Назад
Company hidden
6 дней назад

Senior Director, Global Cyber Detection & Response (Cybersecurity)

Формат работы
remote (только Europe)/onsite
Тип работы
fulltime
Грейд
senior/director
Английский
b2
Страна
US/Poland/Israel
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Director, Global Cyber Detection & Response (Cybersecurity): Building and operating a global threat detection and incident response capability across cloud, on-premises, endpoint, identity, OT/ICS, and product environments with an accent on enterprise SIEM architecture, detection engineering, and 24x7 SOC operations. Focus on modernizing telemetry and detection platforms, applying AI and automation to cyber defense workflows, and leading incident response across a complex multi-country enterprise.

Location: Remote from Israel; Kraków, Poland, onsite or remote. Regular international travel to operating company, R&D, SOC, and manufacturing locations is required, up to 20–30% of the time. The Global Information Security organization is located in Washington, D.C.

Company

hirify.global is a global science and technology company operating across life sciences, diagnostics, and biotechnology through more than 15 businesses and 60,000+ associates.

What you will do

  • Own the global incident detection and response strategy, roadmap, execution, and operational effectiveness across cloud, endpoint, identity, network, OT/ICS, and product environments.
  • Lead the architecture, implementation, and operation of the enterprise SIEM, security data lake, UEBA, SOAR, EDR/XDR, and related detection platforms.
  • Manage the complete telemetry and detection engineering lifecycle, including log onboarding, parsing, normalization, MITRE ATT&CK-aligned use cases, validation, tuning, and coverage measurement.
  • Build and mature a global 24x7 cyber defense organization with SOC analysts, detection engineers, incident responders, threat hunters, and automation engineers.
  • Drive AI, agentic SOC workflows, threat hunting, automated enrichment, alert triage, investigation, and response orchestration.
  • Govern incident response and cyber crisis management while communicating performance metrics to operating company leaders, executives, audit committees, and risk stakeholders.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field, or equivalent professional experience, plus 12+ years of information security experience.
  • Direct ownership of security operations, detection engineering, and/or incident response in a global organization.
  • Experience standing up, migrating, or modernizing enterprise-scale SIEM environments, including telemetry ingestion, data pipelines, parsing, normalization, and detection content ownership.
  • Deep expertise in detection engineering, MITRE ATT&CK-aligned development, correlation rules, detection-as-code, CI/CD, tuning, and coverage measurement.
  • Experience leading a 24x7 SOC and incident response function, including major incident command and executive, legal, privacy, compliance, and regulatory coordination.
  • Hands-on experience with SOAR, security automation, EDR/XDR, AWS, Azure, GCP, identity threat detection, Cribl, Kafka, and streaming ETL, plus leadership of globally distributed teams across multiple regions.

Nice to have

  • Experience applying AI and agentic SOC approaches to alert triage, investigation, threat hunting, response, parser generation, or false-positive reduction.
  • Experience with security data lakes, federated SIEM architectures, IT and OT/ICS integration, or connected product and IoT telemetry.
  • Experience in a decentralized, multi-business-unit organization operating across 50+ countries.
  • Certifications such as CISSP, CISM, GCIA, GCIH, GCFA, or GNFA.
  • Experience presenting to boards, audit committees, or executive risk committees.

Culture & Benefits

  • Work in a global information security organization supporting life sciences, diagnostics, biotechnology, operating companies, and manufacturing environments.
  • Remote work is available from Israel and from Kraków, Poland; the Kraków option may also be onsite.
  • Regular international travel supports collaboration with operating company, R&D, SOC, and manufacturing locations.
  • Work within hirify.global’s culture of continuous improvement and the hirify.global Business System.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →