Senior Director - Cyber Defense Engineering
Listed on 2026-06-02
-
IT/Tech
Cybersecurity, Systems Engineer
Summary
The Senior Director of Cyber Defense Architecture & Engineering leads the strategy, design, engineering and continuous improvement of enterprise detection, response and threat mitigation capabilities across the enterprise. This role is accountable for building or integrating resilient, intelligence-driven, automated cyber defense platforms spanning endpoint, network, cloud, identity, data and SaaS environments. Responsibilities include building strong partnerships with technology teams, other corporate support functions and information security organizations to protect the corporate brand, data and assets;
designing, implementing, operating and maintaining an information security framework, processes and systems that protect the business, services, information and systems against unauthorized use, disclosure, modification, damage and loss.
- Define and execute the enterprise cyber defense architecture strategy aligned with the threat landscape and risk appetite in collaboration with Cyber Defense senior leadership.
- Develop layered defense models across endpoint, network, cloud, identity and SaaS.
- Establish and document detection engineering standards and reference architectures.
- Present defense posture maturity, risk trends and roadmap to executive leadership.
- Establish the enterprise detection engineering program and lead evaluation of new tools and technologies to support the Cyber Defense ecosystem.
- Define logging standards and telemetry requirements across platforms.
- Collaborate and partner with key stakeholders to oversee use case lifecycle management (creation, tuning, retirement).
- Standardize MITRE ATT&CK mapping across detections.
- Reduce false positives while increasing true positive detection rates in collaboration with Cyber Defense teams.
Oversee or drive a collaborative approach to architecture and engineering of:
- SIEM platforms
- SOAR playbooks
- EDR/XDR solutions
- NDR solutions
- Email security and anti‑phishing platforms
- Deception technologies
- Threat intelligence platforms
- Security data lakes and analytics platforms
Integrate defense controls across:
- Public cloud environments (AWS, Azure, GCP)
- Hybrid data centers
- SaaS platforms
- Enterprise networks, endpoints and mobile
- OT/IoT (in partnership with OT senior cybersecurity leadership)
- Drive automation, AI/ML integration and policy‑as‑code for response workflows in collaboration with Cloud Security and other senior security leaders.
- Enable automated containment and remediation capabilities.
- Partner with Incident Response and Cyber Counter Adversary leadership for operational efficiency and maturity uplifts.
- Support purple team exercises to validate detection and response effectiveness.
- Integrate strategic, tactical and operational threat intelligence into engineering roadmap.
- Translate threat actor activity into detection content and control enhancements.
- Support M&A security integrations and divestiture disentanglement.
- Ensure compliance with global regulatory regimes (e.g., HIPAA, GDPR, SOX, FDA/GxP where applicable).
- Establish KPIs, OKRs and performance dashboards.
- Establish control validation framework.
- Lead breach simulation and continuous control monitoring as needed to support Cyber Defense senior leaders.
- Report measurable defense maturity to executive leadership and other senior leaders.
- Lead global team of detection engineers, platform engineers and automation specialists.
- Establish engineering career paths and succession planning.
- Enterprise financial management and planning experience.
- Follow information security trends within and outside of work to strategize and recommend changes and updates to the company.
Education
- Master's Degree in Business Administration, Computer Science, Information Technology or any other related discipline or equivalent related experience.
Preferred Certifications
- Certified Cloud Security Professional (CCSP)
- Certified Information Systems Security Professional (CISSP)
- Offensive Security Certified Professional (OSCP)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Certified Enterprise Defender (GCED)
- GIAC Certified Incident Handler (GCIH)
- Certification in Information Security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).