Job Title: Director, Cyber Engineering and Operations
Berwyn, PA, US, 19312
The Director, Cyber Engineering and Operations is responsible for global threat detection and response, security engineering, and vulnerability management operations across the company's enterprise environment. This role leads a follow-the-sun incident response team spanning the US, EU, and Asia, and owns the operational relationship with the company's managed detection and response (MDR) provider. This role leads the Security Operations & Incident Response function within the Infrastructure, Operations, Architecture & Cyber Defense organization, executing the enterprise cyber defense strategy owned by that leader.
As part of the IT leadership team, this role partners closely with Governance, Risk & Compliance, Identity & Access Management, Enterprise (Infrastructure/Cyber) Architecture, Platform Engineering, and Network teams to deliver a resilient, compliant security operations capability across a global, acquisitive manufacturing environment.
HOW YOU WILL MAKE AN IMPACT:
- Define and execute the Security Operations & Incident Response strategy, roadmap, and staffing model.
- Lead a follow-the-sun Incident Response team covering detection, triage, and response across US, EU, and Asia regions.
- Own the relationship and SLA performance for the company's managed detection and response (MDR/EDR) provider.
- Mature the Security Operations Center (SOC) capability that provides detection and response coverage across the full estate — not only assets covered by the managed service — integrating and governing the MDR service for scale and surge and reducing reliance on it over time.
- Serve as operational incident commander for security incidents, escalating major incidents and executive communications to the Director, Infrastructure, Operations, Architecture & Cyber Defense in accordance with the incident response plan.
- Direct security engineering and detection engineering work, including tuning and content development across the security stack.
- Administer the vulnerability scanning toolset and lead remediation engineering, in partnership with GRC on policy and risk reporting and with functional IT teams on remediation execution.
- Coordinate incident response playbooks, tabletop exercises, and post-incident reviews.
- Partner with Identity & Access Management, Platform Engineering, and Network teams to align security architecture and controls across the environment.
- Partner with the Enterprise (Infrastructure/Cyber) Architect to ensure security requirements and controls are designed into platforms, transitions, and provider operations on a secure-by-design basis.
- Coordinate handoff protocols with third-party MSSPs supporting regulated enclaves (e.g., CMMC).
- Deliver regular security operations metrics, incident reporting, and program status to IT leadership.
- Contribute security operations metrics and maturity evidence to Enterprise Risk Management, the enterprise cybersecurity maturity roadmap (NIST CSF) and to board-level cyber reporting.
- Provide security operations input to M&A cyber due diligence and the rapid onboarding of acquisitions into monitoring and response coverage.
- Support audit readiness and evidence collection for relevant regulatory frameworks (ITAR, CMMC, NIST 800-171).
WHAT YOU WILL BRING TO THE ROLE:
- BS in Computer Science, Information Systems, or related field; equivalent experience considered.
- 10+ years in cybersecurity, including 5+ years leading a security operations or incident response function.
- Experience managing a globally distributed security team, ideally in a follow-the-sun model.
- Hands-on experience with EDR/XDR platforms and managed detection service providers (CrowdStrike experience a plus).
- Familiarity with vulnerability scanning tools and remediation workflows.
- Experience managing external vendors and MSSPs against defined SLAs.
- Exposure to regulated environments (ITAR, CMMC, NIST 800-171) is a plus.
- Certifications (Preferred): CISSP, GIAC (GCIH, GCIA, or similar), CISM.
- Strong communication skills and comfort reporting to IT and executive leadership.
- Experience building or maturing a security operations and incident response function from an early or under-developed state.
- Working familiarity with identity and access management (IAM/PAM) and network security concepts, sufficient to partner effectively with those peer functions.
- Demonstrated ability and willingness to use AI tools to improve productivity, decision-making, work quality, and to reduce costs. The successful candidate must be able to identify appropriate AI use cases and critically evaluate AI-generated outputs.
#LI-BM1
Nearest Major Market: Philadelphia