van den Boom & Associates
See how your profile stacks up against this role.
We compared the job requirements to your profile to show where you're strong and where you fall short.
vdBA SecureOps is building a security-led managed services practice for life sciences clients, anchored by our Secure + MDR offering. We're looking for a Director of Managed Security Services to own that offering end to end: the security operations that support it, the compliance programs that prove it out, and the client-facing credibility that sells it. This is a build-phase leadership role — you'll need real MSSP-side experience running a security practice as a service, not just securing a single organization from the inside.
Own the Security Service Line
Serve as the owner of the Secure + MDR offering — the technical and operational face of vdBA's security practice.
Set the roadmap, tooling stack, and staffing model for the security operations function as it scales.
Define SLAs, escalation paths, and quality standards for 24/7 MDR delivery.
Own the security incident response process end to end: detection, triage, client communication, and post-incident review.
Security Operations & Tooling
Directly manage or oversee SOC/SecOps functions, including SIEM monitoring, threat detection, alert triage, and incident response.
Maintain and optimize the security tool stack, including SIEM (e.g., Microsoft Sentinel, Splunk, QRadar, LogRhythm), EDR/XDR (e.g., CrowdStrike, SentinelOne, Microsoft Defender), SOAR, vulnerability management (e.g., Tenable, Qualys, Rapid7), identity and access security (e.g., Okta, Entra ID, Duo), email security (e.g., Proofpoint, Mimecast), and threat intelligence feeds.
Evaluate and integrate new security tools and partners as the MDR practice matures.
Compliance & Security Program Build
Build, document, and manage administrative security programs — policies, controls, and evidence collection — to support both internal and client compliance obligations.
Lead vdBA's (and support clients') attainment and ongoing maintenance of SOC 2 Type II, HITRUST, ISO 27001, and other relevant frameworks.
Own compliance automation tooling such as Drata, Vanta, or Secureframe, including control mapping, audit readiness, and continuous monitoring.
Serve as the primary point of contact for auditors and compliance reviews.
Client & Cross-Functional Engagement
Act as the technical security authority in sales conversations, QBRs, and security due diligence requests.
Partner with sales and leadership to scope client security needs and translate risk into clear recommendations.
Work with the Service Desk and other delivery functions so security controls are embedded in day-to-day operations, not siloed.
Team & Program Leadership
Build and lead the security operations team as the practice scales — expect a hands-on, individual-contributor-plus-oversight posture in the early stage.
Establish metrics and reporting to track security posture, incident trends, and program maturity for leadership and the board.
Required
Prior experience at an existing MSSP (Managed Security Service Provider) in a leadership or senior technical capacity — internal/enterprise-only security experience is not a substitute.
Hands-on experience with SecOps and SIEM tooling (e.g., Splunk, Microsoft Sentinel, QRadar, LogRhythm, or similar).
Experience across the broader security stack: EDR/XDR, SOAR, vulnerability management, identity and access security, email security, and threat intelligence.
Proven experience building and managing administrative security/compliance programs, including leading organizations through SOC 2 Type II and/or HITRUST audits.
Direct experience with compliance automation platforms such as Drata, Vanta, or Secureframe.
Strong working knowledge of security and compliance frameworks: SOC 2, HITRUST, ISO 27001, NIST CSF, and HIPAA.
Ability to communicate security risk and posture clearly to both technical staff and business/executive stakeholders.
Preferred
Experience serving life sciences, healthcare, or other regulated industries.
Relevant certifications (e.g., CISSP, CISM, GIAC/GCIH, CISA).
Experience building a security service line or practice from an early stage, rather than only operating an existing mature one.
What We're Looking For
A builder who can create structure, process, and credibility where none exists yet.
Comfortable owning both strategic security direction and hands-on operational work in the early stage.
High integrity and discretion, given the sensitivity of security and compliance data.
A fast learner who is energetic and adaptable in a fast-growing environment.
vdB&A is an equal opportunity employer. We welcome and consider qualified applicants regardless of race, religion, gender identity, sexual orientation, disability, or any other status protected by applicable law.
After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.
Marcus Rivera
Chief Revenue Officer

Marvya

Ncontracts

Socure

TekRecruiter

Remote Choice

van den Boom & Associates