Cyber Security Defense; Head of Department
Listed on 2026-07-15
-
IT/Tech
Cybersecurity, IT Project Manager, Security Management & Operations, Information Security & Data Protection
Cyber Security Defense (Head of Department) — Direct-Hire/FTE — Irvine, CA
Compensation: $190,000 – $230,000 Annual Base Salary.
Work Requirements: US Citizen, GC Holder, or Authorized to Work in the U.S.
The Cyber Security Defense Head of Department (HOD) will lead and mature our organization’s end-to-end defensive security capabilities. This senior leadership role oversees the Security Operations Center (SOC), Blue Team, Red Team, Penetration Testing, Incident Response, Threat & Vulnerability Management (TVM), Application Security, and Adversary Simulation functions. The ideal candidate is both a visionary leader and a seasoned technical expert capable of building high‑performing teams, implementing modern security practices, and driving continuous improvement across all cyber defense operations.
StrategicLeadership & Governance
- Develop and execute the Cyber Defense strategy aligned with organizational goals, customer requirements and evolving threat landscapes.
- Establish frameworks, processes, and KPIs for SOC, Incident Response, TVM, App Sec, Red/Blue Teaming, and Adversary Simulation.
- Serve as a senior advisor to the CISO and executive leadership on cyber risks, readiness, and emerging threats.
- Oversee 24/7 SOC operations, ensuring effective monitoring, detection, and response to security events across levels 1-3.
- Drive continuous enhancement of detection engineering, threat hunting, and security analytics.
- Implement best‑in‑class security tooling, automation, and operational processes.
Red Team & Penetration Testing
- Lead internal Red Team and offensive security capabilities, including penetration testing.
- Define testing methodologies, operational rules of engagement, and reporting standards.
- Translate offensive findings into actionable improvements for defensive teams and architecture.
- Oversee the Incident Response program, ensuring rapid and effective handling of security incidents.
- Lead tabletop exercises, simulation drills, and readiness assessments.
- Facilitate and lead high/critical incident responses when the Incident Response Manager is unavailable; coordinate with legal, communications, and executive stakeholders during major incidents.
- Own the enterprise‑wide vulnerability management strategy, including prioritization, remediation, and reporting.
- Drive continuous scanning, assessment, and metrics to reduce risk across infrastructure, applications, and cloud environments.
- Collaborate with engineering and operations teams to ensure timely and effective remediation.
- Facilitate the zero‑day vulnerability response process when the Incident Response Manager is unavailable.
- Lead the organization’s App Sec program, including secure SDLC practices, code reviews, SAST/DAST tools, and developer enablement.
- Partner with software engineering to embed security into product and platform design.
- Develop and run adversary simulation programs that mimic real‑world threat actors.
- Use intelligence‑led scenarios to evaluate detection capabilities, response effectiveness, and organizational resilience.
- 15-20 years of progressive experience across cyber defense disciplines (SOC, Incident Response, Red/Blue teams, or similar). Proven experience leading cyber defense teams, hiring, mentoring, and building high‑performing technical teams.
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or a related discipline.
- Strong knowledge of threat detection, incident response, adversary tactics (MITRE ATT&CK), vulnerability management, and secure software development. Excellent incident management, communication, and executive reporting skills.
- Proficient in English.
- Availability to support critical incident response with a flexible schedule when needed.
- Master’s degree in Cybersecurity, Information Technology, Computer Science or a related discipline.
- Industry‑recognized credentials such as CISSP, CISM, OSCP/OSCE, GIAC (GSEC, GCIA, GCIH, GPEN, GXPN).
- Familiarity…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).