| Location | Plano, Texas |
Why Ryan?
Hybrid Work Options
Award-Winning Culture
Generous Personal Time Off (PTO) Benefits
14-Weeks of 100% Paid Leave for New Parents (Adoption Included)
Monthly Gym Membership Reimbursement OR Gym Equipment Reimbursement
Benefits Eligibility Effective Day One
401K with Employer Match
Tuition Reimbursement After One Year of Service
Fertility Assistance Program
Four-Week Company-Paid Sabbatical Eligibility After Five Years of Service
The Senior Director, Security Development and Operations provides strategic leadership and oversight for Ryan’s integrated security program, including proactive threat management, secure software development, incident response, and team development. This leader strengthens the Firm’s security posture by advancing incident response playbooks, the secure software development life cycle, threat hunting, penetration testing, and performance measurement. Working cross-functionally with engineering, information technology, compliance, and product teams, the Senior Director helps embed security throughout the Firm’s technology stack and culture.
Duties and Responsibilities, as They Align to Ryan’s Key Results
People
Team Leadership and Development
Lead, mentor, and grow a high-performing team of security practitioners, including engineers, analysts, and architects, fostering a culture of continuous learning and collaboration.
Provide guidance and hands-on training to elevate team capabilities in penetration testing, incident response, and threat hunting.
Identify skill gaps, promote professional development, and ensure alignment of security team activities with organizational goals.
Client
Security Controls and Solutions Management
Develop and maintain foundational security controls and solutions, including endpoint detection and response (EDR), security information and event management (SIEM) platforms, email security systems, and cloud security controls.
Evaluate, select, and optimize security technologies to ensure comprehensive threat coverage, alignment with regulatory requirements, and cost-effective risk reduction.
Collaborate with stakeholders to ensure solutions integrate seamlessly with existing infrastructure and workflows.
Value
Secure Software Development Life Cycle and Architecture
Partner with engineering, product, and information technology teams to design and maintain a robust secure software development life cycle (SDLC), embedding security controls and checks throughout the development pipeline.
Review and refine security architecture to ensure applications and infrastructure adhere to best practices and industry standards.
Integrate automated security testing, code analysis, and vulnerability scanning into development workflows to minimize risk and accelerate secure code delivery.
Incident Response and Threat Management
Oversee the continuous improvement of incident response playbooks and processes, ensuring efficient, repeatable workflows for detecting and addressing security incidents.
Direct proactive threat hunting initiatives, leveraging threat intelligence, advanced analytics, and tooling to identify and mitigate risks before they can be exploited.
Guide the implementation of remediation strategies and assess their efficacy against emerging threats.
Penetration Testing and Security Assessments
Establish and evolve a formal penetration testing program, ensuring the use of recognized methodologies, such as Open Worldwide Application Security Project (OWASP) guidance and the Penetration Testing Execution Standard (PTES), and industry-standard tools.
Ensure the team remains current on penetration testing best practices, regularly assessing critical systems, applications, and infrastructure.
Oversee the documentation and presentation of penetration testing findings, including recommended remediation steps and timelines.
Metrics, Key Performance Indicators, and Reporting
Define, implement, and regularly review key performance indicators (KPIs) and metrics to quantify the effectiveness and maturity of security operations, development practices, and threat management efforts.
Communicate program performance and trends to executive leadership, along with data-driven recommendations for continuous improvement.
Maintain transparency and accountability by delivering clear, concise reports that highlight progress, challenges, and opportunities.
Other Threat Management Duties
Perform other threat management duties as assigned.
Education and Experience
Bachelor’s degree in computer science, cybersecurity, information systems, or a related field; master’s degree preferred.
12 or more years of progressive experience in cybersecurity, including leadership roles overseeing security operations center operations, secure development practices, and proactive threat management.
Demonstrated success in guiding teams through complex security initiatives and maturing security programs.
Computer Skills
Strong proficiency in both Microsoft Windows and Linux operating systems.
Ability to write and understand code and scripting languages, such as Python, Bash, and PowerShell, for automation, tooling integration, and validation of security controls.
Understanding of common penetration testing methodologies and primary security assessment tools, such as Nmap, Metasploit, and Burp Suite.
Knowledge of foundational security controls, including endpoint detection and response, security information and event management, email security gateways, and cloud security platforms, and their strategic deployment.
Familiarity with regulatory frameworks, compliance standards, including the National Institute of Standards and Technology Cybersecurity Framework 2.0 and SOC 2, and industry best practices.
Certificates and Licenses
Certified Information Systems Security Professional (CISSP), OffSec Certified Professional (OSCP), Certified Ethical Hacker (CEH), GIAC Certified Incident Handler (GCIH), or similar certifications preferred.
Valid driver’s license required.
Supervisory Responsibilities
This position will have supervisory responsibilities, overseeing multiple security team members and functions.
Equal Opportunity Employer: disability/veteran