- Company Name
- Diligent
- Job Title
- Senior Director, Cyber Threat Detection & Response
- Job Description
-
**Job Title**
Senior Director, Cyber Threat Detection & Response
**Role Summary**
Lead and evolve a global Cyber Threat Detection & Response organization. Provide executive direction while actively managing high‑impact incidents, detection tuning, and vulnerability work. Drive strategic threat intelligence, AI integration, and continuous improvement of incident response and monitoring capabilities.
**Expectations**
- 10+ years in cybersecurity, with 5+ years leading threat response or SOC functions.
- Proven player‑coach: balance executive leadership with hands‑on technical execution.
- Deep technical foundation in incident response, threat hunting, vulnerability management, and security tooling.
- Executive communication and stakeholder management skills.
**Key Responsibilities**
1. Lead, mentor, and grow a global Threat Response team, fostering accountability and continuous improvement.
2. Own the end‑to‑end incident response process (triage, investigation, containment, recovery).
3. Engage directly in critical incident investigations, detection development, and vulnerability remediation.
4. Collaborate with IT, Product, Engineering, Legal, and Risk to coordinate incident communication and remediation.
5. Expand and tune threat detection use cases, integrate threat intelligence, and enhance monitoring capabilities.
6. Manage relationships with technology vendors, MSSP/MDR partners, ensuring SLA compliance and effective incident coordination.
7. Define, track, and report operational metrics (MTTD, MTTR, patch SLA, etc.) to executive leadership.
8. Stay ahead of emerging threats; lead innovation in tools, processes, and team capabilities.
9. Drive integration of AI‑driven tools and methodologies into the incident response lifecycle to improve detection, triage, and resolution.
**Required Skills**
- Incident response, threat hunting, vulnerability management, and security tooling expertise.
- Proficiency with SIEM, SOAR, EDR, vulnerability scanners, and cloud‑native security solutions.
- Knowledge of attacker TTPs and threat modeling frameworks (e.g., MITRE ATT&CK).
- Experience with AWS, Azure, GCP, container security, and cloud platforms.
- Strong communication, executive stakeholder engagement, and team leadership abilities.
**Required Education & Certifications**
- Bachelor’s (or higher) in Computer Science, Cybersecurity, or related field.
- Preferred industry certifications: CISSP, GIAC, CISM, or equivalent.