A technology-driven investment organization seeks a Director of Cyber Defense to lead security operations across multiple businesses. Reporting to the CISO, you will guide engineers, oversee security monitoring, and own the response to cyber threats while remaining closely involved in technical delivery.
A central objective is to build AI-assisted operations that improve alert evaluation, investigation, and response. You will combine Microsoft security expertise, SOC leadership, and practical automation with clear human controls, reliable escalation, and strong protection of sensitive data.
RESPONSIBILITIES- Lead detection engineering, incident response, threat intelligence, hunting, and digital forensics.
- Improve security monitoring coverage and service performance across business entities.
- Oversee SOC delivery and advance the security operations model.
- Build AI-driven enrichment, triage, investigation, and response workflows with human oversight.
- Direct Microsoft security tooling, SIEM/SOAR strategy, and automation engineering.
- Lead significant incidents, coordinate remediation, and improve controls after reviews.
- Secure AI-enabled systems and align operations with data-protection and regulatory obligations.
- Develop engineers and communicate security performance to business and executive stakeholders.
Role Requirements- 10+ years in cyber defense or security operations, including 5+ years leading teams.
- Direct ownership of detection, incident response, and threat intelligence.
- Deep Microsoft Sentinel, Defender, Entra ID, and SOAR expertise, with KQL, Python, and PowerShell proficiency.
- Applied AI/ML and security-automation experience, including a credible approach to agentic operations.
- Monitoring experience across multiple tenants, entities, or shared-services environments.
- Working knowledge of AI security/governance and experience implementing data classification and protection.
- Knowledge of adversary techniques, cloud/endpoint data protection, and security/control frameworks.
- Bachelor s degree in a related field and a relevant security certification, or ability to obtain one.
- Strong technical leadership, coaching, and executive communication.
- Ability to meet the onsite schedule and work in the U.S. Without employer sponsorship now or in the future.
PREFERRED EXPERIENCE- Security operations experience in regulated banking or related industries.
- Experience building a SOC or significantly transforming its operating model.
- Advanced degree in a relevant discipline.