Manager, Cyber Security Defense
TEKsystems · Irvine, CA · 2 wk ago
On-siteFinance$181k–$240k/yrFull-time
About the Role
The Cyber Security Defense Head of Department (HOD) will lead and mature our organization’s end-to-end defensive security capabilities. This leadership role oversees the Security Operations Center (SOC), Blue Team, Red Team, Penetration Testing, Incident Response, Threat & Vulnerability Management (TVM), Application Security, and Adversary Simulation functions. The ideal candidate is both a visionary leader and a seasoned technical expert capable of building high-performing teams, implementing modern security practices, and driving continuous improvement across all cyber defense operations functions.
Responsibilities
- Strategic Leadership & Governance
- Develop and execute the Cyber Defense strategy aligned with organizational goals, customer requirements, and the evolving threat landscapes.
- Establish frameworks, processes, and KPIs for SOC, Incident Response, TVM, AppSec, Red/Blue Teaming, and Adversary Simulation.
- Serve as an advisor to the CISO and executive leadership on cyber risks, readiness, and emerging threats.
- Security Operations & Blue Team Oversight
- Oversee 24x7 SOC operations, ensuring effective monitoring, detection, and response to security events, across levels 1-3.
- Drive continuous enhancement of detection engineering, threat hunting, and security analytics.
- Implement best-in-class security tooling, automation, and operational processes.
- Adversarial Security: Red Team & Penetration Testing
- Lead internal Red Team and offensive security capabilities, including penetration testing.
- Define testing methodologies, operational rules of engagement, and reporting standards.
- Translate offensive findings into actionable improvements for defensive teams and architecture.
- Incident Response & Crisis Management
- Oversee the Incident Response program, ensuring rapid and effective handling of security incidents.
- Lead tabletop exercises, simulation drills, and readiness assessments.
- Facilitate and lead high/critical incident responses when the Incident Response Manager is unavailable.
- Coordinate with legal, communications, and executive stakeholders during major incidents.
- Threat & Vulnerability Management (TVM)
- Own the enterprise-wide vulnerability management strategy, including prioritization, remediation, and reporting.
- Drive continuous scanning, assessment, and metrics to reduce risk across infrastructure, applications, and cloud environments.
- Collaborate with engineering and operations teams to ensure timely and effective remediation.
- Facilitate the zero-day vulnerability response process when the Incident Response Manager is unavailable.
- Application Security (AppSec)
- Lead the organization’s AppSec program, including secure SDLC practices, code reviews, SAST/DAST tools, and developer enablement.
- Partner with software engineering to embed security into product and platform design.
- Adversary Simulation & Cyber Readiness
- Develop and run adversary simulation programs that mimic real-world threat actors.
- Use intelligence-led scenarios to evaluate detection capabilities, response effectiveness, and organizational resilience.
Qualifications
- Expert-level experience in cybersecurity, SOC, incident response, and threat & vulnerability management (TVM).
- Master’s degree in Cybersecurity, Information Technology, Computer Science, or a related discipline is preferred.
- Industry-recognized credentials such as CISSP, CISM, OSCP/OSCE, GIAC (GSEC, GCIA, GCIH, GPEN, GXPN) are highly desirable.
- Familiarity with and prior participation in FIRST (Forum of Incident Response and Security Teams) is preferred.
- Bi-lingual proficiency in English and Korean is preferred to support global coordination and communication.
Pay
The pay range for this position is $181,240.00 - $240,000.00 per year.
Benefits
- Excellent medical benefits.
- Car allowance available.
Schedule
This is a fully onsite position based in Irvine, CA.
Permanent position.