6 дней назад
Senior Director, Global Cyber Detection & Response (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Director, Global Cyber Detection & Response (Cybersecurity): Building and operating a global threat detection and incident response capability across cloud, on-premises, endpoint, identity, OT/ICS, and product environments with an accent on enterprise SIEM architecture, detection engineering, and 24x7 SOC operations. Focus on modernizing telemetry and detection platforms, applying AI and automation to cyber defense workflows, and leading incident response across a complex multi-country enterprise.
Location: Remote from Israel; Kraków, Poland, onsite or remote. Regular international travel to operating company, R&D, SOC, and manufacturing locations is required, up to 20–30% of the time. The Global Information Security organization is located in Washington, D.C.
Company
is a global science and technology company operating across life sciences, diagnostics, and biotechnology through more than 15 businesses and 60,000+ associates.
What you will do
- Own the global incident detection and response strategy, roadmap, execution, and operational effectiveness across cloud, endpoint, identity, network, OT/ICS, and product environments.
- Lead the architecture, implementation, and operation of the enterprise SIEM, security data lake, UEBA, SOAR, EDR/XDR, and related detection platforms.
- Manage the complete telemetry and detection engineering lifecycle, including log onboarding, parsing, normalization, MITRE ATT&CK-aligned use cases, validation, tuning, and coverage measurement.
- Build and mature a global 24x7 cyber defense organization with SOC analysts, detection engineers, incident responders, threat hunters, and automation engineers.
- Drive AI, agentic SOC workflows, threat hunting, automated enrichment, alert triage, investigation, and response orchestration.
- Govern incident response and cyber crisis management while communicating performance metrics to operating company leaders, executives, audit committees, and risk stakeholders.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field, or equivalent professional experience, plus 12+ years of information security experience.
- Direct ownership of security operations, detection engineering, and/or incident response in a global organization.
- Experience standing up, migrating, or modernizing enterprise-scale SIEM environments, including telemetry ingestion, data pipelines, parsing, normalization, and detection content ownership.
- Deep expertise in detection engineering, MITRE ATT&CK-aligned development, correlation rules, detection-as-code, CI/CD, tuning, and coverage measurement.
- Experience leading a 24x7 SOC and incident response function, including major incident command and executive, legal, privacy, compliance, and regulatory coordination.
- Hands-on experience with SOAR, security automation, EDR/XDR, AWS, Azure, GCP, identity threat detection, Cribl, Kafka, and streaming ETL, plus leadership of globally distributed teams across multiple regions.
Nice to have
- Experience applying AI and agentic SOC approaches to alert triage, investigation, threat hunting, response, parser generation, or false-positive reduction.
- Experience with security data lakes, federated SIEM architectures, IT and OT/ICS integration, or connected product and IoT telemetry.
- Experience in a decentralized, multi-business-unit organization operating across 50+ countries.
- Certifications such as CISSP, CISM, GCIA, GCIH, GCFA, or GNFA.
- Experience presenting to boards, audit committees, or executive risk committees.
Culture & Benefits
- Work in a global information security organization supporting life sciences, diagnostics, biotechnology, operating companies, and manufacturing environments.
- Remote work is available from Israel and from Kraków, Poland; the Kraków option may also be onsite.
- Regular international travel supports collaboration with operating company, R&D, SOC, and manufacturing locations.
- Work within ’s culture of continuous improvement and the Business System.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Cyber Incident Response Leader
225 400 - 354 200PLN
10 дней назад
Senior Detection Engineer (Cybersecurity)
195 000 - 230 000$
7 дней назад
Data Protection Analyst
9 дней назад
Senior Detection Engineer (Cybersecurity)
159 800 - 235 000$
CrowdStrike
13 дней назад
Security Advisor I (Cybersecurity)
85 000 - 120 000$
5 часов назад
Senior Active Defense Engineer (AI)
159 600 - 239 400$