
Director, Cyber Defense
Posted Aug 25

Posted Aug 25
This is a fully remote position, open to applicants in United Kingdom.
• Oversee 24/7 global security operations utilizing a follow-the-sun approach across AMER, EMEA, and APAC.
• Manage the complete incident response lifecycle, from initial triage to post-incident evaluation.
• Ensure forensic preservation standards are upheld throughout the incident response process.
• Collaborate with the Incident Commander function, employing escalation authorities, runbooks, and cross-functional protocols.
• Lead the Cyber Threat Intelligence program.
• Transform adversary intelligence into detection requirements, guide control coverage decisions, and implement changes to defensive architecture.
• Govern ATT&CK-aligned detection coverage based on assessed effectiveness.
• Establish ongoing validation through adversary emulation and detection testing.
• Implement detection-as-code principles, including version-controlled content, rigorous release processes, automated testing, and high telemetry quality standards.
• Propel operational metrics to shorten the detect-decide-act cycle in response to AI-accelerated threats.
• Work closely with Vulnerability Management to prioritize remediation and sequence actions informed by exploitability.
• Partner with the AI-Driven Cyber Defense team to embed automation and machine learning into defensive operations.
• Build and nurture a globally diverse team with expertise in technical, analytical, and leadership areas.
• Report directly to the Vice President and Deputy CISO of Cyber Operations.
• A minimum of 12 years of experience in cybersecurity operations, incident response, threat intelligence, or SOC leadership.
• At least 5 years of experience in a senior leadership position managing a globally distributed team.
• Demonstrated capability to lead security operations and incident response at an enterprise level.
• Strong understanding of threat-informed defense, MITRE ATT&CK framework, and kill chain analysis.
• Proficient in detection engineering, detection-as-code methodologies, content lifecycle management, and validation practices.
• Solid grasp of incident response methodologies and escalation protocols.
• Experience managing geographically distributed teams effectively.
• Excellent communication skills with both technical teams and executive leadership.
• Proven track record in leading a cyber defense or security operations program at a similar scale and complexity.
• Background in defending a hybrid or multi-cloud enterprise environment.
• Experience in operationalizing threat intelligence to enhance detection coverage and defensive architecture.
• Familiarity with continuous validation practices.
• Commitment to ongoing learning through self-directed study, certifications, military training, and formal education.
• Flexible and supportive work environment.
• Emphasis on well-being.
• Be Well programs that support financial, mental, physical, and social health.
• Tailored development goals and continuous feedback.
• Opportunities for cutting-edge learning.
• Certifications available with Microsoft, Google, and Amazon.
• Access to coaching and hands-on experiences.
• A flexible, hybrid-friendly culture.
Alzheimer's Association®
The College Board
The College Board
Cargill
Get handpicked remote jobs straight to your inbox weekly.