Job Description
The Director, Cyber Engineering and Operations is responsible for global threat detection and response, security engineering, and vulnerability management operations across the company's enterprise environment. This role leads a follow-the-sun incident response team spanning the US, EU, and Asia, and owns the operational relationship with the company's managed detection and response (MDR) provider. This role leads the Security Operations & Incident Response function within the Infrastructure, Operations, Architecture & Cyber Defense organization, executing the enterprise cyber defense strategy owned by that leader.
As part of the IT leadership team, this role partners closely with Governance, Risk & Compliance, Identity & Access Management, Enterprise (Infrastructure/Cyber) Architecture, Platform Engineering, and Network teams to deliver a resilient, compliant security operations capability across a global, acquisitive manufacturing environment.
HOW YOU WILL MAKE AN IMPACT:
- Define and execute the Security Operations & Incident Response strategy, roadmap, and staffing model.
- Lead a follow-the-sun Incident Response team covering detection, triage, and response across US, EU, and Asia regions.
- Own the relationship and SLA performance for the company's managed detection and response (MDR/EDR) provider.
- Mature the Security Operations Center (SOC) capability that provides detection and response coverage across the full estate — not only assets covered by the managed service — integrating and governing the MDR service for scale and surge and reducing reliance on it over time.
- Serve as operational incident commander for security incidents, escalating major incidents and executive communications to the Director, Infrastructure, Operations, Architecture & Cyber Defense in accordance with the incident response plan.
- Direct security engineering and detection engineering work, including tuning and content development across the security stack.
- Administer the vulnerability scanning toolset and lead remediation engineering, in partnership with GRC on policy and risk reporting and with functional IT teams on remediation execution.
- Coordinate incident response playbooks, tabletop exercises, and post-incident reviews.
- Partner with Identity & Access Management, Platform Engineering, and Network teams to align security architecture and controls across the environment.
- Partner with the Enterprise (Infrastructure/Cyber) Architect to ensure security requirements and controls are designed into platforms, transitions, and provider operations on a secure-by-design basis.
- Coordinate handoff protocols with third-party MSSPs supporting regulated enclaves (e.g., CMMC).
- Deliver regular security operations metrics, incident reporting, and program status to IT leadership.
- Contribute security operations metrics and maturity evidence to Enterprise Risk Management, the enterprise cybersecurity maturity roadmap (NIST CSF) and to board-level cyber reporting.
- Provide security operations input to M&A cyber due diligence and the rapid onboarding of acquisitions into monitoring and response coverage.
- Support audit readiness and evidence collection for relevant regulatory frameworks (ITAR, CMMC, NIST 800-171).
WHAT YOU WILL BRING TO THE ROLE:
- BS in Computer Science, Information Systems, or related field; equivalent experience considered.
- 10+ years in cybersecurity, including 5+ years leading a security operations or incident response function.
- Experience managing a globally distributed security team, ideally in a follow-the-sun model.
- Hands-on experience with EDR/XDR platforms and managed detection service providers (CrowdStrike experience a plus).
- Familiarity with vulnerability scanning tools and remediation workflows.
- Experience managing external vendors and MSSPs against defined SLAs.
- Exposure to regulated environments (ITAR, CMMC, NIST 800-171) is a plus.
- Certifications (Preferred): CISSP, GIAC (GCIH, GCIA, or similar), CISM.
- Strong communication skills and comfort reporting to IT and executive leadership.
- Experience building or maturing a security operations and incident response function from an early or under-developed state.
- Working familiarity with identity and access management (IAM/PAM) and network security concepts, sufficient to partner effectively with those peer functions.
- Demonstrated ability and willingness to use AI tools to improve productivity, decision-making, work quality, and to reduce costs. The successful candidate must be able to identify appropriate AI use cases and critically evaluate AI-generated outputs.
#LI-BM1