The Head of Detect and Respond is accountable for establishing, operating and continuously improving company global cyber detection, monitoring and incident response capability.
Description
* Define and lead company global cyber detect and respond strategy, ensuring priorities align to enterprise cyber risk, operational resilience, regulatory expectations and business impact tolerance.
* Establish and continuously improve enterprise threat detection, monitoring and incident response capabilities across IT, cloud, identity, endpoint, network, data, OT and third-party environments.
* Govern SOC and managed security service performance, ensuring clear service outcomes, quality assurance, escalation paths, metrics, SLAs and continuous improvement plans.
* Lead incident response strategy, playbooks, command structures and crisis coordination for high-severity cyber events, ensuring timely containment, communication, escalation and recovery handover.
* Drive detection engineering, SIEM, EDR, XDR, SOAR, threat intelligence, telemetry onboarding, alert tuning and automation to improve detection quality, reduce false positives and accelerate response.
* Provide cyber detection and response insight to governance, audit, risk, crisis management and senior leadership forums, translating threat activity and service performance into business risk and action.
* Partner with Cyber Recover, Cyber Engineering & Architecture, Service Operations, Digital GRC, Business Continuity, suppliers and senior leaders to embed resilience by design and improve end-to-end cyber maturity.
* Lead, coach and develop three direct reports, building a high-performing cyber operations capability with clear accountabilities, strong delivery discipline and a collaborative culture.
Profile
- Deep knowledge of enterprise threat detection, SOC operations, SIEM, EDR, XDR, SOAR, Crowdstrike, threat intelligence, incident response, digital forensics principles, attacker techniques and detection engineering.
- Strong understanding of cyber frameworks and regulatory expectations, including NIST Cybersecurity Framework, MITRE ATT&CK, NIS2, SOx, ITGC, GxP, data integrity, audit evidence and operational resilience.
- Good understanding of global technology operating models, managed service integration, vendor governance, service transition, cloud, identity, endpoint, network, data and OT monitoring considerations.
- Awareness of pharmaceutical, manufacturing or similarly regulated environments, including the importance of validated systems, manufacturing resilience and audit-ready evidence.
Job Offer
- Permanent contract with long-term career prospects.
Interested candidates are encouraged to apply.