Security Delivery Lead - Managed Detection & Response
DXC Technology | United Arab Emirates | On-site
DXC Technology is seeking an experienced Security Delivery Lead to lead the delivery and operational performance of cybersecurity services within a large-scale, complex technology environment in the UAE.
The successful candidate will be responsible for ensuring the effective delivery of Managed Detection & Response (MDR), security monitoring, incident response, threat detection, vulnerability management, and associated cybersecurity operational services.
This is a senior cybersecurity delivery role requiring strong experience across security operations, SOC/MDR services, cyber incident management, service governance, stakeholder management, and multi-vendor delivery environments.
Key Responsibilities
Cybersecurity Service Delivery
- Lead the end-to-end delivery of cybersecurity operational services across the assigned environment.
- Ensure cybersecurity services are delivered in accordance with agreed SLAs, KPIs, operational requirements, and quality standards.
- Coordinate delivery across SOC/MDR teams, cybersecurity specialists, infrastructure teams, application teams, vendors, and technology partners.
- Maintain strong operational governance across cybersecurity services.
- Monitor service performance and drive corrective actions where service levels or operational objectives are at risk.
- Ensure effective transition of new cybersecurity capabilities into operational services.
Managed Detection & Response
- Provide delivery leadership across Managed Detection & Response (MDR) services.
- Ensure effective security monitoring, threat detection, investigation, escalation, containment, and response processes.
- Oversee operational performance of SIEM, SOAR, EDR/XDR, NDR, threat intelligence, and associated security monitoring capabilities.
- Ensure security events and alerts are appropriately triaged, investigated, escalated, and resolved.
- Drive continuous improvement of detection and response capabilities.
- Monitor detection coverage and identify opportunities to improve security visibility and response effectiveness.
Security Incident Management
- Provide leadership and coordination during significant cybersecurity incidents.
- Ensure appropriate technical teams, stakeholders, vendors, and partners are mobilized during security incidents.
- Coordinate incident escalation, communication, containment, remediation, and recovery activities.
- Ensure post-incident reviews and root-cause analyses are completed.
- Track remediation and preventive actions through to closure.
- Support cybersecurity incident response exercises and readiness activities.
SOC Operations & Governance
- Provide governance and oversight of SOC and security operations activities.
- Monitor operational metrics including incident volumes, response times, detection performance, SLA achievement, backlog, and remediation status.
- Conduct regular cybersecurity service reviews and operational governance meetings.
- Maintain appropriate operational dashboards, reports, risk registers, and improvement plans.
- Ensure security operational procedures, runbooks, escalation paths, and response processes remain current and effective.
Threat & Vulnerability Management
- Coordinate vulnerability identification, prioritization, remediation, and reporting activities.
- Ensure critical vulnerabilities and security exposures are escalated and remediated within agreed timelines.
- Work with technical teams to ensure vulnerability remediation activities are effectively managed.
- Support integration of threat intelligence into security monitoring and detection activities.
- Identify emerging security risks and operational trends requiring additional controls or remediation.
Stakeholder Management
- Act as a senior cybersecurity delivery interface between DXC Technology, stakeholders, technical teams, and security partners.
- Build trusted relationships with senior stakeholders and technology leaders.
- Communicate cybersecurity service performance, risks, incidents, and improvement initiatives clearly and effectively.
- Translate complex security issues into understandable business impacts and recommended actions.
- Provide executive-level reporting on cybersecurity operational performance where required.
Vendor & Partner Management
- Coordinate cybersecurity service delivery across multiple vendors, partners, and technology providers.
- Monitor vendor performance against agreed service levels, deliverables, and operational commitments.
- Drive accountability for incidents, vulnerabilities, remediation activities, and service improvement actions.
- Manage cross-vendor dependencies and operational issues.
- Ensure effective collaboration across the cybersecurity delivery ecosystem.
Security Service Improvement
- Establish and maintain cybersecurity service improvement plans.
- Analyse operational data, incidents, vulnerabilities, detection gaps, and service performance to identify improvement opportunities.
- Drive automation and optimization across security monitoring, investigation, response, and reporting processes.
- Support improvements to SIEM/SOAR use cases, detection rules, playbooks, and response procedures.
- Track improvement initiatives through to measurable outcomes.
Security, Risk & Compliance
- Ensure cybersecurity services operate in accordance with applicable security policies, standards, governance requirements, and controls.
- Work closely with cybersecurity architecture, engineering, risk, compliance, and technology teams.
- Support security assessments, audits, risk reviews, and remediation activities where required.
- Ensure appropriate operational evidence and documentation are maintained.
Required Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline.
- 10+ years of IT/cybersecurity experience, including significant experience in cybersecurity operations or security service delivery.
- Proven experience as a Security Delivery Lead, Cybersecurity Service Delivery Manager, SOC Manager, Security Operations Lead, MDR Lead, or equivalent.
- Strong experience managing SOC, MDR, security monitoring, detection and response, and cyber incident management services.
- Hands-on understanding of technologies such as SIEM, SOAR, EDR/XDR, NDR, vulnerability management, and threat intelligence platforms.
- Strong knowledge of cybersecurity incident response processes and operational security management.
- Experience managing SLAs, KPIs, service performance, operational governance, and continuous improvement.
- Strong experience working within complex multi-vendor technology environments.
- Experience managing major cybersecurity incidents and coordinating technical response teams.
- Strong stakeholder management and executive communication capabilities.
- Ability to translate technical cybersecurity issues into business risks and operational priorities.
Preferred Experience
- Previous cybersecurity delivery experience in the UAE or wider GCC region.
- Experience delivering large-scale MDR, SOC, or managed cybersecurity services.
- Experience working within complex, business-critical and highly governed enterprise environments.
- Strong knowledge of Microsoft Sentinel, Splunk, QRadar, Microsoft Defender XDR, CrowdStrike, Palo Alto, or comparable cybersecurity technologies.
- Understanding of MITRE ATT&CK, NIST CSF, ISO/IEC 27001, incident response frameworks, and threat-informed defence.
- Experience with security automation, orchestration, detection engineering, and SOC transformation.
- Relevant certifications such as CISSP, CISM, GIAC, Security+, ITIL, CCSP, or equivalent are advantageous.
What We Are Looking For
We are looking for a cybersecurity delivery leader who understands both technology and operations.
The successful candidate should be capable of leading complex security services, coordinating SOC/MDR teams and vendors, managing major cybersecurity incidents, maintaining strong service governance, and continuously improving detection and response capabilities.
This is not purely a cybersecurity architecture or GRC position. The ideal candidate will demonstrate strong experience in operational cybersecurity delivery, MDR/SOC environments, incident response, service performance, stakeholder management, and multi-vendor coordination.