The Director of Cyber Defense / Security Engineering Lead / Threat Operations Director leads the organisation’s cyber-defence strategy, security-engineering capabilities, and threat-detection operations. This role protects systems, networks, cloud platforms, applications, data, and users from cyber threats by establishing effective preventive controls, detection capabilities, incident-response processes, and security-operations practices.
The position works closely with Security Operations, Engineering, Cloud, Infrastructure, Application Development, Identity, Risk, Compliance, Legal, Internal Audit, and external security partners. Responsibilities include directing security monitoring, threat hunting, vulnerability remediation, incident response, security-tool engineering, attack-surface management, and forensic investigation activities while ensuring timely escalation and communication of material cyber risks.
At leadership level, the role sets cyber-defence roadmaps, operational standards, service levels, and performance metrics. It leads multidisciplinary security teams, manages technology and vendor investments, improves automation and detection coverage, oversees crisis readiness, and provides senior leadership with clear insight into threats, control effectiveness, incidents, and resilience priorities.
Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, Information Systems, or a related field.
- Master’s degree, executive qualification, or relevant advanced technical experience is an advantage.
- Professional certifications such as CISSP, CISM, GIAC, GCIH, GCIA, OSCP, CEH, CCSP, or equivalent are highly desirable.
- Significant experience in cybersecurity, security operations, threat detection, incident response, security engineering, threat intelligence, or a related field.
- Proven experience leading security operations centres, cyber-defence teams, security-engineering teams, or large-scale threat-management programmes.
- Strong knowledge of network security, endpoint security, cloud security, application security, identity and access management, data protection, and vulnerability management.
- Experience with SIEM, SOAR, EDR/XDR, NDR, threat-intelligence platforms, vulnerability scanners, security analytics, and incident-management tools.
- Strong understanding of threat hunting, detection engineering, attack techniques, malware analysis, digital forensics, security monitoring, and incident-response lifecycle practices.
- Knowledge of threat frameworks and methodologies such as MITRE ATT&CK, Cyber Kill Chain, NIST CSF, CIS Controls, ISO 27001, and relevant regulatory requirements.
- Experience developing detection use cases, response playbooks, escalation procedures, security dashboards, metrics, and service-level objectives.
- Ability to assess cyber threats, prioritise vulnerabilities and incidents, manage remediation, and communicate risk clearly to technical and senior business stakeholders.
- Experience leading cyber-crisis exercises, breach-response activities, post-incident reviews, recovery planning, and continuous-improvement programmes.
- Ability to manage security-service providers, technology vendors, penetration testers, threat-intelligence partners, and external incident-response specialists.
- Strong leadership, stakeholder-management, decision-making, crisis-management, communication, and problem-solving skills.
- High professional integrity, sound judgement, and ability to lead calmly and effectively in fast-moving, high-pressure security environments.
#J-18808-Ljbffr
Kontaktdaten:
Unity - Inovações Disruptivas Recruiting-Team