MUFG logo
MUFGPosted 1 month ago

Global Director of Autonomous Cyber Defense and Security Event Triage (SOC)

$182,000–$227,000 year

HybridTempe, Arizona, United States or Jersey City, New Jersey, United States

Full TimeSenior LevelEnterprise

Job Summary

Direct and mature a 24/7 global cyber operations model for security event monitoring, triage, incident response partnership, and threat hunting across multiple environments. Own functional strategy, multi-year roadmap, and KPI/OKR outcomes for autonomous cyber defense and security event triage, including MTTD/MTTR and false-positive reduction. Lead, mentor, and scale high-performing global teams while defining operating rhythms, coverage models, and escalation paths. Serve as the lead escalation contact in a 24/7 environment, guide appropriate resources to resolution, and oversee budget planning, vendor management, and financial governance for global cyber operations tooling. Drive AI/ML/LLM-enabled autonomous defense initiatives to improve alert quality and standardize decisioning. Establish governance for detection engineering, triage decisioning, and automation to reduce response gaps. Lead critical incident triage and escalation governance, partner with incident response and infrastructure teams to coordinate containment, and oversee third-party security service providers. Sponsor and execute a purple team program to validate detections through adversary emulation aligned to MITRE ATT&CK. Provide global operational leadership during cyber events by coordinating communications and technical execution across regions and time zones. Produce recurring and ad-hoc reporting on threats, trends, and program performance to support stakeholder decision-making.

Required Qualifications

  • Bachelor's degree in Information Technology, Cyber Security, Computer Science, or related discipline or equivalent work experience
  • 7+ years of experience working in the Cybersecurity Operations or Information Security
  • Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position.

Desired Qualifications

  • Relevant technical and industry certifications, such as CISSP, ISSMP, GCIA, CISM, CEH, GCFA, GCIH, or GSEC are preferred
  • Experience in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, or Incident Response and Forensics preferred
  • Experience with information security risk management, including information security audits, reviews, and risk assessments
  • Experience in operational processes such as security monitoring, data correlation, troubleshooting, security operations, etc.
  • Preferred experience with Torq, 7AI, CrowdStrike, Tanium, Snowflake, Splunk, and ELK
  • Scripting/programming experience preferred
  • Education •Bachelor's degree in Computer Science or a closely-related discipline, or an equivalent combination of formal education and experience

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce