Senior Director, Security Threat
Listed on 2026-07-20
-
IT/Tech
Cybersecurity, Security Management & Operations
Director Of Threat Management
The Director of Threat Management is responsible for leading the enterprise detection and response function, owning the reactive side of security: identifying, investigating, and containing threats across a global Fortune 500 environment. This role provides leadership for the Security Operations Center (SOC), Cyber Threat Intelligence (CTI), Detection Engineering, and Incident Response (IR), and is accountable for the speed and quality of threat detection, triage, investigation, and response across the enterprise.
The Director of Threat Management leads a 24x7 monitoring and response organization while advancing the detection engineering pipeline, maturing threat intelligence integration, and driving measurable improvement in mean time to detect and mean time to respond. The role combines strategic direction, operational accountability, and organizational leadership to reduce enterprise risk from active and emerging threats, partnering closely with the platform engineering team that owns the underlying security tooling.
What You Will Do:
Strategy, Governance, and Leadership
- Define and own the enterprise threat detection and response strategy, roadmap, and operating model aligned to cybersecurity, risk, and business objectives.
- Mature the threat management program through formal governance, playbooks, standards, metrics, and leadership reporting.
- Present detection and response posture, incident trends, risks, and investment needs to security leadership and executive stakeholders.
- Establish and monitor KPIs such as mean time to detect (MTTD), mean time to respond (MTTR), detection coverage, and alert quality.
- Lead prioritization decisions across the SOC, threat intelligence, detection engineering, and incident response functions.
Security Operations and Monitoring
- Lead a 24x7 Security Operations Center responsible for monitoring, alert triage, escalation, and initial investigation across the enterprise.
- Own the detection content lifecycle within the SIEM, and define data source onboarding, log storage, and retention requirements for the platform-owning team.
- Drive continuous improvement in alert quality, triage efficiency, and analyst workflow to reduce noise and analyst fatigue.
- Establish tiered operating models, shift coverage, and escalation paths that ensure consistent 24x7 response readiness.
- Oversee SOC performance metrics, service levels, and quality assurance across monitoring and triage activities.
Detection Engineering
- Lead the detection engineering function responsible for building, tuning, and maintaining detection content across SIEM and security telemetry sources.
- Drive a detection-as-code approach with version control, testing, peer review, and measurable detection coverage mapped to MITRE ATT&CK.
- Prioritize detection development against threat intelligence, red team findings, incident learnings, and emerging adversary techniques.
- Establish metrics for detection coverage, efficacy, and false-positive rates, and drive continuous tuning based on outcomes.
- Partner with engineering and platform teams to ensure high-quality, well-structured log and telemetry sources feed detection pipelines.
Cyber Threat Intelligence
- Lead the Cyber Threat Intelligence function responsible for strategic, operational, and tactical intelligence supporting detection and response.
- Operationalize threat intelligence by driving indicator enrichment, threat actor tracking, and intelligence-led detection and hunting priorities.
- Deliver executive and stakeholder threat briefings that translate the threat landscape into business-relevant risk and action.
- Establish threat hunting programs that proactively search for adversary activity across the environment ahead of alerting.
- Manage intelligence sources, sharing partnerships, and integration of intelligence into SIEM, SOAR, and detection workflows.
Incident Response
- Own the enterprise incident response process across detection, triage, containment, eradication, recovery, and post-incident review.
- Lead major incident coordination, serving as an escalation point and driving cross-functional response during significant events.
- Establish and maintain incident response playbooks, runbooks, and tabletop exercises to ensure organizational readiness.
- Drive post-incident reviews and lessons-learned processes that feed detection improvements and control gaps back into the program.
- Partner with legal, communications, IT, and business stakeholders to ensure coordinated response and regulatory notification where required.
Tooling and Automation Requirements
- Define detection and response requirements, use cases, and priorities for the SIEM, SOAR, and log storage platforms owned and operated by the platform engineering team.
- Partner with the platform-owning team to shape roadmap, data onboarding, retention, and automation priorities that serve detection and response needs.
- Specify SOAR automation use cases for triage, enrichment, and response, and validate that delivered automations meet analyst…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).