Global Director of Autonomous Cyber Defense and Security Event Triage (SOC)
Core
Leads strategy, execution, and continuous improvement of a 24/7 global cyber defense and security event triage function to protect enterprise assets.
Role type
Director of Autonomous Cyber Defense and Security Event Triage
Builds
Global cyber operations model, automated response workflows, and AI/ML-enabled defense capabilities
Domain
Cybersecurity Operations / Financial Services
Deliverable
production ML models | dashboards & analysis | client delivery
Required skills
Cybersecurity operations leadership, autonomous defense strategy, AI/ML and LLM workflow integration, budget planning, vendor management, purple team execution, threat hunting, incident triage governance, regulatory compliance oversight, operations analytics, security tooling modernization
Preferred skills
Security governance and oversight, security risk management, network security, threat and vulnerability management, incident response and forensics, security data analysis, offensive security understanding, enterprise detection and response technologies, endpoint detection and response, cloud security tooling, risk analysis, network protocols, operating systems security
Technologies
SOAR, EDR, SIEM, advanced threat detection tools, intrusion detection/prevention systems, network packet analysis, firewalls, anti-malware, web application firewall, cloud security tooling
Responsibilities
Direct and mature a 24/7 global cyber operations model; own functional strategy and multi-year roadmap; oversee budget planning and financial governance; lead, mentor, and scale global teams; serve as lead escalation contact; provide executive-level oversight for audit and regulatory engagements; drive AI/ML/LLM-enabled autonomous defense initiatives; establish governance for detection engineering and automation; lead critical incident triage and escalation governance; oversee monitoring of third-party security service providers; build an operations analytics program; sponsor and execute a purple team program; oversee proactive threat hunting; provide global operational leadership during cyber events; integrate threat intelligence into detection logic; produce and govern recurring reporting on threats and program performance; champion innovation in cyber defense tooling; partner with technology and business leaders to align priorities
Seniority
Director, strategic leadership with hands-on operational oversight