management:
- Lead AEG’s Continuous Threat Exposure Management (CTEM) and enterprise vulnerability management programs across cloud, network, endpoint, application, identity, and operational technology environments.
- Lead identification, prioritization, validation, and remediation of cyber exposures based on threat intelligence, exploitability, and business risk.
- Drive exposure reduction initiatives leveraging threat intelligence, attack surface management, identity security, and security validation activities.
- Partner with Infrastructure, Engineering, Application Development, Cloud Operations, and Compliance teams to coordinate timely remediation and risk reduction initiatives.
- Support identity and access governance initiatives including privileged access management, least-privilege controls, multi-factor authentication, and identity-related risk reduction strategies.
- Oversee vulnerability scanning, attack surface visibility, remediation governance, exposure tracking, and executive-level reporting processes.
- Develop operational metrics, KPIs, and KRIs to measure exposure reduction effectiveness, remediation performance, and overall cyber risk posture.
- Enhance CTEM processes, tooling, automation, and reporting capabilities aligned with evolving threats and business priorities.
- Data Protection & Data Loss Prevention (DLP):
- Lead enterprise Data Loss Prevention (DLP) strategies and data protection initiatives to safeguard sensitive corporate, customer, financial, and regulated data.
- Oversee implementation and monitoring of controls designed to prevent unauthorized access, misuse, disclosure, or exfiltration of sensitive information.
- Conduct regular assessments, audits, and effectiveness reviews of DLP controls and data protection capabilities.
- Partner with Legal, Privacy, Compliance, and business stakeholders to align data protection initiatives with regulatory and organizational requirements.
- Penetration Testing & Security Validation:
- Direct internal and external penetration testing initiatives, red team exercises, and security validation assessments.
- Coordinate remediation activities and track resolution of identified vulnerabilities and security gaps.
- Evaluate effectiveness of security controls through continuous testing and adversary simulation activities.
- Provide strategic recommendations for security architecture and operational improvements based on assessment findings.
- Cybersecurity Strategy, Metrics & Executive Reporting:
- Partner with the CISO and senior leadership to define and execute the cybersecurity operations strategy, roadmap, and maturity initiatives.
- Drive cyber risk reduction initiatives through CTEM, threat-informed defense, and operational maturity programs.
- Develop and communicate meaningful cybersecurity metrics, KPIs, and Key Risk Indicators (KRIs) to measure operational effectiveness, threat exposure, and program maturity.
- Deliver executive-level reporting and briefings on cybersecurity posture, operational resilience, incident trends, emerging threats, and strategic initiatives.
- Translate complex cybersecurity risks and operational issues into clear business-focused insights and recommendations for executive stakeholders.
- Support budget planning, vendor strategy, technology evaluations, and long-term operational planning initiatives.
- Team Leadership & Organizational Development:
- Lead, mentor, and develop high-performing cybersecurity operations teams in a complex, matrixed, and globally distributed environment.
- Foster a culture of accountability, collaboration, innovation, operational excellence, and continuous improvement.
- Support team growth through talent development, succession planning, process improvement, and operational standardization.
- Provide leadership during high-pressure cybersecurity incidents and operational escalations.
- Cross-Functional Collaboration & Stakeholder Engagement:
- Partner with Information Security Engineering, Infrastructure, Compliance, Legal, HR, Privacy, Audit, and business leadership teams to align cybersecurity initiatives with organizational objectives.
- Collaborate with external partners, vendors, industry groups, and law enforcement organizations as appropriate.
- Communicate effectively with technical and non-technical stakeholders to promote cybersecurity awareness, operational alignment, and informed risk management decisions.
- Support enterprise technology transformation initiatives by embedding cybersecurity operational requirements and best practices.
Required Qualifications
- BA/BS Degree (4-year) (Advanced Degree Preferred) Information Technology, Computer Science, Cybersecurity or a related field. Master’s degree preferred.
- 5+ years experience building, scaling, or transforming SOCs, Fusion Centers, or global cyber defense operations.
- Experience leading Security Operations, Incident Response, CTEM/Vulnerability Management, IAM, DLP, Penetration Testing, and Threat Detection programs.
- Strong knowledge of SIEM, SOAR, EDR/XDR, MDR, IAM/PAM, vulnerability management, and cloud security technologies.
- Experience with security automation, detection engineering, threat hunting, and operational process improvement.
- Experience with cloud security operations across AWS, Azure, and/or Google Cloud environments.
- Experience developing cybersecurity metrics, KPIs, KRIs, dashboards, and executive reporting.
- Strong understanding of threat intelligence, MITRE ATT&CK, cyber risk management, and exposure reduction strategies.
- Experience managing MSSPs, MDR providers, cybersecurity vendors, and third-party security partners.
- Strong executive communication and stakeholder management skills with the ability to translate cybersecurity risks into business impact.
- Experience supporting regulatory and compliance frameworks including NIST, ISO 27001, PCI-DSS, SOX, GDPR, and privacy requirements.
- Experience leading cross-functional initiatives within large, matrixed, and geographically distributed organizations.
- 10 years progressive experience in cybersecurity operations, incident response, threat detection, vulnerability management, and enterprise cyber defense within complex enterprise environments.
- Strong written and verbal communication skills with the ability to communicate technical risks to executive and non-technical audiences.
- Deep knowledge of Security Operations, Incident Response, Threat Detection and Response, CTEM/Vulnerability Management, IAM, DLP, and Cyber Fusion Center operations.
- Proven ability to build, mature, and lead cybersecurity operations programs and high-performing teams.
- Strong understanding of modern cyber threats, attack methodologies, threat intelligence, and risk management practices.
- Experience with SIEM, SOAR, EDR/XDR, IAM/PAM, vulnerability management, DLP, and cloud security technologies.
- Knowledge of threat hunting, detection engineering, security automation, and incident response best practices.
- Strong understanding of CTEM, attack surface management, threat-informed defense, and exposure reduction strategies.
- Ability to develop cybersecurity metrics, KPIs, KRIs, dashboards, and executive-level reporting.
- Strong knowledge of cloud security principles, Zero Trust concepts, and hybrid enterprise security architectures.
- Ability to lead high-pressure incident response activities and make informed decisions during critical events.
- Strong project, program, organizational, and operational leadership skills.
- Ability to align cybersecurity strategies and operational priorities with business objectives and enterprise risk management goals.
- Strong collaboration skills with the ability to work effectively across technical, operational, legal, compliance, and business teams.
- Knowledge of applicable cybersecurity and privacy frameworks including NIST, ISO 27001, PCI-DSS, SOX, and GDPR.
- Commitment to continuous improvement and staying current with evolving cybersecurity threats, technologies, and industry trends.
- CISSP Certified Information Systems Security Professional highly desirable
- CISM - Certified Information Security Manager highly desirable
- Certified Emergency Management Specialist (CEMS) highly desirable
- Other equivalent certification highly desirable
Pay Scale: $225,000 to $240,000
The pay scale shown above applies to the LA metro area. Actual pay scale may differ based on geographic region.
Bonus: This position is eligible for a bonus under the current bonus plan requirements.
Benefits: Full-time: We offer a comprehensive benefits package that includes: medical, dental and vision insurance, paid holidays, vacation and sick time, company paid basic life insurance, voluntary life insurance, parental leave, 401k Plan (with a current employer match of 3%), flexible spending and health savings account options, and wellness offerings.
AEG reserves the right to change or modify the employee’s job description whether orally or in writing, at any time during the employment relationship. AEG may require an employee to perform duties outside their normal description.
AEG's policy is to hire the most qualified applicants, and we comply with all applicable federal, state and local employment laws in making hiring and employee decisions. We are an equal opportunity employer and do not discriminate against applicants or employees on the basis of race, color, marital status, disability, religion, age, sex, sexual orientation, national origin, genetic information, veteran status, or any other legally protected status recognized by applicable federal, state or local law.
Employer does not offer work visa sponsorship for this position.