Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director, Cyber Detection & Response

$135.4k - $208.1k

Cardinal Health

What Cybersecurity Defense contributes to Cardinal Health

Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures to protect our digital assets and infrastructure at Cardinal Health. The Director, Cyber Detection & Response is responsible for establishing, leading, and continuously enhancing cybersecurity detection, monitoring, and incident response capabilities to protect the organization from evolving cyber threats. Furthermore, this leader oversees Security Operations Center (SOC) operations, cyber threat detection, incident response, threat intelligence, and security testing functions to enable rapid identification, containment, and remediation of cybersecurity threats. This role plays a critical role in driving proactive defense strategies, improving detection and response capabilities, and ensuring alignment with risk and resilience objectives.

Location - Open to candidates nationwide working in a fully remote capacity, with preference towards those based in Central or Eastern time zones (willingness to travel into our Corporate HQ in Dublin, OH during certain period of the year is a plus)

Responsibilities

  • Develop and lead the cybersecurity detection and response strategy aligned with enterprise risk, threat landscape, and business priorities.

  • Establish governance frameworks and operating models for SOC, incident response, and threat management functions.

  • Serve as an advisor to leadership on threat trends, detection capabilities, and response readiness.

  • Drive continuous improvement of detection and response capabilities to address evolving threats and business needs.

  • Oversee SOC operations, including security logging, monitoring, alerting, and incident triage across the environment.

  • Oversee effective use of SIEM platforms to analyze correlated events, detect anomalies, and escalate potential incidents.

  • Lead the development and optimization of detection use cases, analytics, and monitoring strategies to improve visibility across the environment.

  • Oversee monitoring capabilities across IT and OT environments, ensuring coverage of critical systems and infrastructure.

  • Lead detection engineering and security tooling functions, including SIEM, SOAR, EDR, UEBA, and DLP capabilities.

  • Oversee the definition and implementation of use cases, rules, and configurations to improve automated detection, investigation, and response workflows.

  • Drive optimization and integration of security tools to enhance operational efficiency and reduce false positives.

  • Establish and lead threat intelligence capabilities to gather, analyze, and operationalize threat data from internal and external sources.

  • Oversee threat monitoring, analysis, and detection rule enhancement to proactively identify emerging threats.

  • Lead threat modeling activities to identify attack vectors, vulnerabilities, and control gaps across systems and processes.

  • Drive proactive threat hunting initiatives to identify hidden threats and indicators of compromise (IoCs) within the environment.

  • Lead enterprise incident response (IR) capabilities, including planning, testing, execution, and continuous improvement of IR processes.

  • Oversee incident response lifecycle activities including detection, triage, containment, eradication, and recovery.

  • Oversee incident response simulations and exercises to validate readiness and improve response effectiveness.

  • Enable effective coordination of incident response efforts across cybersecurity, IT, legal, and business stakeholders.

  • Manage breach notification processes and communication protocols for cybersecurity incidents.

  • Oversee digital forensics and investigative activities to determine the scope, root cause, and impact of cybersecurity incidents.

  • Ensure proper evidence collection, analysis, and documentation to support investigations and regulatory requirements.

  • Lead post-incident reviews and root cause analysis to strengthen detection and response capabilities.

  • Lead offensive and defensive security testing capabilities, including red teaming, penetration testing, and adversarial simulations.

  • Oversee blue team operations to detect, analyze, and respond to threats across enterprise environments.

  • Facilitate purple teaming activities to enhance collaboration between offensive and defensive teams and improve detection and response effectiveness.

  • Drive continuous improvement of security controls through testing, validation, and simulation exercises.

  • Collaborate with cybersecurity, IT, risk, legal, and business teams to integrate detection and response capabilities into enterprise operations.

  • Partner with architecture, engineering, and infrastructure teams to ensure detection and response requirements are embedded into system design and deployment.

  • Provide actionable insights and reporting to leadership on threat landscape, incident trends, and response effectiveness.

  • Support audit and regulatory activities by providing evidence and documentation related to detection and response processes

  • Define and track KPIs and KRIs related to detection, response, and operational performance.

  • Provide regular reporting to leadership on SOC performance, incident metrics, and threat trends.

  • Identify opportunities to enhance detection coverage, reduce response times, and improve operational efficiency.

  • Drive continuous improvement initiatives to mature detection and response capabilities.

  • Build and lead a high-performing cybersecurity detection and response team across SOC, IR, and threat management functions.

  • Develop team capabilities through training, mentoring, and structured career development initiatives.

  • Foster a culture of accountability, collaboration, and continuous improvement.

  • Ensure alignment of team capabilities with evolving threat landscape and organizational needs.

Qualifications

  • Ideally targeting individuals with 10+ years of experience in cybersecurity, with a strong focus on detection, incident response, and security operations.

  • Deep expertise in SOC operations, SIEM, incident response, and threat intelligence a plus.

  • Experience leading cybersecurity operations teams and managing complex incident response activities, a strong preference.

  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF) and regulatory requirements required.

  • Demonstrated ability to communicate technical concepts and risk insights to executive leadership.

  • Strong leadership, analytical, and problem-solving skills.

  • Experience in highly regulated industries, a plus

  • Experience with advanced analytics, automation, and AI-driven security operations, a strong preference

#LI-LP

#LI-Remote

Anticipated salary range: $135,400 - $208,100

Bonus eligible: Yes

Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage

  • Paid time off plan

  • Health savings account (HSA)

  • 401k savings plan

  • Access to wages before pay day with myFlexPay

  • Flexible spending accounts (FSAs)

  • Short- and long-term disability coverage

  • Work-Life resources

  • Paid parental leave

  • Healthy lifestyle programs

Application window anticipated to close: 07/01/2026 *if interested in opportunity, please submit application as soon as possible.

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click here (

Vacancy posted 7 hours ago
Similar jobs that could be interesting for youBased on the Director, Cyber Detection & Response in Nashville, TN vacancy
  • $135.4k - $208.1k

     ...Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures...  ...at Cardinal Health. The Director, Exposure Management is responsible...  ...management initiatives with broader cyber defense and risk reduction strategies... 
    Cyber
    Temporary work
    Local area
    Immediate start
    Remote work
    Flexible hours

    Cardinal Health

    Nashville, TN
    7 hours ago
  •  ...seeks a Cybersecurity Engineer Architect responsible for leading cybersecurity operations...  ...enabled workflows. The Architect will set detection strategies and control roadmaps while mentoring...  ...in a dynamic environment focused on cyber resiliency and exposure management. #J-1... 
    Cyber

    Memorial Physician Practices

    Nashville, TN
    2 days ago
  •  ..., and alignment. Attendance is expected and fully supported. Responsibilities The Security team’s goal is to identify, measure, manage, mitigate...  ...methodologies Working knowledge of and experience in cyber/security domain Fluency in leveraging AI in daily workflows... 
    Cyber
    Temporary work
    Local area

    Coinbase

    Nashville, TN
    1 day ago
  • Ernst & Young Oman is looking for a Cyber Triage and Forensics Incident Analyst to join their team in Nashville, TN. This senior role...  ...ideal candidate will have a significant background in incident response and computer forensics, alongside proven integrity and... 
    Cyber

    Ernst & Young Oman

    Nashville, TN
    5 days ago
  • $130.9k - $154k

     ...Senior Manager. The individual will be responsible for executing all aspects of audits, providing...  ...includes coverage over information and cyber security areas, infrastructure,...  ...materials for the Audit Committee and Board of Directors. Validate the effectiveness of... 
    Cyber
    Local area

    Coinbase

    Nashville, TN
    3 days ago
  • $20 per hour

     ...Title: Temporary - Cyber Security Analyst POSITION SUMMARY Under the...  ...ESSENTIAL JOB FUNCTIONS/JOB DUTIES AND RESPONSIBILITIES Conduct or coordinate vulnerability...  ...Implement, monitor and maintain preventive and detective controls. Operate, administer and... 
    Cyber
    Hourly pay
    Temporary work
    Flexible hours

    The Tennessee Board of Regents

    Nashville, TN
    5 days ago
  • $186.9k - $234k

     ...Rubrik's most critical industry partnerships. As a Global Alliances Director, you will orchestrate a massive cross-functional engine—...  ...Operations Company, leads at the intersection of data protection, cyber resilience, and enterprise AI acceleration. Rubrik Security... 
    Cyber
    Local area
    Remote work

    Rubrik

    Nashville, TN
    4 days ago
  •  ...The Incident Response Coordinator supports the end-to-end response to IT incidents and service disruptions, helping restore normal operations...  ...Use monitoring/ITSM data to route incidents; engage infra/app/cyber/vendor dependencies. Communications & Handoffs: Provide... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Nashville, TN
    2 days ago
  • $85.26k - $108.61k

     ...acquired from multiple years of experience in cyber security or closely related area....  ...infrastructure. Conducts active threat detection and analysis, creates threat intelligence...  ...# Provide CSIRT support as needed in response to information security related events.... 
    Cyber
    Full time
    Remote work
    Shift work
    Night shift
    Afternoon shift

    Brookdale Hockessin

    Brentwood, TN
    2 days ago
  • Key Responsibilities War‑Room Facilitation: Structure/facilitate major incident bridges; maintain restoration focus; assign actions/owners...  ...Coordinate with Problem, Change, Release, Service Continuity, and SOC/Cyber IR where service impact/security intersects; support PIRs and... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Nashville, TN
    4 days ago
  • $72.7k - $116.6k

     ...A healthcare organization is seeking a Cyber Incident Responder to manage and investigate live security incidents. This role will involve coordinating with cyber defense technicians, analyzing logs for threats, and driving process improvements. The ideal candidate will... 
    Cyber

    Highmark Health

    Nashville, TN
    1 day ago
  • Director of Transaction Fraud Analytics What We Need Corpay is currently looking to hire...  ...grow high-impact analytics function responsible for reducing fraud losses while minimizing...  .... Setting a clear roadmap for detection and decisioning capabilities, including... 
    Temporary work
    Currently hiring
    Work at office
    Local area
    Worldwide
    Flexible hours

    Corpay

    Brentwood, TN
    1 day ago
  • $127.2k - $246.9k

     ...KPMG is currently seeking a Manager, Cyber Assessment (Penetration Testing) to join our Digital Security Group. Responsibilities: Conduct detailed network and web application...  ...red teaming exercises to assess the detection capabilities of our security operations... 
    Cyber
    H1b
    Local area

    KPMG

    Nashville, TN
    1 day ago
  •  ...The Cybersecurity Engineer Architect is responsible for leading supporting cybersecurity operations...  ...enabled workflows, and contributions to cyber resiliency and exposure management. This...  ...cybersecurity defense program setting detection strategy, control roadmaps, and... 
    Cyber
    Shift work
    Night shift

    Memorial Physician Practices

    Nashville, TN
    2 days ago
  • $130k - $232k

     ...Centre (SOC), while also contributing broadly across other cyber security and platform‐related initiatives.This role is suited...  ...hands‐on expertise to daily SOC operations, including incident detection and response, threat monitoring, vulnerability management, and security... 
    Cyber
    Full time
    Work at office
    Immediate start
    Work visa
    Relocation package
    Shift work
    3 days per week

    Philips International

    Nashville, TN
    3 days ago
  •  ...Position Summary The Senior Manager, Cyber Security Engineering for Manufacturing &...  ...strategic improvements. This role is responsible for designing, implementing, and maintaining...  ...(Palo Alto and Fortinet), intrusion detection systems, endpoint protection, cloud security... 
    Cyber
    Temporary work
    Local area

    Bridgestone Americas

    Nashville, TN
    5 days ago
  •  ...Healthcare. Job Summary You will be a Cyber Defender - serving as the last line of...  ...cyber threats, the Senior Threat Response Engineer will be capable of independently...  ...tools and available logs (e.g. - Endpoint Detection and Response (EDR) tools such as Microsoft... 
    Cyber
    Temporary work
    Live in
    Flexible hours

    Mission Hospital

    Nashville, TN
    1 day ago
  •  ...escalated with appropriate urgency and all response actions are documented accurately. This...  ...Ensure users receive initial and annual Cyber Security Awareness training, as well as...  ...individuals Monitor alerts, detections, or other indicators of compromise/attack... 
    Cyber
    Local area

    Software Technology, Inc.

    Nashville, TN
    3 days ago
  • $76.4k - $138.6k

     ...secure products and services, as well as detect and quickly respond to security events...  ...blend risk strategy, digital identity, cyber defense, application security and technology...  ...in the EY digital attack surface. Your responsibilities will include aiding in the assessment... 
    Cyber
    Summer holiday
    Local area
    Flexible hours

    EY

    Nashville, TN
    4 days ago
  • $70.3k

    Job Description At Regions, the Cyber Security Analyst is responsible for analyzing, identifying, and documenting cybersecurity risks. This role requires...  ...forensics, cyber incident response, network intrusion detection, network traffic and packet analysis, penetration... 
    Cyber
    Full time
    Work at office
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work
    3 days per week

    Regions Bank

    Nashville, TN
    5 days ago
  • Director of Technical Account Management, Customer Success Leading DLP AI Cybersecurity Provider | Remote (US) | Full-Time The Mission...  ...“must‑have” DLP policy, you’re the one translating real‑world cyber risk into product reality . Their cybersecurity victories become... 
    Cyber
    Full time
    Remote work
    Work from home
    Sleeping nights
    Flexible hours
    Night shift

    Planet Green Search

    Nashville, TN
    5 days ago
  • $162.35k - $199.85k

     ...build, configure and deploy solutions to detect and react to anomalous model behavior....  ...Security: AWS, GCP 5+ years of experience in Cyber Security; Strong command of security and...  ...only provides an overview of job responsibilities that are subject to change. Universal Music... 
    Cyber
    Summer work
    Immediate start
    Remote work
    Flexible hours

    Tnentertainment

    Nashville, TN
    5 days ago
  • $40 per hour

     ...cybersecurity problems. Candidates should have over 2 years of hands-on experience in areas like penetration testing or incident response. This position is remote, allowing work from various countries, and offers flexible project choices and hourly pay starting at $40... 
    Cyber
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Nashville, TN
    1 day ago
  • $95.4k - $192k

     ...base. These individuals are responsible for supporting the overall MSS...  ...teams, partners/principals and directors of different groups and...  ...cloud and on premise focused on cyber security and IT projects Proven...  ...(GCP) Well known endpoint detection and response technologies such... 
    Cyber
    Temporary work
    Work experience placement
    Internship
    Local area

    RSM US LLP

    Nashville, TN
    2 days ago
  • $85k - $95k

     ...with a primary focus on FedRAMP. Key Responsibilities: Engage directly with clients through...  ...list: Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops) Cybersecurity...  ...) Securing Cisco Networks with Threat Detection Analysis (SCYBER) Target Base Salary... 
    Cyber
    Remote work
    Relocation

    Motorola Solutions

    Nashville, TN
    4 days ago
  • $725 per month

     ...30 days of the date of the posting. Responsibilities The Senior IT Security Engineer is...  ...acquired from multiple years of experience in cyber security or closely related area....  ...infrastructure. Conducts active threat detection and analysis, creates threat... 
    Cyber
    Hourly pay
    Full time
    Temporary work
    Part time
    Flexible hours
    Shift work
    Night shift
    Afternoon shift

    Brookdale Senior Living

    Brentwood, TN
    1 day ago
  •  ...are as smart as you are. This role is responsible for designing, implementing, automating,...  ...security agents/tools, improving detection capabilities, ensuring platform reliability...  ...and public AI and ML/DL systems against cyber threats, adversarial attacks, and data breaches... 
    Cyber
    Immediate start
    Remote work
    Flexible hours

    Ford Motor Company

    Nashville, TN
    3 days ago
  • $94.25k - $215.05k

     ...Description Cybersecurity Engineers are responsible for maintaining our customers security tools...  ...expected to have an understanding of cyber technologies such as endpoint solutions...  ...components Driving continuous improvement of detection accuracy through strategic tuning and... 
    Cyber
    Full time
    Local area

    Capgemini

    Nashville, TN
    5 hours ago
  • $201.37k - $236.9k

     ...in-house Coinbase Internal Audit team is responsible for strategic analysis, risk assessments...  ...in crypto, digital assets, cloud, cyber, AI, data privacy, and operational resilience...  ...execution (e.g., continuous monitoring, anomaly detection, automated evidence retrieval) and... 
    Cyber
    Work at office
    Local area

    Coinbase

    Nashville, TN
    1 day ago
  • Regions Bank is seeking a Cyber Security Group Manager in Nashville, TN, responsible for overseeing daily operations and enforcing cybersecurity controls to protect the bank's assets. Key responsibilities include developing enterprise Cyber Security strategies, managing... 
    Cyber
    Work at office

    Regions Bank

    Nashville, TN
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director, Cyber Detection & Response. Be the first to apply!