
Senior Director, Global Cyber Detection and Response
Posted Sep 22

Posted Sep 22
This is a fully remote position, open to applicants in Poland.
• Take ownership of Danaher's worldwide Incident Detection & Response program, encompassing strategy, roadmap, execution, and operational efficiency.
• Lead the design, implementation, and operation of the enterprise detection ecosystem, including SIEM, security data lake, UEBA, SOAR, EDR/XDR, and associated platforms.
• Manage the complete telemetry and detection engineering lifecycle, which includes log onboarding, parsing, normalization, data quality monitoring, MITRE ATT&CK-aligned use cases, validation, tuning, coverage measurement, and retirement.
• Construct, guide, and enhance a global 24x7 cyber defense organization across various regions and management tiers.
• Propel AI, agentic SOC workflows, automation, threat intelligence, threat hunting, alert triage, investigation, and response orchestration.
• Develop and oversee enterprise incident response and cyber crisis management procedures.
• Handle executive communications, legal and regulatory coordination, third-party incident response vendors, tabletop exercises, and audit support.
• Define and convey cyber defense performance metrics such as MTTD, MTTR, ATT&CK coverage, telemetry health, analyst efficiency, false-positive reduction, backlog management, and program effectiveness.
• Collaborate with OpCo CISOs, CIOs, plant leaders, product teams, executive leadership, and audit/risk committees.
• Report directly to the Chief Information Security Officer within the Global Information Security organization.
• A Bachelor's degree in Computer Science, Information Security, Engineering, or a related field (or equivalent professional experience).
• Over 12 years of experience in information security.
• Direct responsibility for security operations, detection engineering, and/or incident response in a global organization.
• Experience in establishing, migrating, or modernizing enterprise-scale SIEM environments.
• Proficiency with data pipelines, telemetry ingestion, parsing, normalization, and ownership of detection content.
• Extensive expertise throughout the entire detection engineering lifecycle.
• Familiarity with MITRE ATT&CK-aligned detection development and the creation of correlation/analytic rules.
• Experience with detection-as-code and CI/CD for detections.
• Proven leadership in a 24x7 Security Operations Center and incident response function.
• Experience managing major incident command, executive communications, investigations, and coordination with legal, privacy, compliance, and regulatory stakeholders.
• Practical experience with SOAR, security automation, EDR/XDR, AWS, Azure, GCP, identity threat detection, Cribl, Kafka, and streaming ETL.
• Ability to lead large-scale information security organizations through various management levels.
• Experience directing globally distributed teams across multiple regions, sites, and business environments.
• Experience in complex, multi-country enterprises operating in over 50 countries.
• Willingness to travel up to 20–30% of the time, including for international travel.
• Professional certifications such as CISSP, CISM, GCIA, GCIH, GCFA, or GNFA are advantageous.
• A culture dedicated to continuous improvement.
• Opportunities for career development and internal hiring.
• An inclusive culture of belonging.
• Options for remote work.
• Opportunities for global travel.
Kyndryl
Volunteers of America Chesapeake & Carolinas
Censys
Liberty Dental Plan
Get handpicked remote jobs straight to your inbox weekly.