Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director, Cyber Detection & Response

$135.4k - $208.1k

Cardinal Health

What Cybersecurity Defense contributes to Cardinal Health

Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures to protect our digital assets and infrastructure at Cardinal Health. The Director, Cyber Detection & Response is responsible for establishing, leading, and continuously enhancing cybersecurity detection, monitoring, and incident response capabilities to protect the organization from evolving cyber threats. Furthermore, this leader oversees Security Operations Center (SOC) operations, cyber threat detection, incident response, threat intelligence, and security testing functions to enable rapid identification, containment, and remediation of cybersecurity threats. This role plays a critical role in driving proactive defense strategies, improving detection and response capabilities, and ensuring alignment with risk and resilience objectives.

Location - Open to candidates nationwide working in a fully remote capacity, with preference towards those based in Central or Eastern time zones (willingness to travel into our Corporate HQ in Dublin, OH during certain period of the year is a plus)

Responsibilities

  • Develop and lead the cybersecurity detection and response strategy aligned with enterprise risk, threat landscape, and business priorities.

  • Establish governance frameworks and operating models for SOC, incident response, and threat management functions.

  • Serve as an advisor to leadership on threat trends, detection capabilities, and response readiness.

  • Drive continuous improvement of detection and response capabilities to address evolving threats and business needs.

  • Oversee SOC operations, including security logging, monitoring, alerting, and incident triage across the environment.

  • Oversee effective use of SIEM platforms to analyze correlated events, detect anomalies, and escalate potential incidents.

  • Lead the development and optimization of detection use cases, analytics, and monitoring strategies to improve visibility across the environment.

  • Oversee monitoring capabilities across IT and OT environments, ensuring coverage of critical systems and infrastructure.

  • Lead detection engineering and security tooling functions, including SIEM, SOAR, EDR, UEBA, and DLP capabilities.

  • Oversee the definition and implementation of use cases, rules, and configurations to improve automated detection, investigation, and response workflows.

  • Drive optimization and integration of security tools to enhance operational efficiency and reduce false positives.

  • Establish and lead threat intelligence capabilities to gather, analyze, and operationalize threat data from internal and external sources.

  • Oversee threat monitoring, analysis, and detection rule enhancement to proactively identify emerging threats.

  • Lead threat modeling activities to identify attack vectors, vulnerabilities, and control gaps across systems and processes.

  • Drive proactive threat hunting initiatives to identify hidden threats and indicators of compromise (IoCs) within the environment.

  • Lead enterprise incident response (IR) capabilities, including planning, testing, execution, and continuous improvement of IR processes.

  • Oversee incident response lifecycle activities including detection, triage, containment, eradication, and recovery.

  • Oversee incident response simulations and exercises to validate readiness and improve response effectiveness.

  • Enable effective coordination of incident response efforts across cybersecurity, IT, legal, and business stakeholders.

  • Manage breach notification processes and communication protocols for cybersecurity incidents.

  • Oversee digital forensics and investigative activities to determine the scope, root cause, and impact of cybersecurity incidents.

  • Ensure proper evidence collection, analysis, and documentation to support investigations and regulatory requirements.

  • Lead post-incident reviews and root cause analysis to strengthen detection and response capabilities.

  • Lead offensive and defensive security testing capabilities, including red teaming, penetration testing, and adversarial simulations.

  • Oversee blue team operations to detect, analyze, and respond to threats across enterprise environments.

  • Facilitate purple teaming activities to enhance collaboration between offensive and defensive teams and improve detection and response effectiveness.

  • Drive continuous improvement of security controls through testing, validation, and simulation exercises.

  • Collaborate with cybersecurity, IT, risk, legal, and business teams to integrate detection and response capabilities into enterprise operations.

  • Partner with architecture, engineering, and infrastructure teams to ensure detection and response requirements are embedded into system design and deployment.

  • Provide actionable insights and reporting to leadership on threat landscape, incident trends, and response effectiveness.

  • Support audit and regulatory activities by providing evidence and documentation related to detection and response processes

  • Define and track KPIs and KRIs related to detection, response, and operational performance.

  • Provide regular reporting to leadership on SOC performance, incident metrics, and threat trends.

  • Identify opportunities to enhance detection coverage, reduce response times, and improve operational efficiency.

  • Drive continuous improvement initiatives to mature detection and response capabilities.

  • Build and lead a high-performing cybersecurity detection and response team across SOC, IR, and threat management functions.

  • Develop team capabilities through training, mentoring, and structured career development initiatives.

  • Foster a culture of accountability, collaboration, and continuous improvement.

  • Ensure alignment of team capabilities with evolving threat landscape and organizational needs.

Qualifications

  • Ideally targeting individuals with 10+ years of experience in cybersecurity, with a strong focus on detection, incident response, and security operations.

  • Deep expertise in SOC operations, SIEM, incident response, and threat intelligence a plus.

  • Experience leading cybersecurity operations teams and managing complex incident response activities, a strong preference.

  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF) and regulatory requirements required.

  • Demonstrated ability to communicate technical concepts and risk insights to executive leadership.

  • Strong leadership, analytical, and problem-solving skills.

  • Experience in highly regulated industries, a plus

  • Experience with advanced analytics, automation, and AI-driven security operations, a strong preference

#LI-LP

#LI-Remote

Anticipated salary range: $135,400 - $208,100

Bonus eligible: Yes

Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage

  • Paid time off plan

  • Health savings account (HSA)

  • 401k savings plan

  • Access to wages before pay day with myFlexPay

  • Flexible spending accounts (FSAs)

  • Short- and long-term disability coverage

  • Work-Life resources

  • Paid parental leave

  • Healthy lifestyle programs

Application window anticipated to close: 07/01/2026 *if interested in opportunity, please submit application as soon as possible.

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click here (

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Director, Cyber Detection & Response in Washington DC vacancy
  •  ...Cyber Incident Responder Detect-Response performs all procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or inadvertent access or destruction. Monitor, evaluate, and maintain systems and procedures to safeguard... 
    Cyber
    Shift work

    IC-CAP, LLC

    Washington DC
    3 days ago
  •  ...Sr. Endpoint Detection & Response (EDR) Tools Engineer Location: Washington DC / Los Angeles / Seattle / NYC Duration: Long-Term Contract...  ..., Data Analytics Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make reasonable accommodations for... 
    Cyber
    Long term contract

    InterSources

    Washington DC
    4 days ago
  • $182k - $202k

     ...security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic,...  ..., respect, and accountability. Senior Security Engineer, Detection and Response Remote Location: Austin TX, Seattle, WA, Washington... 
    Cyber
    Apprenticeship
    Local area
    Remote work
    Flexible hours
    Shift work

    HackerOne

    Washington DC
    3 days ago
  • $314.8k - $359.3k

    Sr. Director, Cyber Technical (Cyber Hunt, Logging and Threat Detection) Cybersecurity is essential to Capital One’s commitment to protect our customers and associates...  ...One, you’ll serve as the Senior Director responsible for threat detection, cyber logging, privacy breach... 
    Cyber
    Local area

    Information Technology Senior Management Forum

    Mc Lean, VA
    4 days ago
  • $314.8k - $359.3k

    Capital One is seeking a Senior Director for Cyber Technical in McLean, VA. You will lead the Threat Detection, Cyber Logging, and Data Security teams, focusing on AI-driven security tools and proactive threat assessment. The ideal candidate has extensive cybersecurity... 
    Cyber

    Information Technology Senior Management Forum

    Mc Lean, VA
    4 days ago
  • $135.4k - $208.1k

     ...Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures...  ...at Cardinal Health. The Director, Exposure Management is responsible...  ...management initiatives with broader cyber defense and risk reduction strategies... 
    Cyber
    Temporary work
    Local area
    Immediate start
    Remote work
    Flexible hours

    Cardinal Health

    Washington DC
    1 day ago
  • A cybersecurity services firm in Washington, D.C. seeks an Incident Response Lead to be the subject matter expert in cybersecurity matters. The role includes leading incident detection and response strategies, coordinating recovery efforts, and advising on security architecture... 
    Cyber

    ShorePoint

    Washington DC
    5 days ago
  •  ...Arlington, Virginia is seeking professionals to manage cyber incidents for U.S. Government clients. Responsibilities include correlating incident data, triaging...  ...cybersecurity incidents, and applying advanced intrusion detection techniques. Candidates must possess U.S.... 
    Cyber

    Limelight Health

    Arlington, VA
    5 days ago
  •  ...Director, Cyber Threat Intelligence (CTI) The Director, Cyber Threat Intelligence (CTI) leads an adversary-focused intelligence...  ...intelligence requirements; and integrates CTI into detection engineering, incident response, vulnerability management, fraud, and executive risk... 
    Cyber
    Shift work

    BNY

    Washington DC
    1 day ago
  • $170.6k - $390k

    Government and Public Sector - Cybersecurity Operations & Threat Detection Response - Senior Manager Location: McLean Other locations: Primary...  ...SIEM and XDR platforms Threat hunting and integration of cyber threat intelligence SIEM and SOAR runbook development and optimization... 
    Cyber
    Summer holiday
    Local area
    Flexible hours

    Ernst & Young Advisory Services Sdn Bhd

    Mc Lean, VA
    3 days ago
  •  ...RiVidium is seeking an Incident Response Analyst to support our planned MODES III...  ...Key Responsibilities Support cyber incident response activities including analysis...  ...Familiarity with security logging, threat detection, response coordination, and post-incident... 
    Cyber
    Full time
    Contract work
    Part time
    Shift work
    Night shift

    Rividium Inc

    Alexandria, VA
    5 days ago
  •  ...Cyber Incident Response Analyst This Department of War enterprise data and analytics program delivers mission-critical capabilities that enable...  ...outcomes. Primary Responsibilities Monitor, detect, analyze, mitigate, and respond to cyber threats across the... 
    Cyber

    Navstar

    Alexandria, VA
    4 days ago
  • $112k - $179k

     ...Senior Detection Engineer Job Locations US-VA-Arlington Requisition ID 2026-165378 Position Category Cyber Security Clearance Secret Responsibilities Peraton is currently seeking an experienced Senior Detection Engineer... 
    Cyber
    Contract work
    Monday to Friday
    Shift work

    Peraton

    Arlington, VA
    3 days ago
  • $150k - $201.6k

     ...for a Senior IT Security Engineer, Threat Response. This position could be based in any of...  ...Conduct advanced threat hunting activities to detect unknown and sophisticated threats that...  ...analysis tools.Experience integrating cyber threat intelligence Into security operations... 
    Cyber
    Temporary work
    Remote work
    Flexible hours

    Orrick

    Washington DC
    1 day ago
  • $172.4k - $360.8k

     ...AFS is seeking an experienced Senior Cyber Engineer/Security Architect to join a mission...  .... Strong experience in anomaly detection and analysis of emerging threats across...  ...at Accenture Federal Services has the responsibility to create and sustain a culture where everyone... 
    Cyber
    Live in
    Work at office
    Local area

    Accenture

    Washington DC
    3 days ago
  • $66.9k - $82.1k

     ...Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment, and recovery of cybersecurity incidents across...  ...service management platforms integrated with SOC and cyber defense functions. Certifications such as ITIL Foundation... 
    Cyber
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Washington DC
    10 days ago
  •  ...The Perks: As recognized members of the Cyber Elite, we work together in partnership to...  ...looking for: We are seeking an Incident Response Lead to serve as the Subject Matter...  ...integration and implementation of incident detection and response strategies. The ideal candidate... 
    Cyber
    Contract work

    ShorePoint

    Washington DC
    4 days ago
  • $104k - $166k

     ...Cyber Incident Response Analyst with OT/ICS/SCADA / Travel & Active TS Job Locations US-VA-Arlington Requisition ID...  ...Experience using SIEM tools for pattern identification, anomaly detection, and trend analysis. Experience analyzing ICS network... 
    Cyber
    Contract work
    Currently hiring
    Shift work
    1 day per week

    Peraton

    Arlington, VA
    3 days ago
  • $60 per hour

     ...searching for a Part-Time Tier 2 Incident Response Analyst (IR) to support a law...  ...triaging alerts, and investigating potential cyber threats. As a SOC team member, you will...  ...implementation, and tuning of the SOC tools detection content and alerting signatures. Accurately... 
    Cyber
    Part time
    Shift work
    Night shift
    Weekend work
    Day shift

    Tyto-Athene

    Washington DC
    3 days ago
  • $100k - $125k

    Incident Response Expert III (Cyber Eviction Analysts) Location: Washington DC Metro Area (On-Site) Citizenship: US only Clearance: Active TS...  ...depth principles Hands‑on skill in host/network intrusion detection Ability to perform event correlation Experience with... 
    Cyber
    Local area
    Immediate start

    ARGO Cyber Systems

    Arlington, VA
    3 days ago
  • cFocus Software seeks a Detection Engineering Lead to join our program supporting the Administrative...  ...capabilities. Research emerging cyber threats, adversary capabilities, attack...  ...(CTI), Cybersecurity Triage, Incident Response, and Blue Team personnel to operationalize... 
    Cyber
    Work at office

    cFocus Software Incorporated

    Washington DC
    5 days ago
  • $80.2k - $111.3k

     ...Position Overview The Cybersecurity Incident Response Engineer, Senior leads complex incident...  ...the organization's ability to prevent, detect, and rapidly respond to sophisticated...  ...management platforms integrated with SOC and cyber defense functions. Certifications such... 
    Cyber
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Washington DC
    3 days ago
  •  ...Senior Cloud Detection Engineer Denver, Colorado;Washington, District of Columbia; Chicago...  ...every connection. We do this by driving Responsible Growth and delivering for our clients,...  ...Cloud Detection Engineer to join our Cyber Security Operations team. The ideal candidate... 
    Cyber
    Work at office
    Shift work
    Day shift

    Bank of America

    Washington DC
    1 day ago
  • $136k - $184k

     ...candidate selected be a US Person. Key job responsibilities - You will query big data...  ...threat behaviors, and develop custom threat detection and threat hunting strategies. - You...  ...developing innovative capabilities to identify cyber threat activities at scale. - Work... 
    Cyber
    Internship
    Flexible hours
    Shift work

    Amazon

    Arlington, VA
    3 days ago
  • $100k - $126.5k

     ...Consulting Associate/Cybersecurity & Incident Response CRA's Forensic Services practice...  ..., which may include ongoing breach detection, threat analysis, incident response and...  ...guidance to clients on the adequacy of cyber security controls in accordance with cybersecurity... 
    Cyber
    Work at office
    Work from home
    3 days per week

    Charles River Associates

    Washington DC
    4 days ago
  •  ...Incident Response Expert / Cyber Eviction Analyst Location: Arlington, VA Must have an active Top Secret Security Clearance Node.Digital...  ...strategies Expertise in host and network intrusion detection, event correlation, and malicious activity analysis Strong... 
    Cyber

    Node.Digital

    Arlington, VA
    8 days ago
  • $115k - $136k

     ...SkyePoint Decisions is seeking an experienced Senior Detection Engineer for our customer's Federal Strategic Cyber Group. This position is located in Rosslyn,...  ..., 8am - 4pm. No hybrid/telework allowed. Responsibilities: Performadvancedcustomdevelopmentand... 
    Cyber
    Contract work
    Remote work
    Monday to Friday

    SkyePoint Decisions

    Arlington, VA
    1 day ago
  • $160k - $190k

     ...Solutions is currently seeking an Incident Response (IR) Tech Lead to provide technical...  ...investigative techniques to defend against complex cyber threats. This role requires hands‑on...  ...and the ability to develop and improve detection and response processes. This role will... 
    Cyber
    Contract work

    Edgewater Federal Solutions, Inc.

    Bethesda, MD
    5 days ago
  • $100.2k - $164.1k

     ...Senior Incident Response Consultant 133254 This role joins SpearTip, the cybersecurity...  ..., unique skill sets, and proven cyber counterintelligence strategies, SpearTip...  ...actors and become the gold standard in detecting zero-day vulnerabilities. In this role you... 
    Cyber
    Full time
    Temporary work
    Apprenticeship
    Local area
    Remote work
    Visa sponsorship
    Flexible hours

    Zurich NA

    Washington DC
    2 days ago
  •  ...Threat Detection Security Engineer Job Description Overview CoStar Group (NASDAQ...  ...work in tandem with CoStar's global cyber threat center team to provide continuous...  ...with work from home on Friday. Responsibilities Own cyber security incidents from... 
    Cyber
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Group

    Arlington, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director, Cyber Detection & Response. Be the first to apply!