Demo

SOC and Incident Response, Executive Director

Candescent
Atlanta, GA Full Time
POSTED ON 3/5/2025
AVAILABLE BEFORE 6/4/2025

Candescent is the largest non-core digital banking provider. We bring together the transformative technologies that power and connect account opening, digital banking and branch solutions for banks and credit unions of all sizes on any core. Our Candescent solutions power the top three U.S. mobile banking apps and are trusted by banks and credit unions of all sizes.

We offer an extensive portfolio of industry-leading products and services with an extensible ecosystem of out-of-the-box and integrated partner solutions. In addition, our API-first architecture and developer tools enable financial institutions to optimize and expand upon their existing capabilities by seamlessly integrating custom-built or third-party solutions. And our connected in-person, remote and digital experiences reinvent customer service across all channels.

Self-service configuration and marketing tools give financial institutions greater control of their branding, targeted messaging and overall user experience. And data-driven analytics and reporting tools provide valuable insights to help drive continued growth and profitability. From conversions and implementations to custom development and customer care, our clients get expert, end-to-end support at every step.

Title : SOC and Incident Response, Executive Director

Location : Atlanta, GA

About Candescent

Candescent is the largest non-core digital banking provider. We bring together the transformative technologies that power and connect account opening, digital banking and branch solutions for banks and credit unions of all sizes on any core. Our Candescent solutions power the top three U.S. mobile banking apps and are trusted by banks and credit unions of all sizes.

We offer an extensive portfolio of industry-leading products and services with an extensible ecosystem of out-of-the-box and integrated partner solutions. In addition, our API-first architecture and developer tools enable financial institutions to optimize and expand upon their existing capabilities by seamlessly integrating custom-built or third-party solutions. And our connected in-person, remote and digital experiences reinvent customer service across all channels.

Self-service configuration and marketing tools give financial institutions greater control of their branding, targeted messaging and overall user experience. And data-driven analytics and reporting tools provide valuable insights to help drive continued growth and profitability. From conversions and implementations to custom development and customer care, our clients get expert, end-to-end support at every step.

Executive Director, SOC & Incident Response

This role is a critical part of the Candescent Information Security team, responsible for the development, implementation, and maintenance of Candescent's information security program. The primary objective of this program is to safeguard the confidentiality, integrity, and availability of information resources. Key functions include architecture and design of information security controls, policy and standards development, security awareness training, risk management, assessment and testing, monitoring and metrics, incident management, threat and vulnerability management, and fraud prevention.

The Executive Director of Security Operations Center (SOC) and Incident Response will be responsible for leading and managing a team of security professionals to ensure the protection of the organization's critical information assets. This role will oversee the day-to-day operations of the SOC, incident response processes, policies, tools, threat intelligence and the development and implementation of security best practices. These capabilities of this aspect of the security program are 24 / 7 / 365.

Key Responsibilities

  • Strategic Leadership and Management

Develop and execute a strategic vision for the SOC, balancing internal and external resources and AI-enhanced capabilities.

  • Define performance metrics (e.g., MTTD, MTTR) to measure and continuously improve SOC effectiveness.
  • Align SOC operations with organizational risk tolerance and compliance requirements.
  • Outsourced EDR / MSSP Vendor Oversight
  • Manage relationships with EDR / MSSP vendors to ensure services align with SLAs and organizational security goals.
  • Oversee vendor performance, tracking :
  • SLA Adherence Rates : Ensure timely incident escalation and response.

  • Vendor Detection Effectiveness : Percentage of actionable alerts provided.
  • Cost per Incident : Evaluate cost efficiency of vendor services.
  • Coordinate with vendors to integrate their processes into in-house workflows, ensuring seamless communication and incident handoffs.
  • AI and Automation Integration
  • Identify, deploy, and manage AI / ML-enabled tools to enhance threat detection, triaging, and response capabilities.

  • Implement AI-driven solutions for :
  • Predictive threat modeling.

  • Automated alert triaging and prioritization.
  • Behavior-based anomaly detection.
  • Regularly evaluate and refine AI models to maintain effectiveness and reduce biases.
  • Use AI-enhanced tools like SOAR (e.g., Cortex XSOAR, Swimlane) to streamline repetitive tasks and improve incident response times.
  • Security Monitoring and Threat Detection
  • Oversee real-time monitoring of security events, using tools such as AI-powered SIEM (e.g., Splunk, Sentinel) and EDR platforms.

  • Optimize alert handling by integrating AI with outsourced provider(s) system(s) to prioritize high-risk threats.
  • Track metrics such as :
  • False Positive Rate : Effectiveness of AI and outsourced detection mechanisms.

  • Alert Volume : Monitor the number and quality of alerts generated.
  • Incident Response and Crisis Management
  • Lead all incident response efforts, coordinating between internal teams, external investigations / forensics vendors and MDR / MSSP vendors.

  • Develop and enforce incident playbooks that integrate vendor and AI-driven processes.
  • Ensure SLAs are met for critical incident resolution and containment times.
  • Track metrics such as :
  • Incident Escalation Rates : Effectiveness of handoffs between vendors and internal teams.

  • Containment Time : Speed of isolating compromised systems.
  • Proactive Security Enhancements
  • Drive initiatives such as red / blue / purple teaming and proactive threat hunting, leveraging AI to uncover latent threats.

  • Collaborate with service providers to share threat intelligence and improve defense strategies.
  • Measure :
  • Proactive Threat Hunt Coverage : Percentage of time analysts dedicate to proactive security activities.

  • Vulnerability Remediation Time : Time taken to patch critical vulnerabilities.
  • Metrics-Driven Management
  • Define and track key metrics to evaluate SOC and vendor performance, including :

    MTTD (Mean Time to Detect) : Time to identify threats (Goal :

  • MTTR (Mean Time to Respond) : Time to mitigate threats (Goal :
  • Incident Closure Rate : Percentage of resolved incidents within SLAs (Goal : >
  • 95%).

  • Automation Utilization : Tasks automated by AI and SOAR tools (Goal : >
  • 50% of routine tasks).

  • Present performance dashboards to executive leadership, translating security metrics into business value.
  • Team Development and Coordination
  • Lead and develop a high-performing SOC & Incident Response team

  • Manage in-house analysts and engineers to focus on :
  • High-priority incidents escalated by service providers.

  • Threat hunting, vulnerability management, and long-term strategic improvements.
  • Coordinate training for internal teams to handle escalated incidents effectively.
  • Maintain readiness for "last-mile" incident response (e.g., containment, forensic investigations) that cannot be fully outsourced.
  • Training and Collaboration
  • Train internal teams to collaborate effectively with MDR / MSSP vendors and use AI tools to their full potential.

  • Promote a culture of continuous learning to keep the SOC team updated on the latest tools, threats, and methodologies.
  • Qualifications :

  • Experience & Education
  • 10 years of experience in cybersecurity, with at least 5 years in a SOC or Incident Response leadership role.

  • Proven track record in managing security operations within financial services and SaaS sectors.
  • Bachelor's degree in Cybersecurity, Information Technology, or related field (advanced degree preferred).
  • Skills & Expertise
  • Deep knowledge of cloud security technologies, tools, and best practices.

  • Experience with industry-leading cloud platforms (e.g., AWS, Azure, GCP) and security tools (e.g., SIEM, EDR, SOAR).
  • Strong understanding of compliance frameworks relevant to financial services (e.g., MITRE, NIST CSF, SOC 2, PCI-DSS).
  • Excellent communication, interpersonal and decision-making skills, with the ability to manage complex, high-stakes incidents.
  • Collaboration and work closely with IT, development, and operations stakeholders.
  • Experience in developing and maintaining SOC, IR, and SOP policies and procedures.
  • Ability to identify and resolve complex security issues.
  • Certifications (preferred but not required)
  • CISSP, CISM, GCIH, or similar certifications.

  • Cloud security certifications (e.g., GCP / AWS Certified Security - Specialty).
  • EEO Statement

    Integrated into our shared values is Candescent's commitment to diversity. Candescent is committed to being a globally inclusive company where all people are treated fairly, recognized for their individuality, promoted based on performance and encouraged to strive to reach their full potential. We believe in understanding and respecting differences among all people. This concept encompasses but is not limited to human differences with regard to race, ethnicity, religion, gender, culture and physical ability. Every individual at Candescent has an ongoing responsibility to respect and support a globally diverse environment.

    Offers of employment are conditional upon passage of screening criteria applicable to the job.

    EEO Statement

    Integrated into our shared values is Candescent's commitment to diversity and equal employment opportunity. All qualified applicants will receive consideration for employment without regard to sex, age, race, color, creed, religion, national origin, disability, sexual orientation, gender identity, veteran status, military service, genetic information, or any other characteristic or conduct protected by law. Candescent is committed to being a globally inclusive company where all people are treated fairly, recognized for their individuality, promoted based on performance, and encouraged to strive to reach their full potential. We believe in understanding and respecting differences among all people. Every individual at Candescent has an ongoing responsibility to respect and support a globally diverse environment.

    Statement to Third Party Agencies

    To ALL recruitment agencies : Candescent only accepts resumes from agencies on the preferred supplier list. Please do not forward resumes to our applicant tracking system, Candescent employees, or any Candescent facility. Candescent is not responsible for any fees or charges associated with unsolicited resumes.

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a SOC and Incident Response, Executive Director?

    Sign up to receive alerts about other jobs on the SOC and Incident Response, Executive Director career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $194,072 - $240,547
    Income Estimation: 
    $220,784 - $286,649
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $123,246 - $161,441
    Income Estimation: 
    $152,549 - $188,894
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at Candescent

    Candescent
    Hired Organization Address Atlanta, GA Full Time
    Candescent is the largest non-core digital banking provider. We bring together the transformative technologies that powe...
    Candescent
    Hired Organization Address Atlanta, GA Full Time
    Candescent is the largest non-core digital banking provider. We bring together the transformative technologies that powe...
    Candescent
    Hired Organization Address Atlanta, GA Full Time
    Candescent is the largest non-core digital banking provider. We bring together the transformative technologies that powe...
    Candescent
    Hired Organization Address GA Full Time
    Candescent is the largest non-core digital banking provider. We bring together the transformative technologies that powe...

    Not the job you're looking for? Here are some other SOC and Incident Response, Executive Director jobs in the Atlanta, GA area that may be a better fit.

    Incident Response Planning Specialist

    TEKsystems, Atlanta, GA

    AI Assistant is available now!

    Feel free to start your new journey!