Director, Cyber Detection & Response
$135.4k - $208.1kCardinal Health
What Cybersecurity Defense contributes to Cardinal Health
Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures to protect our digital assets and infrastructure at Cardinal Health. The Director, Cyber Detection & Response is responsible for establishing, leading, and continuously enhancing cybersecurity detection, monitoring, and incident response capabilities to protect the organization from evolving cyber threats. Furthermore, this leader oversees Security Operations Center (SOC) operations, cyber threat detection, incident response, threat intelligence, and security testing functions to enable rapid identification, containment, and remediation of cybersecurity threats. This role plays a critical role in driving proactive defense strategies, improving detection and response capabilities, and ensuring alignment with risk and resilience objectives.
Location - Open to candidates nationwide working in a fully remote capacity, with preference towards those based in Central or Eastern time zones (willingness to travel into our Corporate HQ in Dublin, OH during certain period of the year is a plus)
Responsibilities
Develop and lead the cybersecurity detection and response strategy aligned with enterprise risk, threat landscape, and business priorities.
Establish governance frameworks and operating models for SOC, incident response, and threat management functions.
Serve as an advisor to leadership on threat trends, detection capabilities, and response readiness.
Drive continuous improvement of detection and response capabilities to address evolving threats and business needs.
Oversee SOC operations, including security logging, monitoring, alerting, and incident triage across the environment.
Oversee effective use of SIEM platforms to analyze correlated events, detect anomalies, and escalate potential incidents.
Lead the development and optimization of detection use cases, analytics, and monitoring strategies to improve visibility across the environment.
Oversee monitoring capabilities across IT and OT environments, ensuring coverage of critical systems and infrastructure.
Lead detection engineering and security tooling functions, including SIEM, SOAR, EDR, UEBA, and DLP capabilities.
Oversee the definition and implementation of use cases, rules, and configurations to improve automated detection, investigation, and response workflows.
Drive optimization and integration of security tools to enhance operational efficiency and reduce false positives.
Establish and lead threat intelligence capabilities to gather, analyze, and operationalize threat data from internal and external sources.
Oversee threat monitoring, analysis, and detection rule enhancement to proactively identify emerging threats.
Lead threat modeling activities to identify attack vectors, vulnerabilities, and control gaps across systems and processes.
Drive proactive threat hunting initiatives to identify hidden threats and indicators of compromise (IoCs) within the environment.
Lead enterprise incident response (IR) capabilities, including planning, testing, execution, and continuous improvement of IR processes.
Oversee incident response lifecycle activities including detection, triage, containment, eradication, and recovery.
Oversee incident response simulations and exercises to validate readiness and improve response effectiveness.
Enable effective coordination of incident response efforts across cybersecurity, IT, legal, and business stakeholders.
Manage breach notification processes and communication protocols for cybersecurity incidents.
Oversee digital forensics and investigative activities to determine the scope, root cause, and impact of cybersecurity incidents.
Ensure proper evidence collection, analysis, and documentation to support investigations and regulatory requirements.
Lead post-incident reviews and root cause analysis to strengthen detection and response capabilities.
Lead offensive and defensive security testing capabilities, including red teaming, penetration testing, and adversarial simulations.
Oversee blue team operations to detect, analyze, and respond to threats across enterprise environments.
Facilitate purple teaming activities to enhance collaboration between offensive and defensive teams and improve detection and response effectiveness.
Drive continuous improvement of security controls through testing, validation, and simulation exercises.
Collaborate with cybersecurity, IT, risk, legal, and business teams to integrate detection and response capabilities into enterprise operations.
Partner with architecture, engineering, and infrastructure teams to ensure detection and response requirements are embedded into system design and deployment.
Provide actionable insights and reporting to leadership on threat landscape, incident trends, and response effectiveness.
Support audit and regulatory activities by providing evidence and documentation related to detection and response processes
Define and track KPIs and KRIs related to detection, response, and operational performance.
Provide regular reporting to leadership on SOC performance, incident metrics, and threat trends.
Identify opportunities to enhance detection coverage, reduce response times, and improve operational efficiency.
Drive continuous improvement initiatives to mature detection and response capabilities.
Build and lead a high-performing cybersecurity detection and response team across SOC, IR, and threat management functions.
Develop team capabilities through training, mentoring, and structured career development initiatives.
Foster a culture of accountability, collaboration, and continuous improvement.
Ensure alignment of team capabilities with evolving threat landscape and organizational needs.
Qualifications
Ideally targeting individuals with 10+ years of experience in cybersecurity, with a strong focus on detection, incident response, and security operations.
Deep expertise in SOC operations, SIEM, incident response, and threat intelligence a plus.
Experience leading cybersecurity operations teams and managing complex incident response activities, a strong preference.
Strong understanding of cybersecurity frameworks (e.g., NIST CSF) and regulatory requirements required.
Demonstrated ability to communicate technical concepts and risk insights to executive leadership.
Strong leadership, analytical, and problem-solving skills.
Experience in highly regulated industries, a plus
Experience with advanced analytics, automation, and AI-driven security operations, a strong preference
#LI-LP
#LI-Remote
Anticipated salary range: $135,400 - $208,100
Bonus eligible: Yes
Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
401k savings plan
Access to wages before pay day with myFlexPay
Flexible spending accounts (FSAs)
Short- and long-term disability coverage
Work-Life resources
Paid parental leave
Healthy lifestyle programs
Application window anticipated to close: 07/01/2026 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.
Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.
To read and review this privacy notice click here (
$135.4k - $208.1k
...Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures... ...at Cardinal Health. The Director, Exposure Management is responsible... ...management initiatives with broader cyber defense and risk reduction strategies...CyberTemporary workLocal areaImmediate startRemote workFlexible hours$80.2k - $111.3k
...Position Overview The Cybersecurity Incident Response Engineer, Senior leads complex incident... ...the organization's ability to prevent, detect, and rapidly respond to sophisticated... ...management platforms integrated with SOC and cyber defense functions. Certifications such...CyberContract workWork experience placementWork at office- ..., and alignment. Attendance is expected and fully supported. Responsibilities The Security team’s goal is to identify, measure, manage, mitigate... ...methodologies Working knowledge of and experience in cyber/security domain Fluency in leveraging AI in daily workflows...CyberTemporary workLocal area
$40 per hour
...in the US, Canada, UK, Ireland, Australia, and New Zealand Responsibilities Evaluate AI-generated cybersecurity content, including threat... ...(e.g., penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or...CyberHourly payFull timePart timeRemote work- ...The Incident Response Coordinator supports the end-to-end response to IT incidents and service disruptions, helping restore normal operations... ...Use monitoring/ITSM data to route incidents; engage infra/app/cyber/vendor dependencies. Communications & Handoffs: Provide...CyberContract workWork experience placementWork at officeShift work
- ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates... ...governance and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness and continual...CyberContract workWork experience placementWork at officeShift work
- ...supporting RMF; 7+ years’ experience in DoD cyber Clearance Level & Investigation:... ...Program Manager (IAPM) in protecting, detecting, characterizing, countering, and mitigating... ...experience with High School Diploma Responsibilities Validate cybersecurity compliance; review...Cyber
- Overview A Cyber Data Forensics Analyst specializes in investigating, analyzing, and interpreting... ...analytical methods to uncover evidence, detect anomalies, and reconstruct cyberattacks.... ...legal and ethical integrity. Key Responsibilities Collect, process, and analyze digital...Cyber
- ...evidence is captured and organized. Key Responsibilities Cybersecurity Program Execution &... ...baseline configurations. Track and close cyber‑related FAT punch items; ensure retests... ...expectations are met). Monitoring, Logging, and Detection Enablement Coordinate and document OT...CyberFull timeWork experience placementCasual workWork at officeRemote workHome office
$76.4k - $138.6k
...secure products and services, as well as detect and quickly respond to security events... ...blend risk strategy, digital identity, cyber defense, application security and technology... ...in the EY digital attack surface. Your responsibilities will include aiding in the assessment...CyberSummer holidayLocal areaFlexible hours$94.25k - $215.05k
...Description Cybersecurity Engineers are responsible for maintaining our customers security tools... ...expected to have an understanding of cyber technologies such as endpoint solutions... ...components Driving continuous improvement of detection accuracy through strategic tuning and...CyberFull timeLocal area$94.1k - $150k
...Position Overview The Cyber Threat Hunter proactively protects enterprise environments... ...normal traffic and data-flow baselines, detects anomalies, develops threat hypotheses, and... ...to strengthen cyber defense and incident response operations. This role directly supports a...CyberContract workWork at office- ...cybersecurity training institute in South Carolina is seeking a Cyber Data Forensics Analyst to investigate and analyze data related... ...This position offers the opportunity to contribute to incident responses within a legal and ethical framework. #J-18808-Ljbffr Yugal Tech...Cyber
- ...cybersecurity threat monitoring and incident response. A strong candidate for this position... ...possess experience in the following: Cyber Threat Response and Incident Handling... ...Analyst will be performing monitor, detect and response capabilities in the agency cloud...CyberContract workWork at officeRelocation
- ...Instructor in Information Security and Cyber Leadership The College of Information and... ...build an exemplary master’s program. Responsibilities Teach online courses in the ISCL program... ...in partnership with the Graduate Director. Mentor graduate students in the ISCL program...CyberLocal area
- ...of Product Marketing Our leading internationally recognized cyber security firm is seeking a VP of Product Marketing. The VP of... ...enterprise technology/software market and target audience. Roles and Responsibilities Develop an aligned go-to-market approach to support and...CyberWork experience placement
- ...criminal justice information systems, SLED's diverse responsibilities make it one of the most dynamic law enforcement... ...Oversee the collection, analysis, and dissemination of cyber threat intelligence to prevent, detect, and mitigate attacks, and promotes cybersecurity awareness...CyberWork experience placementLocal area
- ...business continuity. This position will be a part of the team responsible for supporting these efforts and transition to operational... ...policies and procedures to conform and comply with agency standard cyber security policy design related to information risk management,...CyberContract workFor contractorsWork experience placementRemote workRelocationFlexible hours1 day per week
- ...covers configuring these solutions, performing detection, analysis, and reporting with Kusto Query Language (KQL), and mitigating cyber threats. Designed for security operations... ...threat management, monitoring, and response using Microsoft Azure Sentinel, Azure Defender...Cyber
- ...This position is pending contract award. Responsibilities Trace Systems is seeking a dynamic... ...mission critical services; Monitor and detect cybersecurity events; and implement appropriate... .... Manage, guide and train other IA, cyber mission defense and other cyber security...CyberContract workWork experience placementLocal area
- ...everything we do in support of our vision of a safe and secure cyber world. Our globally recognized, award-winning portfolio of... ...This position is not available to residents of California . Responsibilities Participate in a fully remote software engineering...CyberWork experience placementWork at officeRemote work
- ...place. They are looking for a Vertical Sales Director to focus on their Critical Infrastructure Vertical. You will be responsible for presenting their products in ways that... ...opportunity to closure Experience in physical or cyber security pursuit, with acumen in computer...CyberRemote workShift work
- ...unparalleled experience in both investigative and protective operations. Responsibilities include: Conducting complex criminal investigations into financial crimes, including counterfeiting, cyber fraud, and other threats to the financial infrastructure of the United...Cyber
- ...Program for all control systems per the Cybersecurity Roles and Responsibilities for Facility-Related Control Systems at site. Serve as... ...years of experience may be utilized Credentials that meet DoD Cyber Workforce requirements for specialty codes 441 (Network...CyberContract workWork at officeRemote work
$114k - $142k
...you ready to help us make the future? We are seeking a Cyber Security Architect/Engineer II – Active Directory/IAM to... ...work remotely and report directly to our Cyber Security Director. KEY RESPONSIBILITIES This role is responsible for managing the daily operations...CyberPermanent employmentTemporary workWork experience placementRemote workFlexible hours$72.7k
...and investigate live security incidents. Cyber Incident Responders work independently... ...drive process improvements. Essential Responsibilities Coordinate and provide expert... ...document cyber defense incidents from initial detection through final resolution. (5%) Other duties...CyberFor contractorsWork at officeLocal areaRemote work$82.8k - $175k
...business through collaborative and educational efforts. JOB RESPONSIBILITIES: # Coaches, motivates, and professionally develops direct... ...staffing plans and budget processes. # Coordinate with Nelnet Cyber Security Group (CSG) to ensure that NBS is compliant with all...CyberTemporary workLocal area- ...and oversee the overall Young Life Military program, known as Club Beyond, which is ecumenically focused and outreach oriented. Responsibilities include: Actively develop healthy relationships with adults, as well as kids, and build vibrant relationships with the...Full timeLive outWork at officeLocal areaOverseas
- ...Campus Director of Admissions - ECPI This position will work at ECPI University's Columbia, SC campus location. Transform your... ...Position Summary The Campus Director of Admissions is responsible for leading and managing an admissions team to provide professional...Work at office
$79.6k - $143.3k
...is making our Veterans a priority for employment in state agencies and institutions. Job Responsibilities Under general supervision, serves as the Director of Classification and Compensation and Human Resource Information Systems for the SC Technical College...Full timeTemporary workWork at officeRemote workMonday to FridayFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Cyber Detection & Response. Be the first to apply!
- director lease administration Columbia, SC
- residence director Columbia, SC
- director of benefits Columbia, SC
- nonprofit director Columbia, SC
- director of video production Columbia, SC
- senior director it Columbia, SC
- director biotech Columbia, SC
- director m&a integration Columbia, SC
- director of innovation Columbia, SC
- director of community relations Columbia, SC

