Director, Cyber Detection & Response
$135.4k - $208.1kCardinal Health
What Cybersecurity Defense contributes to Cardinal Health
Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures to protect our digital assets and infrastructure at Cardinal Health. The Director, Cyber Detection & Response is responsible for establishing, leading, and continuously enhancing cybersecurity detection, monitoring, and incident response capabilities to protect the organization from evolving cyber threats. Furthermore, this leader oversees Security Operations Center (SOC) operations, cyber threat detection, incident response, threat intelligence, and security testing functions to enable rapid identification, containment, and remediation of cybersecurity threats. This role plays a critical role in driving proactive defense strategies, improving detection and response capabilities, and ensuring alignment with risk and resilience objectives.
Location - Open to candidates nationwide working in a fully remote capacity, with preference towards those based in Central or Eastern time zones (willingness to travel into our Corporate HQ in Dublin, OH during certain period of the year is a plus)
Responsibilities
Develop and lead the cybersecurity detection and response strategy aligned with enterprise risk, threat landscape, and business priorities.
Establish governance frameworks and operating models for SOC, incident response, and threat management functions.
Serve as an advisor to leadership on threat trends, detection capabilities, and response readiness.
Drive continuous improvement of detection and response capabilities to address evolving threats and business needs.
Oversee SOC operations, including security logging, monitoring, alerting, and incident triage across the environment.
Oversee effective use of SIEM platforms to analyze correlated events, detect anomalies, and escalate potential incidents.
Lead the development and optimization of detection use cases, analytics, and monitoring strategies to improve visibility across the environment.
Oversee monitoring capabilities across IT and OT environments, ensuring coverage of critical systems and infrastructure.
Lead detection engineering and security tooling functions, including SIEM, SOAR, EDR, UEBA, and DLP capabilities.
Oversee the definition and implementation of use cases, rules, and configurations to improve automated detection, investigation, and response workflows.
Drive optimization and integration of security tools to enhance operational efficiency and reduce false positives.
Establish and lead threat intelligence capabilities to gather, analyze, and operationalize threat data from internal and external sources.
Oversee threat monitoring, analysis, and detection rule enhancement to proactively identify emerging threats.
Lead threat modeling activities to identify attack vectors, vulnerabilities, and control gaps across systems and processes.
Drive proactive threat hunting initiatives to identify hidden threats and indicators of compromise (IoCs) within the environment.
Lead enterprise incident response (IR) capabilities, including planning, testing, execution, and continuous improvement of IR processes.
Oversee incident response lifecycle activities including detection, triage, containment, eradication, and recovery.
Oversee incident response simulations and exercises to validate readiness and improve response effectiveness.
Enable effective coordination of incident response efforts across cybersecurity, IT, legal, and business stakeholders.
Manage breach notification processes and communication protocols for cybersecurity incidents.
Oversee digital forensics and investigative activities to determine the scope, root cause, and impact of cybersecurity incidents.
Ensure proper evidence collection, analysis, and documentation to support investigations and regulatory requirements.
Lead post-incident reviews and root cause analysis to strengthen detection and response capabilities.
Lead offensive and defensive security testing capabilities, including red teaming, penetration testing, and adversarial simulations.
Oversee blue team operations to detect, analyze, and respond to threats across enterprise environments.
Facilitate purple teaming activities to enhance collaboration between offensive and defensive teams and improve detection and response effectiveness.
Drive continuous improvement of security controls through testing, validation, and simulation exercises.
Collaborate with cybersecurity, IT, risk, legal, and business teams to integrate detection and response capabilities into enterprise operations.
Partner with architecture, engineering, and infrastructure teams to ensure detection and response requirements are embedded into system design and deployment.
Provide actionable insights and reporting to leadership on threat landscape, incident trends, and response effectiveness.
Support audit and regulatory activities by providing evidence and documentation related to detection and response processes
Define and track KPIs and KRIs related to detection, response, and operational performance.
Provide regular reporting to leadership on SOC performance, incident metrics, and threat trends.
Identify opportunities to enhance detection coverage, reduce response times, and improve operational efficiency.
Drive continuous improvement initiatives to mature detection and response capabilities.
Build and lead a high-performing cybersecurity detection and response team across SOC, IR, and threat management functions.
Develop team capabilities through training, mentoring, and structured career development initiatives.
Foster a culture of accountability, collaboration, and continuous improvement.
Ensure alignment of team capabilities with evolving threat landscape and organizational needs.
Qualifications
Ideally targeting individuals with 10+ years of experience in cybersecurity, with a strong focus on detection, incident response, and security operations.
Deep expertise in SOC operations, SIEM, incident response, and threat intelligence a plus.
Experience leading cybersecurity operations teams and managing complex incident response activities, a strong preference.
Strong understanding of cybersecurity frameworks (e.g., NIST CSF) and regulatory requirements required.
Demonstrated ability to communicate technical concepts and risk insights to executive leadership.
Strong leadership, analytical, and problem-solving skills.
Experience in highly regulated industries, a plus
Experience with advanced analytics, automation, and AI-driven security operations, a strong preference
#LI-LP
#LI-Remote
Anticipated salary range: $135,400 - $208,100
Bonus eligible: Yes
Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
401k savings plan
Access to wages before pay day with myFlexPay
Flexible spending accounts (FSAs)
Short- and long-term disability coverage
Work-Life resources
Paid parental leave
Healthy lifestyle programs
Application window anticipated to close: 07/01/2026 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.
Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.
To read and review this privacy notice click here (
- The State Employees' Credit Union seeks a Vice President of Cyber Security Incident Detection & Response to lead a team in Raleigh, NC. This role involves overseeing incident detection and response processes, mentoring staff, and ensuring compliance with best practices...Cyber2 days per week
- ...the credit union philosophy of "People Helping People," join our team! Position Overview The Vice President of Cyber Security Incident Detection & Response is a management role responsible for overseeing and managing the Security Incident Detection and Response function...Cyber
$135.4k - $208.1k
...Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures... ...at Cardinal Health. The Director, Exposure Management is responsible... ...management initiatives with broader cyber defense and risk reduction strategies...CyberTemporary workLocal areaImmediate startRemote workFlexible hours$110k - $152.4k
...North Carolina OR remotely in USA. Meet the Team Incident Detection & Response (ID&R) is part of the investigative branch of Cisco’s Security... ...(S&TO) and serves as Cisco’s information security, cyber investigations, and forensics team. We provide Cisco with tailored...CyberFull timeTemporary workWork at officeLocal areaRemote workFlexible hours- ...Governance, this role will redefine how cyber third-party risk is identified, assessed... ...audit engagements. ESSENTIAL DUTIES AND RESPONSIBILITIES Following is a summary of the essential... ...NYDFS), functions (Anticipate, Protect, Detect, Respond) and information security controls...CyberFull timeContract workPart timeShift workDay shift
$80.2k - $111.3k
...Position Overview The Cybersecurity Incident Response Engineer, Senior leads complex incident... ...the organization's ability to prevent, detect, and rapidly respond to sophisticated... ...management platforms integrated with SOC and cyber defense functions. Certifications such...CyberContract workWork experience placementWork at office$100.2k - $164.1k
...Senior Incident Response Consultant 133254 This role joins SpearTip, the cybersecurity... ..., unique skill sets, and proven cyber counterintelligence strategies, SpearTip... ...actors and become the gold standard in detecting zero-day vulnerabilities. In this role you...CyberFull timeTemporary workApprenticeshipLocal areaRemote workVisa sponsorshipFlexible hours- ...KPMG is currently seeking an Associate Director, Presales Solution Architect - Cyber to join our KPMG Delivery Network organization. Responsibilities: Lead KYC / AML Solution... ...such as incident management, threat detection, vulnerability management, and operational...CyberH1bLocal area
$86.4k - $138.6k
...leading healthcare organization in North Carolina seeks a Senior Cyber Incident Responder to lead investigations and provide expert... .... The role includes analyzing log files, coordinating incident response, and making recommendations for risk mitigation. Candidates should...CyberRemote work$148k - $296k
K&L Gates is seeking a Senior Manager, Security Operations to oversee cybersecurity and incident response. The role requires 10+ years of experience in IT audit and multi-cloud environments, alongside demonstrated expertise in DevSecOps and security automation. The position...CyberRemote work$109.2k - $223.4k
...Job Description The Director for Global Defense - Japan is responsible for leading and growing strategic defense and national security business in Japan... ...solutions (e.g., cloud, data platforms, AI/analytics, cyber). Ensure proposals and delivery plans align to...CyberContract workTemporary workFor contractorsLocal areaFlexible hours- ...healthcare organization in Raleigh, North Carolina, is looking for a Cyber Incident Responder to manage and investigate security... ...a related field and at least 3 years in relevant experience. Responsibilities include coordinating technical support and performing log analysis...Cyber
$90k - $150k
...successful candidate will lead a 24/7 security team, manage incident response, and drive operational excellence within the organization. The... ...'s degree in a related field and significant experience in Cyber Security Operations. Competitive pay range of $90,000 - $150,00...Cyber$128.1k - $239.6k
...Information Security (Info Sec) - Info Sec prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and our information... .... The opportunity The Active Defense team is responsible for four core areas: Network Reconnaissance, Proactive...CyberSummer holidayLocal areaRemote workFlexible hoursNight shiftWeekend work- Ernst & Young Oman is hiring a Cyber Triage and Forensics Incident Analyst in Raleigh, North Carolina. The successful candidate will be responsible for security incident response, focusing on forensic analysis and identifying indicators of compromise. Required qualifications...Cyber
$40 per hour
...in the US, Canada, UK, Ireland, Australia, and New Zealand Responsibilities Evaluate AI-generated cybersecurity content, including threat... ...(e.g., penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or...CyberHourly payFull timePart timeRemote work$148.5k - $247.5k
...Communications, Inc. Job Family Group Sales Job Profile Director, Sales Engineering Management Level Director... ...Google, our solutions focus on business outcomes with embedded cyber resiliency and AI to protect today and enable tomorrow backed by...CyberRemote workVisa sponsorshipFlexible hoursShift work- ...The Incident Response Coordinator supports the end-to-end response to IT incidents and service disruptions, helping restore normal operations... ...Use monitoring/ITSM data to route incidents; engage infra/app/cyber/vendor dependencies. Communications & Handoffs: Provide...CyberContract workWork experience placementWork at officeShift work
- ...Job Title Responsible for developing and maintaining the technical IT / cyber security capabilities necessary for safeguarding the firm's information systems and... ...including but not limited to firewalls, intrusion detection/prevention systems, network operating systems,...CyberWork experience placementWork at office
- ...position supports Information Security and Cyber Threat management programs within the... ...group or assist special projects. Responsibilities Security Review - Monitors and evaluates... ...the Bank's networks and systems. Detects anomalies, malware infections, and intrusion...CyberFor contractorsRemote work
- ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates... ...governance and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness and continual...CyberContract workWork experience placementWork at officeShift work
- ...Cyber Defense & Data Security Lead (Americas) Location: Raleigh/hybrid The Cyber... ...South America, with the primary goal to detect, prevent, and minimize business impacting... ...security operations, including incident response and incident management, threat intelligence...CyberFull timeLocal areaShift work
- ...requests only; other inquiries won't receive a response). Regular or Temporary: Regular... ...and maintaining the technical IT / cyber security capabilities necessary for safeguarding... ...but not limited to firewalls, intrusion detection/prevention systems, network operating...CyberFull timePart timeWork experience placementWork at officeShift workDay shift
- ...and proactive on-going value and support to Varonis customers, responsible for driving measurable security outcomes across cloud data, modern... ...data to ensure all data is protected from insider threats, cyber-attacks, and policy violations Help customers identify and mitigate...CyberRemote work
- ...business capabilities across grid upgrades, cyber security, metering, & behind-the-meter... ...change across the company. Key Responsibilities: Develop and implement strategic plans... ...who perform line locating and gas leak detection services, to intelligent software that...CyberFor contractorsWorldwide
- ...certifications: CEH OR CFR OR CCNA Cyber Ops OR CCNA-Security OR CySA+ OR CHFI... ...cybersecurity concepts, including threat detection, malware analysis, and network security... ..., Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement...CyberContract workShift workNight shiftRotating shift
- ...The Senior Cybersecurity Professional is responsible for protecting the organization's computer systems and networks from cyber threats. This is a hands-on role. Only candidates... ...and incident response, ensuring timely detection, investigation, escalation, and resolution...CyberLocal area
$70.63k - $112.16k
...Crime Commission (GCC). This position is responsible for the planning, organization,... ...consultant and resources to the Executive Director of the Governor's Crime Commission and the... ...on the "National Standards to Prevent, Detect, and Respond to Prison Rape." PREA Hiring...Full timePart timeWork experience placementInternshipWork at officeLocal areaRemote workMonday to Friday- Join to apply for the Cyber Security Analyst II role at SECU Join to apply for the Cyber... ...: A Security Administrator II is responsible for implementing, managing, and optimizing... ...security teams to ensure effective threat detection and response. The Security Administrator...Cyber16 hoursFull timeInternshipWork from home
- ...helping businesses be secure -we're redefining what it means to be cyber resilient. Our end-to-end platform blends AI-powered... ...believe in what they do-and in you. The Benefits Coordinator is responsible for providing administrative support for the Total Rewards team...CyberLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Cyber Detection & Response. Be the first to apply!
- director lease administration Raleigh, NC
- residence director Raleigh, NC
- director of foundation relations Raleigh, NC
- director of benefits Raleigh, NC
- nonprofit director Raleigh, NC
- director of video production Raleigh, NC
- senior director it Raleigh, NC
- director biotech Raleigh, NC
- director medical device Raleigh, NC
- director m&a integration Raleigh, NC

