waypointjobs

TKO Group Holdings, Inc.

VP, Cybersecurity Operations and Engineering

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Who We Are:

TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company. TKO owns iconic properties including UFC, the world’s premier mixed martial arts organization; WWE, the global leader in sports entertainment; and PBR, the world’s premier bull riding organization. Together, these properties reach 1 billion households across 210 countries and territories and organize more than 500 live events year-round, attracting more than three million fans. TKO also services and partners with major sports rights holders through IMG, an industry-leading global sports marketing agency; and On Location, a global leader in premium experiential hospitality.Position Overview

The VP, Cybersecurity Operations & Engineering is responsible for leading and maturing the enterprise cybersecurity Operations and Engineering programs with oversight on Cybersecurity program execution, and risk management, while leading cybersecurity operations and engineering capabilities. This leader partners across Cybersecurity, technology, legal, compliance, privacy, and business units to align and articulate strategy, operationalize policy, strengthen controls, improve resilience, and provide measurable security outcomes across a complex global environment.

The ideal candidate brings a strong blend of executive leadership, program & project management discipline, technical depth, and business partnership. They are equally effective shaping long-range roadmaps, communicating across all levels of an enterprise, driving control maturity, and ensuring day-to-day operational readiness across detection, response, vulnerability management, security engineering, risk management, and threat-informed defense.

Key Responsibilities

Cybersecurity Program Leadership and Governance

Lead the enterprise cybersecurity operations & engineering programs, including documenting strategy, risk governance, organization roadmap development, budgeting, KPI reporting, and preparing executive communications.

Contribute to cybersecurity policies, standards, procedures, and control frameworks aligned to business objectives and risk appetite.

Develop and maintain governance forums, steering committee materials, risk updates, and decision-supporting business cases for senior leadership.

Partner with legal, compliance, privacy, internal audit, and technology stakeholders to strengthen the company’s overall security, regulatory, and governance posture.

Drive consistent security practices across corporate, cloud, application, and business environments, ensuring alignment with enterprise architecture and operating models.

Translate threat, control, and assessment findings into practical, risk-informed recommendations and prioritized remediation plans.

Operations Oversight and Resilience

Provide executive oversight for security operations, including SOC and/or MSSP performance, alert monitoring, incident triage, escalation management, and operational readiness.

Own and mature incident response planning, operational runbooks, tabletop exercises, and cross-functional response coordination with technology, legal, HR, and compliance teams.

Oversee threat intelligence, threat detection, threat hunting, and vulnerability management capabilities to improve visibility, response speed, and control effectiveness.

Ensure the organization is prepared to protect, detect, respond to, and recover from cybersecurity events affecting critical systems, intellectual property, data, and brand reputation.

Develop and monitor operational metrics and service-level indicators for security operations, incident management, remediation progress, and program effectiveness.

Security Engineering and Control Maturity

Oversee the design, implementation, enhancement, and lifecycle management of cybersecurity technologies and control capabilities across on-premises, cloud, endpoint, identity, and network domains.

Partner closely with infrastructure, platform, and software engineering teams to embed security into enterprise architecture, system design, and operational workflows.

Support secure development lifecycle practices, software assurance, secure coding, and application security initiatives across internal and customer-facing environments.

Guide the selection and optimization of security tools and services, including SIEM, EDR, IDS/IPS, firewalls, vulnerability management, logging, monitoring, and related protection technologies.

Promote automation, orchestration, and process simplification to improve scalability, consistency, and efficiency across cybersecurity operations and engineering.

Risk, Compliance, and Business Partnership

Lead cyber risk assessments across infrastructure, applications, vendors, business processes, and emerging technology initiatives.

Support compliance and control maturity efforts related to frameworks and obligations such as NIST, ISO 27001, PCI-DSS, SOC, SOX, GDPR, privacy, and other applicable requirements.

Provide security leadership for vendor and third-party reviews, architectural reviews, major initiatives, and transformation programs.

Build trusted relationships with business and technology leaders to ensure security enables growth, resilience, and informed risk-taking.

Champion security awareness, education, and culture-building efforts that improve employee behavior and strengthen organizational readiness.

Team Leadership

Lead, coach, and develop high-performing cybersecurity managers and individual contributors across program, operations, and engineering functions.

Foster a culture of accountability, collaboration, continuous improvement, and service-oriented partnership.

Mentor technical teams on incident response, operational excellence, architectural decision-making, and effective communication with executive and non-technical audiences.

Qualifications

Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.

12+ years of progressive cybersecurity experience, including leadership of enterprise security programs in complex, high-growth, or globally distributed organizations.

7+ years of leadership experience managing managers, cross-functional teams, and/or external service providers across multiple cybersecurity domains.

Demonstrated success building or maturing cybersecurity governance, program management, security operations, and security engineering capabilities.

Strong working knowledge of cybersecurity frameworks, regulatory requirements, and assurance practices, including NIST CSF, ISO 27001, PCI-DSS, SOC, SOX, data privacy, and related standards.

Experience leading or overseeing incident response, threat intelligence, vulnerability management, detection engineering, and security monitoring programs.

Strong technical understanding of cloud security, identity and access management, endpoint protection, network security, logging and monitoring, system hardening, and enterprise security architecture.

Experience working closely with software development and infrastructure teams to integrate security into lifecycle management, architecture, and operational processes.

Proven ability to define metrics, communicate risk clearly, and present meaningful security insights to operational, technical, and executive stakeholders.

Strong business judgment and the ability to balance risk reduction, operational efficiency, and strategic enablement.

Excellent written and verbal communication skills, with the ability to influence across all levels of the organization.

Preferred Qualifications

Master’s degree in a relevant discipline.

CISSP or comparable industry certification.

Experience in media, entertainment, sports, or other fast-paced global operating environments.

Experience overseeing a hybrid model that includes internal teams and managed security partners.

Experience building metric-driven security programs and using automation to streamline cyber workflows

.

What Success Looks Like

A clearly governed cybersecurity program with measurable outcomes, executive visibility, and aligned priorities.

Strong project portfolio management including active projects, roadmaps, greenlighting materials, and overall strategy documents.

Maintains Cyber Risk Register and Risk governance process

Supports procurement calendar, budget, and actuals for current and future year.

Mature operational readiness across monitoring, response, vulnerability remediation, and threat-informed defense.

Supports engaging C-Suite and IT Leadership content, meeting materials, and agendas.

Strong partnership across technology and business teams, resulting in better security-by-design and faster risk reduction.

Scalable engineering and program capabilities that improve resilience while enabling the business.

Per local requirements and in the interest of transparency, the hourly rate shown below reflects the prevalent current hiring range for this position. Hiring pay rates are based on a number of factors, including location and may vary depending on job-related qualifications, knowledge, skills and experience. The company strives to provide locally competitive rewards packages, which include base rate along with, as applicable, short- and long-term incentives, growth and developmental opportunities, and robust benefits, such as health care, retirement, vacation and other paid time off, and additional offerings.

Hiring Rate Minimum:

$225,000 annually(minimum will not fall below the applicable State/local minimum salary thresholds)Hiring Rate Maximum:

$300,000 annuallyTKO is an Equal Opportunity Employer and complies with all applicable federal, state, and local laws regarding non-discrimination in employment. TKO makes employment decisions based on merit and qualifications, without considering an employee’s or applicant’s race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, marital status, veteran status, or any other basis prohibited under federal, state or local laws governing non-discrimination in employment in every location in which the Company has facilities. TKO also provides reasonable accommodations for qualified individuals with disabilities in accordance with the Americans with Disabilities Act (ADA) and applicable state or local laws. For information about Privacy and Information Security for TKO employment candidates, please review our Privacy Policy. For information regarding Terms of Use for this and other TKO websites, please review our Terms of Use.

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

Red Wine and Blue

Himalayas

General Interest Application

Remote — United States (see country and timezone requirements)

Salary not specifiedfull timeRemote

WHO THE HECK ARE WE? Red Wine & Blue is a national community of over 600,000 diverse suburban women working together to defeat extremism, one fr…

Listing expires 2026-12-04View job

Carle Health

Himalayas

Finance Systems Analyst

Remote — United States (see country and timezone requirements)

$26.41 – $44.10 per hourfull timeRemote

OverviewThe Finance Systems Analyst assists with supporting assigned finance/accounting applications for the enterprise such as costing, producti…

Listing expires 2026-12-04View job

Kyowa Kirin

Himalayas

Scientific Relations Manager

Remote — Worldwide (see timezone requirements)

Salary not specifiedfull timeRemote

OverviewWE PUSH THE BOUNDARIES OF MEDICINE. LEAPING FORWARD TO MAKE PEOPLE SMILE At Kyowa Kirin International (KKI), our purpose is to make peop…

Listing expires 2026-12-04View job

Belden, Inc

Himalayas

Solution Consultant - Cybersecurity Practice (US)

Remote — United States (see country and timezone requirements)

$125,000.00 – $160,000.00 per yearfull timeRemote

Innovation Starts With YouPropel your career at Belden, where innovation creates possibilities—for our people, our customers, and the communities…

Listing expires 2026-12-04View job