Director of Cyber Defense

Posted · Add Comment
Career Techniques Inc
Published
August 6, 2026
Location
Dallas, TX - Hybrid - 3 days/week in-office
Category
 
Job Type

Description

The Position

The Director of Cyber Defense reports to the Chief Information Security Officer and operates within the Office of the CISO. This role owns the full cyber defense mission: threat detection, incident response, threat intelligence, threat hunting, and digital forensics. The Director is accountable for global IT security monitoring across this multi-entity, multi-tenant environment, ensuring consistent visibility, detection coverage, and response readiness regardless of where in the ecosystem a threat emerges.

This is an AI-first leadership role. The Director will lead the organization in AI adoption by designing and building an agentic cyber defense capability, in which AI agents augment and increasingly execute detection engineering, alert triage, investigation, and response orchestration under strong human oversight. Equally, the Director is responsible for governing and securing AI itself: defending the enterprise AI platforms, gateways, and agentic workloads the business depends on, and ensuring the AI used within cyber defense meets the firm's governance, data classification, and acceptable use standards.

The ideal candidate pairs deep operational cyber defense expertise, particularly in the Microsoft security ecosystem, with a demonstrated record of building teams, transforming operating models, and applying AI/ML to security operations at scale.

Responsibilities

  • Cyber defense leadership: Own and mature the enterprise cyber defense function, spanning detection engineering, incident response, threat intelligence, threat hunting, and DFIR, setting strategy, standards, and operational metrics across the Ecosystem.
  • Global monitoring across a diverse ecosystem: Direct 24x7 global IT security monitoring across a multi-tenant environment serving a diverse ecosystem of companies, including regulated financial entities, ensuring consistent telemetry coverage, detection fidelity, and response SLAs for every entity.
  • Agentic cyber defense: Lead the organization in AI adoption by architecting and delivering an agentic cyber defense model, deploying AI agents for alert enrichment, triage, investigation, detection engineering, and automated response, with clearly defined human-in-the-loop controls, guardrails, and escalation paths.
  • Govern and secure AI: Establish and enforce governance for AI used in cyber defense (model risk, data handling, auditability, and acceptable use), and defend the enterprise's AI estate, including AI gateways, model endpoints, agent frameworks, and AI-enabled SaaS, against emerging threats such as prompt injection, model abuse, and data exfiltration.
  • Incident response: Own the enterprise incident response framework and entity-specific playbooks; lead major incident command, coordinate cross-entity response, and drive post-incident reviews, root cause analysis, and control improvements.
  • Detection and automation engineering: Direct SIEM/SOAR strategy and engineering, driving AI/ML-enhanced detections, behavioral analytics, and intelligent automation to improve signal-to-noise ratio and reduce time to detect and respond.
  • Threat intelligence and hunting: Mature the threat intelligence program with PIR-driven collection and dissemination, and lead proactive, hypothesis-driven threat hunting across the ecosystem.
  • Stakeholder engagement: Partner with entity leadership, IT, engineering, legal, and compliance; represent cyber defense in architecture reviews and risk governance forums; report operational posture and metrics to executive leadership and boards.
  • Team leadership: Build, coach, and retain a high-performing cyber defense team; accurately assess performance, develop talent, and evolve roles as agentic capabilities reshape the operating model.
  • Regulatory alignment: Ensure monitoring and response capabilities satisfy regulatory obligations across the portfolio, including federally regulated banking entities, and support audits, examinations, and legal matters as required.

Requirements

  • Bachelor’s degree in computer science, Information Security, or a related field; advanced degree a plus.
  • 10+ years of progressive experience in cyber defense or security operations, including 5+ years leading teams, with direct accountability for detection, incident response, and threat intelligence functions.
  • Demonstrated experience applying AI/ML and automation to security operations, and a credible vision for building agentic cyber defense capabilities with appropriate human oversight.
  • Working knowledge of AI security and governance: securing LLM/agentic workloads, AI gateways, and model endpoints, and familiarity with frameworks such as the NIST AI RMF, MITRE ATLAS, and the OWASP Top 10 for LLM Applications.
  • Deep expertise in the Microsoft security ecosystem (Sentinel, Defender suite, Entra ID) and modern SOAR platforms; proficiency with KQL, Python, and PowerShell.
  • Experience running security monitoring at scale in multi-tenant, multi-entity, or shared-services environments; exposure to regulated industries (e.g., OCC/FDIC-supervised banking) strongly preferred.
  • Experience implementing and operationalizing enterprise data classification and protection programs, including sensitivity labeling, data loss prevention, and data security posture management (e.g., Microsoft Purview, DSPM platforms), with the ability to align detection and response priorities to data classification tiers.
  • Strong understanding of data protection controls across cloud and endpoint environments, including encryption, key management, data residency, and insider risk monitoring, and their application in regulated and multi-entity contexts.
  • Strong command of adversary tradecraft and frameworks including MITRE ATT&CK, and experience operationalizing threat intelligence.
  • Possession of, or ability to obtain, professional certifications such as CISSP, CISM, GCIH, GCFA, or equivalent.
  • Strong knowledge of security, regulatory, and control frameworks such as NIST CSF, ISO 27001, CIS, and GDPR.
  • Exceptional communication skills, with the ability to convey security and risk concepts to technical teams, executives, and boards.
  • High level of personal integrity and the ability to professionally handle confidential matters.
  • Strong coaching and team-building skills, with the ability to motivate others through direct and indirect reporting relationships to achieve objectives.
  • Max. file size: 100 MB.
  • Please complete the math question to prove you are human.

Related Jobs

Director of Vulnerability and Exploits   Dallas, TX - Hybrid - 3 days/week in-office
July 16, 2026
Incident Response Engineer - Cyber Defense   Dallas, TX - Hybrid - 3 days/week in-office
July 9, 2026
Cyber Defense Engineer - SIEM   Dallas, TX - Hybrid - 3 days/week in-office
July 9, 2026
Director of Offensive Security   Dallas, TX - Hybrid - 3 days/week in-office
June 1, 2026
Director of Incident Response   Dallas, TX - Hybrid - 3 days/week in-office
June 1, 2026