Global Director of Autonomous Cyber Defense and Security Event Triage (SOC)
$182k - $227kMUFG Bank, Ltd.
Role Overview
The Global Director of Autonomous Cyber Defense and Security Event Triage leads the strategy, execution, and continuous improvement of a 24/7 global cyber defense and security event triage function. The role is accountable for protecting enterprise assets and services by driving outcomes across detection engineering, automated response, incident triage, and threat hunting. The director oversees global cyber operations performance, operating rhythms, and service delivery across multiple environments and partners while owning budget planning and financial stewardship for the function. Additionally, the role advances autonomous defense capabilities by applying AI/ML and LLM‑enabled workflows to improve alert quality, reduce time to detect/respond, and standardize documentation and remediation at scale.
The selected colleague will work at an MUFG office or client site four days per week and have one remote day.
Major Responsibilities
- Direct and mature a 24/7 global cyber operations model for security event monitoring, triage, incident response partnership, and threat hunting across multiple environments.
- Own functional strategy, multi‑year roadmap, and KPI/OKR outcomes for autonomous cyber defense and security event triage (e.g., MTTD/MTTR, false‑positive reduction, containment SLAs).
- Work with the Global Head to define the vision for Autonomous Cyber Defense and Security Event Triage and execute against that vision in alignment with the strategic design.
- Oversee budget planning, vendor management, and financial governance for global cyber operations tooling, services, and staffing; optimize spend to risk reduction and service performance.
- Lead, mentor, and scale high‑performing global teams (employees and partners); define operating rhythms, coverage models, escalation paths, and on‑call expectations.
- Serve as a lead escalation contact in a 24/7 environment; guide appropriate resources to resolution.
- Provide executive‑level oversight for audit, risk, and regulatory engagements related to cyber operations; ensure processes, evidence, and metrics meet policy and compliance requirements.
- Deliver leadership reporting on cyber operations health, emerging threats, and risk posture; translate technical findings into business impact and prioritized actions.
- Drive AI/ML/LLM‑enabled autonomous defense initiatives, including alert enrichment, case summarization, analyst co‑pilots, automated containment, and continuous learning to improve signal‑to‑noise.
- Establish governance for detection engineering, triage decisioning, playbooks, and automation (SOAR/EDR/SIEM) to standardize response, reduce gaps, and improve response times.
- Lead critical incident triage and escalation governance; partner with incident response, infrastructure, identity, and application teams to coordinate containment and recovery.
- Oversee monitoring of third‑party security service providers and managed tooling to ensure coverage, quality, and alignment to enterprise standards and SLAs.
- Build an operations analytics program to measure and continuously improve triage accuracy, response efficiency, backlog health, and automation effectiveness across regions and shifts.
- Sponsor and execute a purple team program (red/blue collaboration) to validate detections and response through adversary emulation aligned to MITRE ATT&CK; track gaps to closure.
- Oversee proactive threat hunting and continuous control validation to identify adversary behaviors, reduce dwell time, and harden critical services.
- Provide global operational leadership during cyber events by coordinating communications, handoffs, and technical execution across regions, functions, and time zones.
- Integrate threat intelligence, vulnerability insights, and attacker TTP research into detection logic, triage guidance, and autonomous response workflows.
- Produce and govern recurring and ad‑hoc reporting on threats, trends, and program performance; ensure consistent narratives and decision support for stakeholders.
- Champion innovation and modernization of cyber defense tooling and techniques, including evaluation and adoption of new capabilities that measurably reduce risk.
- Partner with technology, product, and business leaders to align cyber operations priorities, drive remediation ownership, and embed security‑by‑design practices.
Qualifications
- Bachelor’s degree in Information Technology, Cyber Security, Computer Science, or related discipline or equivalent work experience.
- 7+ years of experience working in Cybersecurity Operations or Information Security.
- Relevant technical and industry certifications, such as CISSP, ISSMP, GCIA, CISM, CEH, GCFA, GCFE, GCIH, or GSEC are preferred.
- Experience in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, or Incident Response and Forensics.
- Experience with information security risk management, including audits, reviews, and risk assessments.
Desired Skills
- Security data collection, analysis and correlation.
- Well‑developed analytic, qualitative, and quantitative reasoning skills.
- Demonstrated creative problem‑solving abilities.
- Security event monitoring, investigation, and overall incident response process.
- Strong time management skills to balance multiple activities and lead junior analysts.
- Understanding of offensive security and common attack methods.
- Ability to pivot across multiple datasets to correlate artifacts for a single security event.
- Knowledge of enterprise detection and response technologies and processes (advanced threat detection tools, intrusion detection/prevention systems, network packet analysis, endpoint detection and response, firewalls, anti‑malware, SIEM). Experienced with EDR, email security, web application firewall, and cloud security tooling.
- Proficiency in risk analysis utilizing logs and other information from various sources.
- Understanding of network protocols, operating systems (Windows, Unix, Linux, macOS, databases), mobile device security, and cyber‑attack types.
- Fundamental understanding of enterprise cybersecurity frameworks such as MITRE ATT&CK and Cyber Kill Chain.
- Experience documenting and explaining technical details in a concise manner.
- Preferred experience with Torq, 7AI, CrowdStrike, Tanium, Snowflake, Splunk, ELK, and scripting/programming.
Education
Bachelor's degree in Computer Science or a closely‑related discipline, or an equivalent combination of formal education and experience.
Remuneration
The typical base pay range for this role is as follows: New York / New Jersey: $182k–227k; Non–New York / New Jersey: $203k–249k, depending on job‑related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance‑based bonus and/or incentive compensation.
Benefits
Our Total Rewards program provides a competitive benefits package that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays.
Visa Sponsorship
Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position.
Equal Employment Opportunity Statement
We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including the San Francisco Fair Chance Ordinance, the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance, and the California Fair Chance Act) to the extent that an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and that they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship, potentially resulting in the withdrawal of a conditional offer of employment, if any. The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of personnel so classified.
We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal, state, or local law.
#J-18808-Ljbffr$182k - $227k
## Global Director of Autonomous Cyber Defense and Security Event Triage (SOC)Applylocations: Tempe, AZ: Jersey City, NJtime type: Full timeposted on: Posted Todayjob requisition id: 10076418-WD**Do you want your voice heard and your actions to count?**Discover your opportunity...CyberWork experience placementWork at officeLocal areaRemote workShift work1 day per week- ...everything we do. L3Harris is the Trusted Disruptor in defense tech. With customers’ mission‑critical needs always... ...solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Associate Mgr., Operations Management...CyberLocal areaShift work
- ...SOC Watch Officer Founded in 1989, SOSi is among... ...integrators in the defense and government services... ...results to enable national security missions worldwide.... ...response to cybersecurity events Oversee incident response... ...activities aligned to cyber defense operations,...CyberContract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
- ...Tangent Technologies LLC is seeking a qualified Security Operations Center (SOC) Tier I Cyber Security Analyst to support the Department of Homeland Security in Chandler, AZ. This entry-level position requires US citizenship and an Active DoD Secret Clearance. Candidates...Cyber
- ...everything we do. L3Harris is the Trusted Disruptor in defense tech. With customers’ mission-critical needs always... ...solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Assembly C Job ID: 240683 Job...CyberLocal area
- ...Harris is the Trusted Disruptor in defense tech. With customers’ mission‑... ...connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title Manager, Supply Chain... ...role will report directly to Director, Supply Chain and is responsible...CyberLocal area
- ...everything we do. L3Harris is the Trusted Disruptor in defense tech. With customers' mission-critical needs always... ...solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Sr. Specialist, Manufacturing...CyberLocal area
- ...Associate Creative Director Gen is a global leader in Cyber Safety and the company behind trusted consumer brands including Norton, Avast, LifeLock, and MoneyLion. Gen reaches approximately 500 million global users across 150+ countries, and Newsweek recognized Gen...Cyber
- ...everything we do. L3Harris is the Trusted Disruptor in defense tech. With customers' mission-critical needs always... ...solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Assembly A Job Code: 41306 Job...CyberWork at officeLocal area
- ...multichannel environmental input sensors to enable intelligent and autonomous applications. EDGE3’s vision analytics software platforms... ...of automobiles, the efficiency of shipping logistics, or the security of one’s home. EDGE3 has an IP portfolio of over 70 awarded and...
- ...are seeking a hands‑on Cyber Incident Response Analyst... ...you will be part of a global team operating in a... ...an externally managed SOC to support escalated investigations... ...platform, lower‑level triage work is handled... ...engineering, infrastructure, and security teams to investigate...CyberPermanent employmentTemporary workWork experience placementFlexible hours
- ...About the Community In addition to a robust calendar of community events, classes, and activities, this award‑winning, master planned... ...Simply put, we create experiences that connect people. Lifestyle Directors work with residents and community partners to create and...Full timeTemporary workWork at officeLocal areaImmediate startLong distanceMonday to FridayFlexible hoursNight shiftWeekend work
- ...Tempe, AZ, is seeking a skilled Cybersecurity Analyst to enhance security operations and respond to incidents. You will monitor security... ...(MDR) partners, and develop processes to handle security events efficiently. Your role includes conducting vulnerability assessments...
$162k
...Director of Business Development.Phoenix, Arizona, United States.TryTuring LLC is... ...more Full-time +1 Associate Director of Events and Engagement, Development.Grand... ...government warehouse server computer security data entry clerk cyber security data entry amazon warehouse...CyberFull timeWork from home$60k - $180k
...capabilities include IT Talent Solutions, Data Delivery & Analytics, Cyber Security, Cloud Migration, Applications and Infrastructure, Software... ..., and Finance & Accounting. M9 Solutions is seeking a SOC Watch Officer to work on-site in support of a government contract...CyberFull timeContract workFor subcontractor- ...billion of assets under management and a global portfolio of more than 400 hotels spanning... ...acres and 50,000 square feet of flexible event space provide a perfect, palm-lined... ...Manager is responsible for assisting the Director of Human Resources with a variety of Human...Hourly payWorldwideFlexible hoursNight shift
- ...history spans over 16 years and today we are an Award-Winning Global Software Consultancy solving complex problems with technology.... ...Development, Data Analytics Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make reasonable accommodations for clients and...Cyber
- ...areas of high-performance computing, artificial intelligence, cyber security as well as non-contact sensing applications. Quantum Computing... ...organization audit and compliance programs (i.e., SOX, PCI, ISO 27001, SOC 2, CMMC, etc.). Duties And Responsibilities IT Security Risk...CyberLocal area
$178.85k - $234.74k
...Hi, we’re Oscar. We’re hiring a Director, Medical Economics to join our Actuarial team.... ...will work as a strategic "quarterback", to triage deep-dive analytics to centralized analytic... ...required in-office day for team meetings and events, while your other two office days are...Full timeWork at officeLocal areaFlexible hours$198k - $368k
...future as we are, join our team. KPMG is currently seeking a Director, Security Compliance to join our Digital Security team.... ...professional services environment specializing in physical and cyber security Bachelor's degree from an accredited college or university...CyberTemporary workH1bLocal area- ...history spans over 13 years and today we are an Award-Winning Global Software Consultancy solving complex problems with technology.... ...Development, Data Analytics Infrastructure & Cloud Solutions, Cyber Security Services etc. We make reasonable accommodations for clients and...CyberContract work
$84k - $131k
...areas of high‑performance computing, artificial intelligence, cyber security, and remote sensing applications. Job Title: IT Administrator... ...Recovery Planning and testing experience. Familiarity with SOC‑2, CIS, CMMC, SOX, or other compliance frameworks. LAN and...CyberFull timeWork at officeRemote work$130k - $135k
...Minimum of 3–5 years of experience in an operational security program. Bachelor’s in computer science,... ...operations, and security initiatives. Background in SOC operations, detection engineering, threat hunting, or cyber threat intelligence. Must be comfortable...CyberFull timeRemote workFlexible hoursShift workWeekend workAfternoon shift- ...history spans over 16 years and today we are an Award-Winning Global Software Consultancy solving complex problems with technology.... ...Development, Data Analytics Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make reasonable accommodations for clients and...Cyber
- Principal Security Engineer - Temporary We are seeking a visionary Principal Security Engineer - Temporary to architect the next generation... ...provisioning and de-provisioning workflows. Partner with the SOC to build ITDR capabilities that detect and automatically...Temporary workRemote workWork from home
- ...seeking a qualified candidate to fulfill a role as a Security Operations Center (SOC) Tier I Cyber Security Analyst supporting the Department of Homeland... ...with experience working with Security Information and Event Management (SIEM) solutions. Familiarity with various...CyberFull timeLocal area
- ...Pipelines Follow the Industry standard data security practices and evangelize the same across... ...years and today we are an Award-Winning Global Software Consultancy solving complex... ...Analytics Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make...CyberLong term contractRemote work
- ...Customer Service Agent Gen is a global company dedicated to powering Digital Freedom... ...heritage is rooted in financial empowerment and cyber safety for the first digital generations,... ...consumers and help them grow, manage and secure their digital and financial lives. We're...CyberFlexible hours
- ...Job Description **Must be a U.S. Citizen** Phoenix Cyber is looking for SOC Analysts to join our client delivery team. This is onsite... ...analyze network traffic, Intrusion Detection Systems (IDS), security events and logs; Prioritize and differentiate between potential...CyberShift workNight shift
$275k - $305k
...Chief Information Security Officer (CISO) is... ..., the Board of Directors, regulators, and external... .... Translate cyber risk into business... ...PCI DSS 4.0, SOC 1/SOC 2, GLBA, FFIEC... ...Experience building a defensible security posture... ...future investment events. ~ Strong...CyberRemote workWork from homeShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Global Director of Autonomous Cyber Defense and Security Event Triage (SOC). Be the first to apply!




