Exec Director, Cyber Defense Operations
Listed on 2026-06-19
-
IT/Tech
Cybersecurity
Job Summary
The Executive Director of Defense Operations, within the Cyber Defense organization, is responsible for defining and executing a multi‑year, enterprise‑wide strategy for the Security Operations Center and the Computer Security Incident Response Team functions. This role provides executive leadership for a 24×7 security operations capability, ensuring rapid identification, containment, and remediation of cyber threats while continuously advancing the maturity, scalability, and effectiveness of detection and response programs.
Responsibilities- Define, develop, maintain and execute the enterprise‑wide detection and response program aligned with Cyber Defense, business objectives, and regulatory requirements.
- Own and maintain the enterprise Detection and Response Maturity Model, Strategy, Roadmap, and Operating Model.
- Lead and mentor a team of triage, detection engineers, threat hunters, and incident response professionals, fostering a culture of continuous improvement and operational excellence.
- Strategize with senior leaders across Product, Engineering, and Security to advocate for necessary telemetry and architectural changes.
- Serve as Incident Commander for major security incidents, coordinating technical teams and executive leadership.
- Develop innovative detection content aligned with ATT&CK, ATLAS, D3
FEND, and other cybersecurity frameworks. - Identify and surface root‑cause patterns to leadership, anticipating future challenges and delivering proactive solutions.
- Track OKRs aligned to maturity models, define, monitor, and report on KPIs and KRIs to demonstrate operational and strategic improvements.
- Partner with threat intelligence and other security teams to enhance detection and response capabilities.
- Act as liaison with legal, compliance, and public relations during high‑impact incidents.
- Provide executive‑level briefings and actionable insights to senior leadership.
- Drive automation and orchestration initiatives to improve operational efficiency.
- Monitor emerging threats, adapt operations, tactics, and strategies accordingly.
- Lead tabletop exercises and simulations to validate readiness.
- 15+ years of experience in cybersecurity with 8+ years in a leadership role managing global detection and response, threat hunting, or security operations teams.
- Experience developing and executing a long‑term strategic vision for security operations at an enterprise scale.
- Experience leveraging automation and orchestration (e.g., SOAR) to improve the efficiency and effectiveness of a SOC.
- Experience applying AI/ML to security data for anomaly detection, threat modeling, and predictive security.
- Experience managing a globally distributed 24/7 security operations team.
- Experience defining and driving a multiyear strategy for threat detection and response.
- Strong understanding of security frameworks, risk management, and incident response.
- Deep understanding of people, process, and technologies in a successful cybersecurity program.
- Strong leadership, people management, project management, and time‑management skills.
- Proficient in analyzing operational data and creating visualizations and reports.
- Excellent verbal, written, and presentation communication skills.
- Bachelor's degree required or equivalent specialized training in SOC/CSIRT or a structured methodology; technical certifications in advanced security incident and remediation management are considered an advantage.
Base salary: $ – $ (annual). The actual offer depends on experience, education, geography, and other factors. The role is eligible for bonus, commission, short‑term incentive, and company equity award programs.
BenefitsComprehensive benefits package including medical, dental, vision coverage, paid time off, retirement savings options, wellness programs, and other resources—subject to eligibility.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws.
Application window closes on 08/29/2026.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).