×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Global Director of Autonomous Cyber Defense and Security Event Triage; SOC

Job in Tempe, Maricopa County, Arizona, 85285, USA
Listing for: MUFG Bank, Ltd.
Full Time position
Listed on 2026-07-24
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 180000 - 280000 USD Yearly USD 180000.00 280000.00 YEAR
Job Description & How to Apply Below
Position: Global Director of Autonomous Cyber Defense and Security Event Triage (SOC)

Role Overview

The Global Director of Autonomous Cyber Defense and Security Event Triage leads the strategy, execution, and continuous improvement of a 24/7 global cyber defense and security event triage function. The role is accountable for protecting enterprise assets and services by driving outcomes across detection engineering, automated response, incident triage, and threat hunting. The director oversees global cyber operations performance, operating rhythms, and service delivery across multiple environments and partners while owning budget planning and financial stewardship for the function.

Additionally, the role advances autonomous defense capabilities by applying AI/ML and LLM‑enabled workflows to improve alert quality, reduce time to detect/respond, and standardize documentation and remediation at scale.

The selected colleague will work at an MUFG office or client site four days per week and have one remote day.

Major Responsibilities
  • Direct and mature a 24/7 global cyber operations model for security event monitoring, triage, incident response partnership, and threat hunting across multiple environments.
  • Own functional strategy, multi‑year roadmap, and KPI/OKR outcomes for autonomous cyber defense and security event triage (e.g., MTTD/MTTR, false‑positive reduction, containment SLAs).
  • Work with the Global Head to define the vision for Autonomous Cyber Defense and Security Event Triage and execute against that vision in alignment with the strategic design.
  • Oversee budget planning, vendor management, and financial governance for global cyber operations tooling, services, and staffing; optimize spend to risk reduction and service performance.
  • Lead, mentor, and scale high‑performing global teams (employees and partners); define operating rhythms, coverage models, escalation paths, and on‑call expectations.
  • Serve as a lead escalation contact in a 24/7 environment; guide appropriate resources to resolution.
  • Provide executive‑level oversight for audit, risk, and regulatory engagements related to cyber operations; ensure processes, evidence, and metrics meet policy and compliance requirements.
  • Deliver leadership reporting on cyber operations health, emerging threats, and risk posture; translate technical findings into business impact and prioritized actions.
  • Drive AI/ML/LLM‑enabled autonomous defense initiatives, including alert enrichment, case summarization, analyst co‑pilots, automated containment, and continuous learning to improve signal‑to‑noise.
  • Establish governance for detection engineering, triage decisioning, playbooks, and automation (SOAR/EDR/SIEM) to standardize response, reduce gaps, and improve response times.
  • Lead critical incident triage and escalation governance; partner with incident response, infrastructure, identity, and application teams to coordinate containment and recovery.
  • Oversee monitoring of third‑party security service providers and managed tooling to ensure coverage, quality, and alignment to enterprise standards and SLAs.
  • Build an operations analytics program to measure and continuously improve triage accuracy, response efficiency, backlog health, and automation effectiveness across regions and shifts.
  • Sponsor and execute a purple team program (red/blue collaboration) to validate detections and response through adversary emulation aligned to MITRE ATT&CK; track gaps to closure.
  • Oversee proactive threat hunting and continuous control validation to identify adversary behaviors, reduce dwell time, and harden critical services.
  • Provide global operational leadership during cyber events by coordinating communications, handoffs, and technical execution across regions, functions, and time zones.
  • Integrate threat intelligence, vulnerability insights, and attacker TTP research into detection logic, triage guidance, and autonomous response workflows.
  • Produce and govern recurring and ad‑hoc reporting on threats, trends, and program performance; ensure consistent narratives and decision support for stakeholders.
  • Champion innovation and modernization of cyber defense tooling and techniques, including evaluation and adoption of new capabilities that measurably reduce risk.
  • Partner with…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary