Director, Cyber Detection & Response
$135.4k - $208.1kCardinal Health
What Cybersecurity Defense contributes to Cardinal Health
Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures to protect our digital assets and infrastructure at Cardinal Health. The Director, Cyber Detection & Response is responsible for establishing, leading, and continuously enhancing cybersecurity detection, monitoring, and incident response capabilities to protect the organization from evolving cyber threats. Furthermore, this leader oversees Security Operations Center (SOC) operations, cyber threat detection, incident response, threat intelligence, and security testing functions to enable rapid identification, containment, and remediation of cybersecurity threats. This role plays a critical role in driving proactive defense strategies, improving detection and response capabilities, and ensuring alignment with risk and resilience objectives.
Location - Open to candidates nationwide working in a fully remote capacity, with preference towards those based in Central or Eastern time zones (willingness to travel into our Corporate HQ in Dublin, OH during certain period of the year is a plus)
Responsibilities
Develop and lead the cybersecurity detection and response strategy aligned with enterprise risk, threat landscape, and business priorities.
Establish governance frameworks and operating models for SOC, incident response, and threat management functions.
Serve as an advisor to leadership on threat trends, detection capabilities, and response readiness.
Drive continuous improvement of detection and response capabilities to address evolving threats and business needs.
Oversee SOC operations, including security logging, monitoring, alerting, and incident triage across the environment.
Oversee effective use of SIEM platforms to analyze correlated events, detect anomalies, and escalate potential incidents.
Lead the development and optimization of detection use cases, analytics, and monitoring strategies to improve visibility across the environment.
Oversee monitoring capabilities across IT and OT environments, ensuring coverage of critical systems and infrastructure.
Lead detection engineering and security tooling functions, including SIEM, SOAR, EDR, UEBA, and DLP capabilities.
Oversee the definition and implementation of use cases, rules, and configurations to improve automated detection, investigation, and response workflows.
Drive optimization and integration of security tools to enhance operational efficiency and reduce false positives.
Establish and lead threat intelligence capabilities to gather, analyze, and operationalize threat data from internal and external sources.
Oversee threat monitoring, analysis, and detection rule enhancement to proactively identify emerging threats.
Lead threat modeling activities to identify attack vectors, vulnerabilities, and control gaps across systems and processes.
Drive proactive threat hunting initiatives to identify hidden threats and indicators of compromise (IoCs) within the environment.
Lead enterprise incident response (IR) capabilities, including planning, testing, execution, and continuous improvement of IR processes.
Oversee incident response lifecycle activities including detection, triage, containment, eradication, and recovery.
Oversee incident response simulations and exercises to validate readiness and improve response effectiveness.
Enable effective coordination of incident response efforts across cybersecurity, IT, legal, and business stakeholders.
Manage breach notification processes and communication protocols for cybersecurity incidents.
Oversee digital forensics and investigative activities to determine the scope, root cause, and impact of cybersecurity incidents.
Ensure proper evidence collection, analysis, and documentation to support investigations and regulatory requirements.
Lead post-incident reviews and root cause analysis to strengthen detection and response capabilities.
Lead offensive and defensive security testing capabilities, including red teaming, penetration testing, and adversarial simulations.
Oversee blue team operations to detect, analyze, and respond to threats across enterprise environments.
Facilitate purple teaming activities to enhance collaboration between offensive and defensive teams and improve detection and response effectiveness.
Drive continuous improvement of security controls through testing, validation, and simulation exercises.
Collaborate with cybersecurity, IT, risk, legal, and business teams to integrate detection and response capabilities into enterprise operations.
Partner with architecture, engineering, and infrastructure teams to ensure detection and response requirements are embedded into system design and deployment.
Provide actionable insights and reporting to leadership on threat landscape, incident trends, and response effectiveness.
Support audit and regulatory activities by providing evidence and documentation related to detection and response processes
Define and track KPIs and KRIs related to detection, response, and operational performance.
Provide regular reporting to leadership on SOC performance, incident metrics, and threat trends.
Identify opportunities to enhance detection coverage, reduce response times, and improve operational efficiency.
Drive continuous improvement initiatives to mature detection and response capabilities.
Build and lead a high-performing cybersecurity detection and response team across SOC, IR, and threat management functions.
Develop team capabilities through training, mentoring, and structured career development initiatives.
Foster a culture of accountability, collaboration, and continuous improvement.
Ensure alignment of team capabilities with evolving threat landscape and organizational needs.
Qualifications
Ideally targeting individuals with 10+ years of experience in cybersecurity, with a strong focus on detection, incident response, and security operations.
Deep expertise in SOC operations, SIEM, incident response, and threat intelligence a plus.
Experience leading cybersecurity operations teams and managing complex incident response activities, a strong preference.
Strong understanding of cybersecurity frameworks (e.g., NIST CSF) and regulatory requirements required.
Demonstrated ability to communicate technical concepts and risk insights to executive leadership.
Strong leadership, analytical, and problem-solving skills.
Experience in highly regulated industries, a plus
Experience with advanced analytics, automation, and AI-driven security operations, a strong preference
#LI-LP
#LI-Remote
Anticipated salary range: $135,400 - $208,100
Bonus eligible: Yes
Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
401k savings plan
Access to wages before pay day with myFlexPay
Flexible spending accounts (FSAs)
Short- and long-term disability coverage
Work-Life resources
Paid parental leave
Healthy lifestyle programs
Application window anticipated to close: 07/01/2026 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.
Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.
To read and review this privacy notice click here (
$108k - $135k
Early Warning Services LLC in Scottsdale seeks a Cyber Security Incident Response Analyst II. This role involves detecting, identifying, and responding to urgent cybersecurity threats as part of a high-performance team. Candidates must have a Bachelor's degree and at least...Cyber$135.4k - $208.1k
...Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures... ...at Cardinal Health. The Director, Exposure Management is responsible... ...management initiatives with broader cyber defense and risk reduction strategies...CyberTemporary workLocal areaImmediate startRemote workFlexible hours$66.9k - $82.1k
...Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment, and recovery of cybersecurity incidents across... ...service management platforms integrated with SOC and cyber defense functions. Certifications such as ITIL Foundation...CyberContract workWork experience placementWork at office$80.2k - $111.3k
...Position Overview The Cybersecurity Incident Response Engineer, Senior leads complex incident... ...the organization's ability to prevent, detect, and rapidly respond to sophisticated... ...management platforms integrated with SOC and cyber defense functions. Certifications such...CyberContract workWork experience placementWork at office- Position: Cybersecurity Incident Response Analyst at Splunk, Arizona. Role The Cybersecurity Incident Response Analyst works... ..., 24/7 Security Operations Center (SOC) supporting the detection and response to cyber threats. You will have comprehensive applied knowledge of...CyberLocal areaShift work
$108k - $135k
...position is ineligible for employment Visa sponsorship. Overall Purpose The Cyber Security Incident Response Analyst II is part of a high-performance team, responsible for detecting, identifying, mitigating and responding to critical or urgent threat situations....CyberHourly payWork experience placementWork at officeImmediate startVisa sponsorshipWork visaFlexible hours- Cisco is looking for a Cybersecurity Incident Response Analyst to join Splunk in Arizona. This role involves supporting a 24/7 SOC operation, responding to security threats, and enhancing security measures. The ideal candidate will have over 5 years of relevant experience...Cyber
- ...advisor to senior leadership and the Board of Directors, translating risk into the business and... ...program, security governance, incident response, and the work that keeps our compliance... ...environment. Deep fluency in cyber risk across IT and OT, with real command...CyberPermanent employmentFor contractorsLocal areaWork from homeHome office
- A technology-focused company is seeking a Cyber Security Engineer to design and implement security software and policies at the Enterprise... ...in Computer Science, 3-5 years of experience in incident response, and familiarity with Azure Cloud and SIEM technologies. The role...CyberFull timeRemote work
- ...Fraud Prev & Detect Lead Keeping our customers safe from fraud is critical to the success... ...and Detection Team Lead will be responsible for supporting the fraud detection and prevention... ...of Compliance, Corporate Security, Cyber Security, Legal and on occasion, outside...Cyber
$167.28k - $196.8k
...quantitative factors, including KRIs and KPIs. Serving as the Directly Responsible Individual (DRI) for key security initiatives or workstreams... ...methodologies ~ Working knowledge of and experience in cyber/security domain ~ Fluency in leveraging AI in daily workflows...CyberTemporary workLocal area- ...Seeking an Individual Contributor in Cybersecurity Escalation Response Management. The Manager for Escalation Response will coordinate... ...and prepare CSC for adverse events. They will be expected to use Cyber intelligence to proactively seek out threats and protect firm...CyberWork at office
$162k - $203k
...As a Principle Incident Response Analyst at Honeywell Aerospace, you will be instrumental in conducting detailed analysis and... ...strategies and initiatives You will report directly to our Sr. Director of Cyber Security, and work out of our Phoenix, AZ location or REMOTE...CyberPermanent employmentTemporary workWork experience placementRemote workFlexible hours$130.9k - $154k
...Senior Manager. The individual will be responsible for executing all aspects of audits, providing... ...includes coverage over information and cyber security areas, infrastructure,... ...materials for the Audit Committee and Board of Directors. Validate the effectiveness of...CyberLocal area$87.7k - $164k
Ernst & Young Oman is hiring a Cyber Triage and Forensics Incident Analyst in Phoenix, Arizona. In this senior role, you will lead technical security incident responses and perform digital forensic analysis, coordinating efforts to remediate security incidents. The ideal...Cyber- ...Security Operations Team as a central point of contact for Client Cybersecurity Services and act as a resource for technology related to cloud security controls. They will maintain & support Endpoint Detection & Response of SaaS applications & Cloud infrastructure....Cyber
- Lumifi Cyber, based in Scottsdale, Arizona, is seeking a Senior Security Analyst (L2) to join their SOC team. The role involves triaging alerts, assisting customers with incident responses, and mentoring junior analysts. Candidates should have 3+ years in incident response...Cyber
- ...policies. Research and remains aware of any regulatory changes. Responsible for preparing and submitting required compliance reports (e.g.,... ...scam, please visit the Department of Homeland Security’s Cyber Smart website ( to learn how to report it. #J-18808-Ljbffr Goodwill...CyberLocal areaRemote work
- ...Security Culture and Awareness, Endpoint Protection, DLP, Incident Response. Active member of reviewing/resolving tickets in... ...managing Vulnerability Management, Log Centralization, and Endpoint Detection and Response technologies and processes. ~ Energized with strong...CyberContract work
- ...assessments, and offers of employment. Essential Duties and Responsibilities: Leads a team of Retail and/or Warehouse Recruiters to continuously... ...scam, please visit the Department of Homeland Security’s Cyber Smart website ( to learn how to report it. Seniority level...CyberFull timeLocal areaRemote work
$68 per hour
...respect, integrity, and a belief that our responsibility is to help people make smart investment... ...As the Cybersecurity Engineer, you'll detect threats and protect organizational assets... ...challenges, and collaborate closely with the Cyber Operations team. In addition to an...CyberHourly payContract workFor contractors$40 per hour
...in the US, Canada, UK, Ireland, Australia, and New Zealand Responsibilities Evaluate AI-generated cybersecurity content, including threat... ...(e.g., penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or...CyberHourly payFull timePart timeRemote work- ...have a comprehensive understanding of security practices, including 3+ years with Splunk and 2+ years with Qualys, as well as relevant cyber security certifications. The firm is committed to fostering an inclusive workplace where all employees can thrive. #J-18808-Ljbffr...Cyber
$186.9k - $234k
...Rubrik's most critical industry partnerships. As a Global Alliances Director, you will orchestrate a massive cross-functional engine-... ...Operations Company, leads at the intersection of data protection, cyber resilience, and enterprise AI acceleration. Rubrik Security...CyberLocal areaRemote work$68 per hour
...contract basis in Phoenix, AZ. This role involves detecting threats, managing vulnerability projects, and collaborating with the Cyber Operations team. Candidates should possess 5... ...experience, with strong skills in incident response and cloud security. Competitive hourly rate...CyberHourly payContract work- ...Overview of Job Function: The Sr. Director, Technical Delivery ("Sr. Director") is the senior leader responsible for defining, scaling, and optimizing all technical delivery... ...Implement proactive monitoring systems that detect and prevent issues before they impact customer...Local area
$55.7k - $82.1k
...The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity threats targeting mission-critical systems and data. The role performs initial investigations, distinguishes false positives...Contract workWork at officeShift work- ...Information Cyber Security Analyst (Security Operations Center) We are seeking an Information Cyber Security Analyst to... ...self-driven security professional with a passion for threat detection, incident response, and continuous learning. The successful candidate will...CyberShift work
- ...specializing in network visibility, threat detection, and active defense strategies. This... ...protect organizations from real-world cyber threats. The team is looking for someone... ...deeper infrastructure and security responsibilities while being part of a highly technical,...CyberFull timeWork at office
- ...you will be at the forefront of threat detection and responseâ€"analyzing complex network... ...and opportunities to deepen expertise in cyber defense strategies. Here’s what... ...teams to validate alerts and coordinate response efforts Identify vulnerabilities...CyberContract workFlexible hoursShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Cyber Detection & Response. Be the first to apply!
- director lease administration Phoenix, AZ
- erp director Phoenix, AZ
- residence director Phoenix, AZ
- director of foundation relations Phoenix, AZ
- director of benefits Phoenix, AZ
- nonprofit director Phoenix, AZ
- director of video production Phoenix, AZ
- senior director it Phoenix, AZ
- director biotech Phoenix, AZ
- director medical device Phoenix, AZ


