Director, Cyber Defense

Kyndryl

Greater London

Hybrid

GBP 150,000 - 210,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Kyndryl seeks a Director, Cyber Defense to lead its 24/7 global security operations across AMER, EMEA, and APAC. You will own the full incident response lifecycle, coordinate with the Incident Commander, and drive threat intelligence into detection coverage and the defensive architecture.

You will set detection-as-code discipline, validate content, and collaborate with SIEM, SOAR, and development teams to continuously improve defenses.

Qualifications

  • 12+ years in cybersecurity operations, incident response, threat intelligence, or SOC leadership.
  • Minimum 5 years in a senior leadership role over a globally distributed team.
  • Experience operationalizing threat intelligence into detection coverage and defensive architecture.
  • Familiarity with detection engineering and continuous validation practices.

Responsibilities

  • Lead 24/7 global security operations through a follow-the-sun model across AMER, EMEA, and APAC.
  • Own the full incident response lifecycle, triage through post-incident review, with forensic preservation standards.
  • Coordinate with the Incident Commander function with escalation authorities, runbooks, and cross-functional protocols for cybersecurity incidents.
  • Direct the Cyber Threat Intelligence program and convert intelligence into detection requirements and defensive changes.
  • Set detection-as-code discipline, version-controlled content, automated testing, and telemetry quality with SIEM/SOAR teams.

Skills

Threat-informed defense
Incident response leadership
Cross-functional collaboration
Automation and ML in security
MITRE ATT&CK

Tools

SIEM/SOAR platforms

Job description

Who We Are

At Kyndryl, we run and reimagine the mission‑critical technology systems that drive advantage for the world’s leading businesses. We are at the heart of progress; with proven expertise and a continuous flow of AI‑powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people—Kyndryls—that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well‑being is prioritized and your potential can thrive.

The Role

The Director, Cyber Defense, leads Kyndryl's operational defense mission across a globally distributed security organization. This role reports to the Vice President and Deputy CISO, Cyber Operations. You will own the full incident response lifecycle, run follow‑the‑sun security operations across AMER, EMEA, and APAC, direct the cyber threat intelligence program, and drive the conversion of that intelligence into the detection coverage and defensive architecture that protect Kyndryl's global enterprise estate. You will set the engineering discipline that keeps detection content tested, version‑controlled, and continuously validated against the adversary. During major security incidents, you will exercise cross‑functional coordination authority to drive rapid, disciplined response. The window between vulnerability and exploit is compressing as adversaries adopt AI‑accelerated tooling. This role exists to keep Kyndryl's defense ahead of that curve.

What You'll Do

Lead 24/7 global security operations through a follow‑the‑sun model spanning AMER, EMEA, and APAC regions. Own the full incident response lifecycle, triage through post‑incident review, with forensic preservation standards maintained throughout. Coordinate with the Incident Commander function with clear escalation authorities, runbooks, and cross‑functional coordination protocols for cybersecurity incidents. Direct the Cyber Threat Intelligence program and own the intelligence‑to‑defense loop: convert prioritized adversary intelligence into detection requirements, control coverage decisions, and changes to the defensive architecture. Govern ATT&CK‑aligned detection coverage on measured efficacy, and stand up continuous validation through adversary emulation and detection testing to prove that intelligence‑driven defenses fire against the techniques they target. Set detection‑as‑code discipline across the detection lifecycle: version‑controlled content, release rigor, automated testing, and telemetry quality standards, executed jointly with the SIEM, SOAR, & Agent Development team that owns the underlying pipeline and platform. Drive operational measurement toward compressing the defender's detect‑decide‑act cycle against AI‑accelerated adversaries, not raw response speed alone. Coordinate with Vulnerability Management on remediation prioritization and exploitability‑informed sequencing. This role does not own the vulnerability management function. Collaborate with the AI‑Driven Cyber Defense team to integrate automation and ML into defensive operations. Build and develop a globally diverse team, investing in their growth across technical, analytical, and leadership competencies.

What You Bring

Proven ability to lead security operations and incident response at enterprise scale, with the composure and decision quality to perform under pressure. Strong command of threat‑informed defense: translating intelligence into detection coverage and architecture decisions, anchored in MITRE ATT&CK, with kill chain analysis as a supporting lens for mapping attacker progression. Working command of detection engineering practice: detection‑as‑code, content lifecycle management, and validation discipline, partnering with platform engineering rather than operating in isolation from it. Strong command of incident response methodologies and escalation processes. A leadership style that builds operational discipline without stifling initiative. You want your team thinking, not just executing. Experience running geographically distributed teams with the cultural awareness that global operations demand. The ability to communicate effectively with technical teams and executive leadership alike.

Who You Are Requirements

12+ years in cybersecurity operations, incident response, threat intelligence, or SOC leadership, with at least 5 years in a senior leadership role over a globally distributed team. Demonstrated track record leading a cyber defense or security operations program at comparable scale and complexity, defending a hybrid or multi‑cloud enterprise estate. Experience operationalizing threat intelligence into detection coverage and defensive architecture, with familiarity in detection engineering and continuous validation practice. Dedication to continuous learning through a combination of self‑directed, certification, military, and formal education sources.

Being You

At Kyndryl, we focus on ensuring all Kyndryls feel included and we welcome people of all cultures, backgrounds, and experiences. Even if you don’t meet every requirement, we encourage you to apply. We believe in growth, and we’re excited to see what you can bring. At Kyndryl, employee feedback has told us that our number one driver of employee engagement is belonging. That sense of belonging — being a valued, respected, trusted member of the team — is fundamental to our culture and fueling great experiences for our customers. This dedication to welcoming everyone into our company means that Kyndryl gives you the ability to thrive and contribute to our culture of empathy and shared success. That’s The Kyndryl Way.

What You Can Expect

Your career with us isn’t just a job—it’s an adventure with purpose. We offer a dynamic, hybrid‑friendly culture that supports your well‑being and empowers you to grow. Our Be Well programs are thoughtfully designed to support your financial, mental, physical, and social health‑because we know that when you feel your best, you do your best. From your very first day, you’ll dive into impactful work that powers the systems our customers rely on every day. You won’t just contribute—you’ll make a difference, tackling meaningful projects that sharpen your skills and fuel your growth. We’re here to champion your journey. With powerful tools to chart your career path, personalized development goals aligned with your ambitions, and continuous feedback to keep you inspired and on track, you’ll have everything you need to thrive and evolve. You’ll develop in-demand skills to grow your career and achieve your ambitions with access to cutting‑edge learning opportunities—From certifications with Microsoft, Google, and Amazon to coaching and hands‑on experiences. And through it all, you’ll be part of a culture that values empathy, restless learning, and a devotion to shared success. We want you to thrive here—and we’re committed to helping you do just that.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Kyndryl Consult Partner - Insurance
Kyndryl Consult Partner - Insurance

Kyndryl • Greater London

On-site
GBP 120,000 - 180,000
Forward Deployed Engineer - Lead Platform Engineer
Forward Deployed Engineer - Lead Platform Engineer

Kyndryl Inc. • Greater London

Hybrid
GBP 90,000 - 130,000
Kyndryl Consult Partner - Public Sector
Kyndryl Consult Partner - Public Sector

Kyndryl Inc. • Greater London

Hybrid
GBP 150,000 - 210,000
Associate Director - AI Innovation Lab, Human-centered Design
Associate Director - AI Innovation Lab, Human-centered Design

Kyndryl • Liverpool

Hybrid
GBP 90,000 - 150,000
Associate Director, HR Mergers & Acquisitions
Associate Director, HR Mergers & Acquisitions

Kyndryl Inc. • Warwick

Hybrid
GBP 110,000 - 150,000
Global Cyber Defense Director — 24/7 Incident Response Lead
Global Cyber Defense Director — 24/7 Incident Response Lead

Kyndryl • Greater London

Hybrid
GBP 150,000 - 210,000
DevOps / Openshift Engineer
DevOps / Openshift Engineer

Kyndryl Inc. • United Kingdom

Hybrid
GBP 60,000 - 90,000
Foundation Solution Architect - Apple Devices & macOS (Tenant-to-Tenant Migration)
Foundation Solution Architect - Apple Devices & macOS (Tenant-to-Tenant Migration)

Kyndryl • Greater London

Hybrid
GBP 110,000 - 150,000
Application Architect - VA DMV
Application Architect - VA DMV

Kyndryl • Greater London

On-site
GBP 90,000 - 130,000
Director of Cyber Security
Director of Cyber Security

0026 Checkout Technology Ltd • Greater London

Hybrid
GBP 90,000 - 130,000