×
Register Here to Apply for Jobs or Post Jobs. X

Cyber Threat Detection & Response Team Lead

Job in San Francisco, San Francisco County, California, 94102, USA
Listing for: Control Risks
Full Time position
Listed on 2026-06-27
Job specializations:
  • IT/Tech
    Cybersecurity, IT Project Manager
Job Description & How to Apply Below

Cyber Detection And Response Team Lead

The Cyber Detection and Response Team Lead will play a pivotal role in building and leading a world-class Detection and Response Team (DART) for a major client of Control Risks. This is a hands-on technical leadership role responsible for standing up the team from the ground up; developing strategy, building capabilities, and leading a team of security professionals to proactively detect, investigate, and respond to cyber threats across the client's environment.

This position works in close partnership with the client's Security Engineering team to ensure detection and response capabilities are deeply integrated into the broader security architecture. The Team Lead provides technical direction and operational oversight on all detection and response matters, ensuring the protection of the client's systems, networks, data, and cloud environments. The role supports a strong first-line ownership model by partnering with technology and business stakeholders to embed security into planning, development, and operational activities.

  • Working closely with client stakeholders and the Security Engineering team, build, manage, and scale a Cyber Detection and Response Team (DART) from the ground up.
  • Define and implement the DART's operational model, including tiered escalation paths, on-call rotations, and coordination protocols with Security Engineering, IT, Legal, Risk, and other business stakeholders.
  • Lead the development of Standard Operating Procedures (SOPs) for detection and response activities, including tooling integration, reporting lines, and out-of-hours incident protocols.
  • Establish and continuously refine incident response playbooks aligned to the MITRE ATT&CK framework and the client's specific threat landscape.
  • Serve as Incident Commander for critical and high-severity cyber security incidents, directing technical response across forensics, network, endpoint, cloud, and identity work streams.
  • Lead on managing the most severe cyber security incidents, including supporting responders with reporting, executive updates, root cause analysis, and remediation recommendations.
  • Oversee the triage of cyber events, ensuring rapid identification, investigation, containment, and remediation.
  • Lead proactive threat hunting operations to identify potential compromises, undetected adversary activity, and gaps in detection coverage.
  • Integrate threat intelligence into DART workflows and leverage intelligence to inform response and prevention strategies.
  • Team Lead Support
  • Conduct regular check-ins, provide coaching and feedback, manage performance reviews and improvement plans, and support career development with the members of your team.
  • Serve as the main liaison between team members and the ECS program management team, ensuring timely program and personnel updates and controlling quality on client deliverables.
  • With the support of the Talent Acquisition team, participate in hiring processes ensuring team resourcing aligns with client expectations and program needs.
  • Lead onboarding tasks (e.g., joiner tickets, scheduling, equipment, success plans), manage offboarding logistics and leaver tickets, and ensure operational continuity.
  • Manage team schedules, approve PTO, ensure timesheet compliance, and maintain a consistent high-quality service to the client.
  • Working closely with the ECS program management team, align on overall program strategy and priorities to create clear, actionable team deliverables.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary