Head of Cyber Defence & Incident Response
Quadient
Head Of Cyber Defence & Incident Response
At Quadient, we support businesses of all sizes in their digital transformation and growth journey, unlocking operational efficiency with reliable, secure, and sustainable automation processes.
Our success in delivering innovation and business growth is inspired by the connections our diverse teams create every day, with our clients and each other.
It's these connections that make Quadient such an exceptional place to grow your career, develop your skills and make a real impact – help our future-focused business lead the way in powering secure and sustainable business connections through digital and physical channels.
Your Role In Our Future
- Location: Quadient offices, Markham Ontario, Canada or Eastern USA (EST Time zone)
- The Head of Cyber Defence and Incident Response owns the organisation's cyber defence capability across a hybrid environment (mix of on‑prem and cloud platforms), ensuring effective monitoring, detection, response and recovery.
- Reports directly to the CISO and leads cyber defence operations (including the MSSP) and cybersecurity incident response across the organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology.
- A key focus is optimising security tooling (e.g., SIEM, SOAR, EDR/XDR, NDR, email security, vulnerability scanning) and driving strong vulnerability and threat management, using threat intelligence to prioritise defensive improvements.
Key Responsibilities
- Own the incident response lifecycle (prepare, detect, analyse, contain, eradicate, recover), ensuring playbooks, tooling, and decision-making processes are in place and exercised.
- Lead and coordinate response to security incidents, acting as incident commander where required, including stakeholder communications, forensic triage, and recovery coordination.
- Manage the MSSP relationship end‑to‑end: service definition, SLAs/KPIs, escalation paths, continuous improvement plans, quality assurance, and commercial governance.
- Optimise security monitoring and response tooling working across technology teams (e.g., SIEM, SOAR, EDR/XDR, NDR, email security) including use‑case coverage, alert quality, automation, logging strategy, and operational runbooks.
- Own the vulnerability management programme (on‑prem and cloud), including scanning coverage, prioritisation, remediation SLAs, exception handling, verification, and executive reporting.
- Drive threat management by operationalising threat intelligence (internal and external) into defensive priorities: detection use cases, hardening actions, control uplift and proactive hunting themes.
- Lead continuous improvement of the defence stack: rationalise tools, tune detections, improve signal quality, reduce noise, and expand automation to accelerate triage and response.
- Establish and run a threat hunting programme using hypothesis‑driven approaches, telemetry coverage mapping, and lessons learned from incidents and red-team activity.
- Run regular tabletop exercises and simulations (including ransomware and cloud compromise scenarios), ensuring roles, escalation paths, and technical procedures are validated and improved.
- Own incident response governance: severity model, on‑call and escalation processes, evidence handling, case management, and alignment to legal/regulatory obligations.
- Define and report cyber defence metrics (e.g., MTTD/MTTR, alert volumes and precision, incident trends, vuln remediation performance, control coverage), presenting insights and recommendations to senior leadership.
- Lead post-incident reviews and root cause analysis, ensuring lessons learned translate into measurable improvements (detections, hardening, identity controls, backups, segmentation, and training).
- Support business continuity and crisis management processes during cyber events, contributing to executive updates and coordinated communications with Legal/Privacy and other stakeholders.
- Maintain and improve incident response documentation and readiness (playbooks, runbooks, contact trees), and ensure training is delivered for technical responders and business stakehol
- Communicate cyber risk and active incidents clearly to technical and non‑technical audiences, including concise executive briefings and after‑action summaries.
Your Profile
- Strong experience leading cyber defence/SOC and incident response, including major incident coordination, investigation, containment and recovery.
- Hands-on understanding of detection and response tooling and concepts (SIEM, SOAR, EDR/XDR, NDR, email security, log pipelines), including tuning, use-case engineering and operational workflows.
- Proven experience managing an MSSP or outsourced SOC capability, including SLAs/KPIs, service governance, escalations, and continuous improvement.
- Strong experience running vulnerability management and threat management programmes, including prioritisation based on exploitability, exposure, and business impact.
- Knowledge of incident response processes, digital forensics fundamentals, evidence handling, and working with legal/privacy and external forensic partners.
- Experience defending hybrid environments (on‑prem and cloud), including identity signals, network telemetry, endpoint visibility, and cloud-native security monitoring.
- Ability to operate under pressure and lead cross-functional teams through high-severity incidents, communicating clearly and making timely risk-based decisions.
- Fluent in English – excellent written and verbal communication skills, including producing clear architecture guidance, standards, and security design documentation.
Desirable
- Certifications such as GCIH, GCIA, GNFA, CISSP, CISM, or equivalent experience in incident response and security operations.
- Experience with threat hunting, purple teaming, and using MITRE ATT&CK to structure detections, gaps analysis, and defensive improvements.
- Experience with security operations in cloud platforms and common tools (e.g., Microsoft Defender, Sentinel, Splunk, CrowdStrike, Palo Alto, AWS/Azure security services) and integrating telemetry across environments.
- Calm under pressure , able to lead effectively during incidents and make timely decisions with incomplete information.
- Highly collaborative, able to coordinate across IT, engineering, legal/privacy, and business leaders during investigations and recovery.
- Operationally rigorous with strong attention to detail, documentation and evidence quality (case notes, timelines, lessons learned).
- Continuous improvement mindset—drives measurable outcomes through tooling optimisation, process refinement, and coaching teams to improve security hygiene.
Rewards & Benefits
- Flexible Work: Embrace a hybrid work model blending office and remote setup for a balanced lifestyle.
- Endless Learning: Access global opportunities for growth through our 24/7 online learning platform.
- Inclusive Community: Join our Empowered Communities and engage in our Philanthropy program.
- Comprehensive Rewards: Enjoy competitive Total Rewards covering wellness, work/life balance, and more, including a generous referral scheme.
- Caring for Wellbeing: Access our complimentary employee assistance program for mental health support.
Smart Work at Quadient At Quadient, our Smart Work approach fosters connection, collaboration, and innovation while offering flexibility based on role requirements. Whether on-site, hybrid, or remote, our work environments are designed to support productivity and engagement. Hybrid employees balance remote and in-office work, on-site roles contribute daily to our vibrant workplace culture, and remote employees stay connected through virtual collaboration and in-person events. No matter where you work, you'll be part of a dynamic, people-first community that drives success together.
Be yourself at Quadient Our values define how we work as a team: Empowerment, Passion, Inspiration and Community. They inspire us to be EPIC. Together. What makes Quadient different is how different we are. We're a team of individuals with one goal but many perspectives. When you connect with Quadient, you become part of a community that cares - in a culture that embraces differences and values every voice.
We will consider any reasonable modifications to the interview process. If you require any assistance with the application process, please email us at View email address on click.appcast.io
Quadient is an Equal Employment Opportunity Employer. We firmly believe in zero discrimination in employment on any basis, including race, color, religion, sex, national origin, age, disability, veteran or military status, genetic information, citizenship status, and any other characteristics protected by local, state, or federal law.
People. Connected.
- ...to provide legal counsel in data privacy and cybersecurity incidents. The ideal candidate should have 6-12 years of experience, excellent... ...skills, and be a member in good standing with a state Bar. Responsibilities include overseeing investigations and directing experts...Cyber
- ...heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential... ...Details Position Summary The Engineer II, Cyber Incident Response, is a mid-level technical role within the Security...CyberFull timeWork experience placementLocal area
$89.01k - $142.19k
...Are you looking for a unique Cyber Security role whereby you will provide key insight and research into new threats, exploits,... ...You will be entrusted as the senior most technical member of incident response team for our global information security organization About...CyberLocal areaWork from home- Freshman Head Girls Volleyball Coach Southeast Delco School District Academy Park High... ...Park High School Essential Duties & Responsibilities Teach and train players on fundamental... ...all student concerns, injuries, and incidents to the Athletic Department immediately....SuggestedContract workPart timeWork at officeImmediate start
- ...cybersecurity) analyst to be responsible for desktop, mobile... ..., troubleshooting incidents and implementing security... ...ensuring the proper defences are present for each... ...management of external Cyber audits of the SERB IT... ...security issues to the Group Head of IT and/or CFO...CyberFor contractorsWork at officeImmediate startWork from homeWorldwide3 days per week
- A multi-country niche law firm is seeking an Associate Attorney to provide legal counsel on data privacy and cybersecurity incidents. The ideal candidate should be a member of the Pennsylvania Bar and have 1 to 8 years of relevant experience. This role involves working...
$70k - $100k
...organization, ensuring compliance with published policies; conducting cybersecurity vulnerability and threat analysis; and support cyber incident-response by isolating potentially effected assets, initial investigation and data collection, through status updates/reporting....CyberContract workWork at officeRemote work$75.28k - $122.33k
...-level member of the cybersecurity team responsible for the execution, development and maintenance... .... Serve as a key contributor to incident response planning, testing,... ...tools and the sources available to conduct cyber security alerting, analysis, and enhanced...CyberInternshipWork at officeFlexible hours3 days per week- ...Job Description Job Description Head Start is a comprehensive preschool program for low-income children ages birth through five... ...instructional process by serving as a teacher with specific responsibility for supervising students within the classroom and other assigned...Work at office
- ...reduce costs, but to improve business processes, accelerate response time, improve services to end-users, and give our customers a... ...cybersecurity vulnerability and threat analysis, and supporting cyber incident response Current IAM-II certification (CAP, CASP+ CE, CISM...CyberFor contractors
- ...GreenShades, GoDaddy, ADP, Coupa Negotiate pricing and leverage competition among vendors Conduct cyber security risk mitigation and cyber security incident responses; develop and implement Information System Contingency Plan using NIST SP 800-34 Troubleshoot IT-...Cyber
- ...Analyst, reporting to the Sr. Manager, Cyber Security, and is focused on securing enterprise... ...Participate in data security incidents and investigations, assisting with evidence... ...and business stakeholders. This team is responsible for defining security standards and enabling...CyberFull timeWork experience placementWork at office2 days per week
- ...Overview: As the Head of Cyber Defense within Vanguard's Cyber Security Operations Center... ...) , you will serve as a senior leader responsible for advancing and executing Vanguard's... ...defense Close alignment with incident response, detection engineering, and platform...Cyber
- ...infrastructure and operations. Key Responsibilities Ensure availability, performance, and... ...Monitor systems for threats and respond to incidents. Promote user awareness of... ...endpoint protection tools Certification in cyber security (e.g., CompTIA Security+,...Cyber
- ...Job Opportunity Responsibilities Provide advanced subject matter expertise to customers,... ...partners that support the entire suite of cyber services Support marketing efforts... ...presence, mobile apps, loss mitigation and incident response Work with clients both...CyberWork at office
$140k - $175k
...Information Security Engineer IV is a key member of the cyber security team that is responsible for designing and implementing security solutions that... ...identify, assess, and mitigate security risks, and supporting incident response to contain the damage from security incidents...CyberFull time- ...Cyber Security Analyst Location US-PA-Philadelphia ID 2025-1... ...NSWCPD) is a Department of Defense entity responsible for research and development, test and evaluation... ...and DISA guidance Reporting security incidents in accordance with the Command's...CyberFull timeFor contractorsLocal area
$190k
...lifecycles, system designs, and IT architectures. Utilizing cyber risk quantification to reduce uncertainty around cyber risk... ...-top exercises. Delivering operational resilience through incident response, business continuity, and disaster recovery planning. What...CyberWork at office- ...oversee a large engineering organization responsible for the full lifecycle of endpoint... ...reduce engineering RUN burden to %. Reduce incident volume through standardization, automation... ...alignment with enterprise architecture, cyber security, risk & compliance,...Cyber
$106.8k - $194.8k
...Operations Solution Engineer, you will be responsible for implementing and managing Web... ...solutions to protect client applications from cyber threats. You will work within a team of... ...analyze security events, and respond to incidents to mitigate risks effectively. Additionally...CyberSummer holidayFlexible hours- ...Security Automation Engineer. This position is responsible for engineering the Barracuda XDR SOAR... ...research. Train new and current cyber security analysts on existing or new technologies... ...customers remediate active breaches/incidents. Designing and implementing AI-driven...CyberLocal areaWorldwideFlexible hours
$76.4k - $138.6k
...blend risk strategy, digital identity, cyber defense, application security and technology... ...impact of security weaknesses.Your responsibilities will include supporting the validation... ...you’ll also have OWASP training Incident response experience What we look for...CyberSummer holidayLocal areaFlexible hours- ...Security Engineers (ISSE) to carry out all cyber hygiene tasks involved in the planning... ...you join us on that mission! Key Responsibilities Assists with implementation of... ...to determine compliance Prepares incident reports of analysis methodology and results...CyberWork at office
$110.5k - $205k
...connecting the space, air, land, sea and cyber domains in the interest of national... ...Administrator serves as a technical expert responsible for the effective provisioning, installation... ...Administration and Documentation Incident Response Backup and Recovery Ability...CyberLocal areaFlexible hours$101.49k - $120k
...partners closely with Service Desk, Field Support, Cyber Security, and key vendors to coordinate service delivery... ..., and provide senior-level escalation for complex incidents and systemic issues. Core responsibilities include administration and optimization of the...CyberWork experience placementLocal area$90 per hour
...Therapist to provide PT services to K-12 students who attend Cyber Charter School in Delaware County, PA . Opportunities are... ...Experience working with the pediatric population, preferred Responsibilities: To provide high-quality 1:1 services to students based...CyberDaily paidContract workReliefMonday to FridayFlexible hours- ...Office) and overall security. They are responsible for implementing proactive security initiatives... ..., and breaches. Respond to security incidents by identifying root causes, mitigating... ...security experience ~2-3 years of cyber security experience ~ Constant...CyberWork experience placementWork at officeLocal area
- ...Philadelphia, PA 19112 (on-site) Job Description/Responsibilities: Maintains overall responsibility for the availability... ...for suspicious activities and respond to security incidents. Stay up-to-date with the latest cyber threats, vulnerabilities, and security...CyberWork experience placementWorldwideFlexible hours
$77.5k - $140.9k
...risks and vulnerabilities. As part of our Cyber Threat and Vulnerability Management (... ...clients' specific needs. Your Key Responsibilities Deliver exceptional client services... ...Possess a thorough understanding of the incident response process and familiarity with frameworks...CyberWork experience placementSummer holidayFlexible hours$65.2k - $101.95k
...Responsibilities Noblis MSD supports the Naval Sea Systems Command (NAVSEA) and the Naval... ...Monitor systems for threats and respond to incidents. Promote user awareness of... ...endpoint protection tools Certification in cyber security (e.g., CompTIA Security+, CISSP...CyberFull timeContract workPart timeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Head of Cyber Defence & Incident Response. Be the first to apply!


