Director, ProdSecOps
This is a transformational role. The Director is expected to lead the organisation from fragmented, task-based security handling into a mature, agile program - modernising how security is embedded across engineering, redefining operational efficiency, and setting how the cybersecurity function operates and perceived across the business.
This role leads the combined Product Security and Security Operations function at Genius Sports. It is a program leadership role responsible for embedding security into how products are designed, built, and shipped - and for owning the full threat detection and incident response pipeline end-to-end.
The Director sets direction for a global team spanning secure development lifecycle, security architecture, threat modeling, vulnerability and exposure management, offensive security, cloud security, security monitoring, and incident management. The role translates cyber risk into business risk and drives the conversation leadership can act on. Strong experience across both Product Security and SecOps is required. This is a leader-coach role in a lean, high-ownership team operating in a regulated sports data and betting environment.
- Lead the transformation from fragmented security tasks to a mature program, reshaping team structure, ways of working, and organisation growth.
- Own the ProdSecOps program - vision, goals, and delivery across both product security and security operations functions.
- Define and lead the product security framework - mapping assets, ownership, and cyber risk to business value.
- Build and maintain a cyber risk management view that is aggregate, contextual, and actionable for leadership.
- Lead, develop, and grow a distributed team across multiple regions and time zones.
- Set team objectives aligned to functional and company-level OKRs. Own delivery against them.
- Drive shift-left security - embed threat modelling, secure design review, and SDL practices into the development lifecycle.
- Own the security architecture direction, including zero trust principles and secure design patterns.
- Own vulnerability and exposure management across application, cloud, and infrastructure layers - risk-based prioritization, engineering ownership models, and remediation SLAs.
- Oversee application security testing - SAST, DAST, SCA - and the offensive security program including pen testing and red team engagements.
- Own cloud security posture across the estate - CSPM, container and Kubernetes security, IaC review.
- Own threat detection and telemetry fidelity end-to-end - high-fidelity signals into SIEM, log source coverage across endpoint, SaaS, cloud, and network.
- Own incident management - ensure the incident response plan is defined, tested, and executable, with clear escalation paths and playbooks.
- Drive detection engineering - use case development, correlation rules, alert tuning, and measurable noise reduction.
- Manage the MSSP relationship - enforce SLAs, drive false-positive reduction, and define L1 alert handling procedures.
- Deliver the 24/7 coverage model - on-call structure, follow-the-sun planning, SOAR automation of Tier 1 triage.
- Consolidate the security stack - one signal, one view, less noise. Drive down cost and eliminate coverage gaps.
- Own the security tooling lifecycle - evaluation, vendor management, implementation, and adoption to production maturity across both functions.
- Communicate at the executive level - concise, compelling, business-risk framing. Influence decision-making at senior level.
- Lead collaborative initiatives across the organization.
- Navigate complex stakeholder relationships to drive decisions and outcomes.
- Champion security culture across engineering and the wider business.
- Inspire others to care about security.
- Coach and mentor the team.
- Drive a culture of learning, quality, and accountability.
- Anticipate emerging risks, including AI-related risk, and shape security strategy accordingly.
- 10+ years in cybersecurity with significant depth in both product/application security and security operations (required).
- Proven leadership of security engineering or SOC teams - including distributed, multi-region teams (required).
- Expert-level knowledge of secure SDL frameworks (OWASP SAMM, NIST SSDF), threat modelling, and security architecture (required).
- Deep experience with detection engineering, SIEM/XDR platforms, incident response, and MSSP management (required).
- Strong cloud security expertise - AWS required; container and Kubernetes security experience (required).
- Track record of translating technical risk into business impact for executive audiences (required).
- Experience building or maturing vulnerability management programs with engineering ownership models (required).
- Experience in tech and regulated environments - betting, gaming, or sports data (preferred).
- Experience integrating acquired companies into an existing security program (preferred).
- Security certifications - CISSP, OSCP, GIAC, or equivalent (preferred).
- Experience with SOAR implementation and security automation at scale (preferred).
- Experience operating follow-the-sun or 24/7 security coverage models (preferred).
- Competitive salary.
- Range of benefits.
- Support for employee wellbeing.
- Opportunities to grow skills, experience, and career.
Genius Sports is a sports data and technology company that supplies official data, streaming, integrity and advertising services to sports leagues, sportsbooks and media companies. Founded in 2001 and headquartered in London, with a major office in New York and others worldwide, it is the official data partner of organisations including the NFL, English Premier League and FIBA. The company provides the technology that connects sports, betting and media businesses. Genius Sports is listed on the New York Stock Exchange.
