Hyland is the pioneer of the Content Innovation Cloud™, delivering ubiquitous enterprise intelligence to organizations. The Associate Vice President of Security Engineering & Operations is responsible for building and scaling a high-performance security function, leading the Security Operations Center, and embedding security into various engineering processes.
Responsibilities:
- Build and lead a highly efficient, AI-enabled Security Operations Center (SOC), delivering threat detection, exposure management, posture management, incident response, and digital forensics capabilities; define and own KPIs for SOC performance including MTTD, MTTR, and SLA adherence
- Oversee and continuously improve DevSecOps/AppSec integration, embedding security into CI/CD pipelines, SCA/SAST/DAST tooling, secure code review, non-human identity/API security programs, and threat modeling
- Direct and approve the design of security systems including zero trust architecture, network segmentation, and identity security; drive offensive and defensive security operations including red teaming and blue team resilience
- Lead end-to-end ownership of multi-faceted and distributed vulnerability management programs, including prioritization frameworks and release gates tied to business risk
- Set vision and collaborate with senior management to define departmental strategy and budget management; develop future leaders and build a management team bench capable of meeting the demands of rapid growth
- Serve as a strategic partner to product, engineering, and technical teams to embed security into the software development lifecycle; act as an escalation point for complex and high-level security issues and removing obstacles for security and stakeholder teams
Requirements:
- Bachelor's degree in computer science, information security, engineering, or a related field
- 15+ years of progressive experience in cybersecurity or engineering leadership
- At least 5 years in SaaS cloud-native environments
- Proven track record of leading incident response, application security, or DevSecOps functions at enterprise scale
- Deep expertise in DevSecOps, cloud-native security, software engineering, and automation
- Exceptional knowledge of CI/CD, SRE, and multi-cloud operating environments
- Demonstrated fiscal responsibility and accountability in managing budgets
- Track record for consolidating tooling expenses
- Up to 10% travel time required
- Relevant certifications such as CISSP, CISM, SANS/GIAC, CSSLP, or OSCP
- Exceptional ability to design, implement, and prove security effectiveness through evidence-based testing and measurable outcomes
- Deep familiarity with cloud-native security architecture
- Experience defining and owning KPIs for SOC performance and engineering delivery
- Strong ability to build and maintain relationships with stakeholders
- Experience with zero trust architecture, network segmentation, and identity security design and implementation
- Strong people leadership skills with a proven track record of developing future leaders and building high-performance security teams