Responsibilities
- Establishing program structure, operating rhythms, and reporting for cyber defense initiatives, in support of program priorities set by the Sr. Manager
- Tracking ownership and accountability across the detection, threat intelligence, and response functions, and maintaining a single trusted source of program status
- Driving visibility into program health, risks, and execution status for the Sr. Manager and leadership
- Orchestrating threat intelligence program activities and workflows, coordinating the integration of intelligence into detection and response
- Driving consistency in threat-informed prioritization across teams
- Tracking detection coverage, telemetry onboarding, and capability maturity
- Coordinating remediation of monitoring and visibility gaps and driving consistency in detection-related execution across teams
- Tracking execution of control and detection-related initiatives, and coordinating cross-functional efforts to close control and detection gaps
- Supporting alignment of control implementation with detection and response priorities
- Coordinating incident response program execution and readiness, including runbook lifecycle, tabletop exercises, and post-incident review follow-through
- Tracking incident lifecycle activities and escalations through to closure
- Coordinating day-to-day engagement with the managed detection and response provider, including escalation procedures and service review preparation
- Preparing program reporting and dashboards that carry the operational performance metrics defined by the Sr. Manager (e.g., MTTD, MTTR, containment effectiveness, recovery performance)
- Driving testing, exercises, and continuous improvement across readiness activities
- Track and coordinate the end-to-end vulnerability management lifecycle, ensuring system-level gaps are identified, asset owners are documented, and remediation schedules are maintained.
- Oversee the lifecycle of the Security Exception Management process, ensuring technical exceptions are documented with robust compensating controls and tracked through formal approval workflows.
Qualifications
- The successful candidate will possess the following:
- 5+ years of technical program or information security management experience, with at least 2 years supporting security operations, detection engineering, threat intelligence, or incident response programs
- Proven success running multi-workstream programs with heavy cross-functional dependencies
- Strong understanding of security operations concepts, including the detection engineering lifecycle, telemetry and log onboarding, threat intelligence integration, and the incident response lifecycle
- Experience supporting programs built on security tooling and platforms (e.g., SIEM, EDR, threat intelligence platforms)
- Strong command of program management tooling (e.g., Jira, Azure DevOps) and discipline in maintaining accurate program data
- Demonstrated ability to coordinate senior technical staff and partner teams without direct authority
- Experience with managed security service provider (MSSP/MDR) engagement models preferred
- Experience standing up program structure in a new or maturing function preferred
- Excellent written and verbal communication skills, including executive-ready status reporting
- Experience working across Security, IT, and business stakeholders
- Proficiency in data visualization and reporting suites (such as PowerBI or Tableau) to analyze vulnerability trends, operate program metrics, and maintain executive-ready reporting dashboards.
- Certifications such as Project Management Professional (PMP) and Certified Information Systems Security Professional (CISSP) are highly desired.