Vice President, Security Detection & Response, Global Information Security
Job Description
Sunday to Wednesday
) to align with the nature of the support provided by the team.
Flexibility may occasionally be required to support business, operational, or project deliverables.
Role Description:
We are seeking an experienced and motivated Security Detection & Response Analyst (SDR II) to join the GIS Monitoring and Triage team. This role supports cybersecurity operations across threat detection, investigation, response, and continuous service improvement.
You should be an experienced security practitioner capable of operating within the end-to-end detection and response lifecycle (detect → investigate → respond → improve), combining broad analytical capability with an engineering mindset to rapidly identify, investigate, and contain threats. The analyst will operate across multiple security domains, validating detections, investigating threats, and executing response actions with sound judgment.
This role requires cross-domain security expertise, broad analytical and engineering capabilities, and the ability to leverage automation, orchestration, and AI-driven technologies to improve detection outcomes, reduce manual effort, and continuously enhance overall security effectiveness.
Responsibilities:
- You will operate within the end-to-end detection and response lifecycle (detect → investigate → respond → improve), including analyzing logs and telemetry from multiple sources to establish attack scope, impact, and root cause
- You will build, validate, tune, and optimize detection logic and coverage, leveraging attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK to improve accuracy and reduce false positives
- Execute and coordinate security event response activities, including containment, isolation, escalation, and remediation, applying sound judgment during active engagements
- You will maintain and improve automation and orchestration capabilities, including SOAR workflows, automated playbooks, scripted response actions, and AI-driven enhancements to reduce manual effort and improve detection and response outcomes. Accountable for measurable improvements in MTTR, detection quality, and signal-to-noise ratio
- You will document and communicate security event findings, including timelines and lessons learned, while providing clear updates to stakeholders and driving continuous improvement in detection and response processes
- Identify gaps in monitoring and detection coverage, contributing to operational maturity through continuous improvement initiatives, metrics, and enhancements to detection, response, and automation capabilities
- Support integration of partner use cases into detection and monitoring workflows
- Guide and instruct junior members of the team to support the achievement of professional goals
What we are looking for
- Experience in security operations, incident response, detection engineering, or related cybersecurity functions within a production environment
- Experience in security detection, investigation, and response across multiple domains, with the ability to pivot across data sources and independently manage end-to-end investigations from initial triage through post-incident improvement
- Ability to build, validate, and tune detections and response workflows, including reducing false positives.
- Considerable proficiency in log analysis, telemetry interpretation, and cross-system data correlation, including the ability to query, manipulate, and optimize data using KQL, SPL, SQL, or similar languages for investigative and detection use cases
- Practical experience with containment, response actions, and automation, including developing or maintaining SOAR workflows, API integrations, and scripted response actions using sound judgment
- Experience with security platforms and technologies, including SIEM, EDR/XDR, identity security, and cloud security
- Working knowledge of identity and access systems and common attack paths, including credential theft, privilege escalation, and session/token abuse
- Considerable understanding of attacker tactics, techniques, and procedures (TTPs), including MITRE ATT&CK
- Record of improving operational effectiveness, including reducing alert noise, improving detection coverage, and decreasing mean time to detect and respond
- Great analytical, decision-making, and communication skills, including the ability to clearly articulate findings, provide timely incident updates to both technical and non-technical stakeholders, and operate effectively in high-pressure scenarios
- Ability to operate with minimal supervision and make risk-informed decisions quickly
Skills that will help
- Exceptional communication and executive presence, with the ability to influence at all organizational levels
- Process discipline
- Leadership competency in geographically diverse matrixed environment.
- Relevant Cyber Security Certificate
- Worked in SOC environment before
- Familiarity with Cyber Security and Information Technology.
- Strong problem-solving and critical thinking skills.
- Effective communication and interpersonal skills.
Not included in the source posting: about the role, what you'll do, benefits.
Skills
Who can apply
The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.
Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.