VP, Cybersecurity Operations and Engineering
Who We Are:


TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company. TKO owns iconic properties including UFC, the world’s premier mixed martial arts organization; WWE, the global leader in sports entertainment; and PBR, the world’s premier bull riding organization. Together, these properties reach 1 billion households across 210 countries and territories and organize more than 500 live events year-round, attracting more than three million fans. TKO also services and partners with major sports rights holders through IMG, an industry-leading global sports marketing agency; and On Location, a global leader in premium experiential hospitality.

Position Overview
The VP, Cybersecurity Operations & Engineering is responsible for leading and maturing the enterprise cybersecurity Operations and Engineering programs with oversight on Cybersecurity program execution, and risk management, while leading cybersecurity operations and engineering capabilities. This leader partners across Cybersecurity, technology, legal, compliance, privacy, and business units to align and articulate strategy, operationalize policy, strengthen controls, improve resilience, and provide measurable security outcomes across a complex global environment.
The ideal candidate brings a strong blend of executive leadership, program & project management discipline, technical depth, and business partnership. They are equally effective shaping long-range roadmaps, communicating across all levels of an enterprise, driving control maturity, and ensuring day-to-day operational readiness across detection, response, vulnerability management, security engineering, risk management, and threat-informed defense.
Key Responsibilities
Cybersecurity Program Leadership and Governance
-
Lead the enterprise cybersecurity operations & engineering programs, including documenting strategy, risk governance, organization roadmap development, budgeting, KPI reporting, and preparing executive communications.
-
Contribute to cybersecurity policies, standards, procedures, and control frameworks aligned to business objectives and risk appetite.
-
Develop and maintain governance forums, steering committee materials, risk updates, and decision-supporting business cases for senior leadership.
-
Partner with legal, compliance, privacy, internal audit, and technology stakeholders to strengthen the company’s overall security, regulatory, and governance posture.
-
Drive consistent security practices across corporate, cloud, application, and business environments, ensuring alignment with enterprise architecture and operating models.
-
Translate threat, control, and assessment findings into practical, risk-informed recommendations and prioritized remediation plans.
Operations Oversight and Resilience
-
Provide executive oversight for security operations, including SOC and/or MSSP performance, alert monitoring, incident triage, escalation management, and operational readiness.
-
Own and mature incident response planning, operational runbooks, tabletop exercises, and cross-functional response coordination with technology, legal, HR, and compliance teams.
-
Oversee threat intelligence, threat detection, threat hunting, and vulnerability management capabilities to improve visibility, response speed, and control effectiveness.
-
Ensure the organization is prepared to protect, detect, respond to, and recover from cybersecurity events affecting critical systems, intellectual property, data, and brand reputation.
-
Develop and monitor operational metrics and service-level indicators for security operations, incident management, remediation progress, and program effectiveness.
Security Engineering and Control Maturity
-
Oversee the design, implementation, enhancement, and lifecycle management of cybersecurity technologies and control capabilities across on-premises, cloud, endpoint, identity, and network domains.
-
Partner closely with infrastructure, platform, and software engineering teams to embed security into enterprise architecture, system design, and operational workflows.
-
Support secure development lifecycle practices, software assurance, secure coding, and application security initiatives across internal and customer-facing environments.
-
Guide the selection and optimization of security tools and services, including SIEM, EDR, IDS/IPS, firewalls, vulnerability management, logging, monitoring, and related protection technologies.
-
Promote automation, orchestration, and process simplification to improve scalability, consistency, and efficiency across cybersecurity operations and engineering.
Risk, Compliance, and Business Partnership
-
Lead cyber risk assessments across infrastructure, applications, vendors, business processes, and emerging technology initiatives.
-
Support compliance and control maturity efforts related to frameworks and obligations such as NIST, ISO 27001, PCI-DSS, SOC, SOX, GDPR, privacy, and other applicable requirements.
-
Provide security leadership for vendor and third-party reviews, architectural reviews, major initiatives, and transformation programs.
-
Build trusted relationships with business and technology leaders to ensure security enables growth, resilience, and informed risk-taking.
-
Champion security awareness, education, and culture-building efforts that improve employee behavior and strengthen organizational readiness.
Team Leadership
-
Lead, coach, and develop high-performing cybersecurity managers and individual contributors across program, operations, and engineering functions.
-
Foster a culture of accountability, collaboration, continuous improvement, and service-oriented partnership.
-
Mentor technical teams on incident response, operational excellence, architectural decision-making, and effective communication with executive and non-technical audiences.
Qualifications
-
Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.
-
12+ years of progressive cybersecurity experience, including leadership of enterprise security programs in complex, high-growth, or globally distributed organizations.
-
7+ years of leadership experience managing managers, cross-functional teams, and/or external service providers across multiple cybersecurity domains.
-
Demonstrated success building or maturing cybersecurity governance, program management, security operations, and security engineering capabilities.
-
Strong working knowledge of cybersecurity frameworks, regulatory requirements, and assurance practices, including NIST CSF, ISO 27001, PCI-DSS, SOC, SOX, data privacy, and related standards.
-
Experience leading or overseeing incident response, threat intelligence, vulnerability management, detection engineering, and security monitoring programs.
-
Strong technical understanding of cloud security, identity and access management, endpoint protection, network security, logging and monitoring, system hardening, and enterprise security architecture.
-
Experience working closely with software development and infrastructure teams to integrate security into lifecycle management, architecture, and operational processes.
-
Proven ability to define metrics, communicate risk clearly, and present meaningful security insights to operational, technical, and executive stakeholders.
-
Strong business judgment and the ability to balance risk reduction, operational efficiency, and strategic enablement.
-
Excellent written and verbal communication skills, with the ability to influence across all levels of the organization.
Preferred Qualifications
-
Master’s degree in a relevant discipline.
-
CISSP or comparable industry certification.
-
Experience in media, entertainment, sports, or other fast-paced global operating environments.
-
Experience overseeing a hybrid model that includes internal teams and managed security partners.
-
Experience building metric-driven security programs and using automation to streamline cyber workflows
.
What Success Looks Like
-
A clearly governed cybersecurity program with measurable outcomes, executive visibility, and aligned priorities.
-
Strong project portfolio management including active projects, roadmaps, greenlighting materials, and overall strategy documents.
-
Maintains Cyber Risk Register and Risk governance process
-
Supports procurement calendar, budget, and actuals for current and future year.
-
Mature operational readiness across monitoring, response, vulnerability remediation, and threat-informed defense.
-
Supports engaging C-Suite and IT Leadership content, meeting materials, and agendas.
-
Strong partnership across technology and business teams, resulting in better security-by-design and faster risk reduction.
-
Scalable engineering and program capabilities that improve resilience while enabling the business.
Per local requirements and in the interest of transparency, the hourly rate shown below reflects the prevalent current hiring range for this position. Hiring pay rates are based on a number of factors, including location and may vary depending on job-related qualifications, knowledge, skills and experience. The company strives to provide locally competitive rewards packages, which include base rate along with, as applicable, short- and long-term incentives, growth and developmental opportunities, and robust benefits, such as health care, retirement, vacation and other paid time off, and additional offerings.

Hiring Rate Minimum:
$225,000 annually(minimum will not fall below the applicable State/local minimum salary thresholds)
Hiring Rate Maximum:
$300,000 annually

TKO is an Equal Opportunity Employer and complies with all applicable federal, state, and local laws regarding non-discrimination in employment. TKO makes employment decisions based on merit and qualifications, without considering an employee’s or applicant’s race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, marital status, veteran status, or any other basis prohibited under federal, state or local laws governing non-discrimination in employment in every location in which the Company has facilities. TKO also provides reasonable accommodations for qualified individuals with disabilities in accordance with the Americans with Disabilities Act (ADA) and applicable state or local laws. For information about Privacy and Information Security for TKO employment candidates, please review our Privacy Policy. For information regarding Terms of Use for this and other TKO websites, please review our Terms of Use.
Required Skills
Required Languages
🇬🇧 English