Senior Director, Global Cyber Detection & Response

Danaher Corporation

Warszawa

Remote

PLN 699,000 - 932,000

Full time

10 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Danaher seeks a Senior Director for Global Cyber Detection & Response to own the strategy, engineering, and operations across cloud, on‑prem, and product environments. You will lead a 24x7 SOC, manage detection engineering, and drive automation and AI adoption to improve threat outcomes.

This remote role requires travel to Danaher sites worldwide and supports Poland as a possible Kraków location. The role partners with CISO and OpCo leaders to govern incident response, security data lakes, and

Qualifications

  • Bachelor's degree and 12+ years in info security with global experience.
  • Experience architecting/modernizing enterprise SIEM (Splunk, Sentinel, Chronicle, Elastic, Panther).
  • Deep expertise in the detection engineering lifecycle and MITRE ATT&CK-aligned use cases.
  • Proven leadership of a 24x7 SOC and incident response across multiple regions.
  • Experience with SOAR, EDR/XDR, cloud security, and modern log pipelines.

Responsibilities

  • Own global Incident Detection & Response program strategy and execution.
  • Lead architecture and operation of enterprise detection ecosystem (SIEM, UEBA, SOAR, EDR/XDR).
  • Oversee telemetry, detection engineering lifecycle, enable detections across environments.
  • Build and mature a 24x7 cyber defense org across regions.
  • Drive AI adoption and automation for detection and response.
  • Govern incident response processes and executive communications.
  • Define cyber defense performance metrics and report to leadership.

Skills

Security operations
Detection engineering
Incident response
SIEM
SOAR
EDR/XDR
Cloud security
MITRE ATT&CK
Leadership
Global teams

Education

Bachelor's degree in Computer Science, Information Security, Engineering, or related field

Tools

Splunk
Microsoft Sentinel
Google Chronicle
Elastic
Panther
Cribl
Kafka

Job description

Bring more to life.

At Danaher, our work saves lives. And each of us plays a part. Fueled by our culture of continuous improvement, we turn ideas into impact — innovating at the speed of life.

Our 60,000+ associates work across the globe at more than 15 unique businesses within life sciences, diagnostics, and biotechnology.

Are you ready to accelerate your potential and make a real difference? At Danaher, you can build an incredible career at a leading science and technology company, where we're committed to hiring and developing from within. You'll thrive in a culture of belonging where you and your unique viewpoint matter.

Learn about the Danaher Business System (https://www.danaher.com/how-we-work/danaher-business-system) which makes everything possible.

The Senior Director, Global Cyber Detection & Response is responsible for building and operating Danaher's global threat detection and incident response capability across our operating company portfolio. This leader owns the strategy, engineering, and day-to-day operations of the enterprise SIEM and detection platform, the detection engineering discipline, the security operations center (SOC), and the incident response function. The role is accountable for how quickly Danaher sees, understands, and stops threats across cloud, on-premises, endpoint, identity, OT/ICS, and product environments.

This position reports to the Chief Information Security Officer (CISO) and is part of the Global Information Security organization, located in Washington, D.C. and will be a remote role, with regular travel required to Danaher operating company and manufacturing locations globally.

Possible locations:

Israel: remote

Poland: Kraków onsite or remote

In this role, you will have the opportunity to:

  • Own Danaher's global Incident Detection & Response program, including strategy, roadmap, execution, and operational effectiveness across cloud, endpoint, identity, network, OT/ICS, and product environments, ensuring rapid threat detection, investigation, containment, eradication, recovery, and continuous improvement.
  • Lead the architecture, implementation, and operation of the enterprise detection ecosystem, including SIEM, security data lake, UEBA, SOAR, EDR/XDR, and related platforms, with accountability for platform strategy, tiering, retention, scalability, telemetry architecture, and cost governance.
  • Own the end-to-end telemetry and detection engineering lifecycle, including log source onboarding, parsing, normalization, data quality monitoring, telemetry controls, MITRE ATT&CK-aligned use case development, detection content engineering, validation, tuning, coverage measurement, and retirement of detections.
  • Build, lead, and continuously mature a global 24x7 cyber defense organization, including SOC analysts, detection engineers, incident responders, threat hunters, and automation engineers across multiple regions and management layers, while driving operational excellence, workforce development, and organizational scalability.
  • Drive adoption of AI, agentic SOC workflows, automation, and threat-informed defense capabilities, integrating threat intelligence, proactive threat hunting, automated enrichment, alert triage, investigation, response orchestration, and advanced detection techniques to improve security outcomes and analyst effectiveness.
  • Establish and govern enterprise incident response and cyber crisis management processes, including executive communications, legal and regulatory coordination, third-party incident response providers, tabletop exercises, audit support, and partnerships with operating company leadership during major incidents.
  • Define, govern, and communicate enterprise cyber defense performance, including MTTD, MTTR, ATT&CK coverage, telemetry health, analyst efficiency, false-positive reduction, backlog management, and overall program effectiveness, while partnering with OpCo CISOs, CIOs, plant leaders, product teams, executive leadership, and audit/risk committees to embed detection and response capabilities across Danaher's global businesses.

The essential requirements of the job include:

  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related field (or equivalent professional experience) and 12+ years of information security experience, including direct ownership of security operations, detection engineering, and/or incident response within a global organization.
  • Demonstrated success standing up, migrating, or modernizing enterprise-scale SIEM environments (e.g., Splunk, Microsoft Sentinel, Google SecOps/Chronicle, Elastic, Panther), including data pipelines, telemetry ingestion, parsing, normalization, and detection content ownership.
  • Deep expertise across the full detection engineering lifecycle, including use case intake, backlog prioritization, MITRE ATT&CK-aligned detection development, correlation and analytic rule authoring, validation, detection-as-code, CI/CD for detections, tuning, and coverage measurement.
  • Proven leadership of a 24x7 Security Operations Center (SOC) and incident response function, including major incident command, executive communications, investigations, and coordination with legal, privacy, compliance, and regulatory stakeholders.
  • Hands-on experience with modern cyber defense technologies, including SOAR and security automation, EDR/XDR, cloud-native detection across AWS, Azure, and GCP, identity threat detection, and modern log pipeline technologies such as Cribl, Kafka, and streaming ETL.
  • Demonstrated ability to lead large-scale information security organizations through multiple layers of management, building and directing globally distributed teams across multiple regions, sites, and business environments.
  • Experience operating within highly complex, multi-country enterprises spanning 50+ countries, with responsibility for delivering consistent cybersecurity capabilities, governance, and operational outcomes across diverse geographic and organizational landscapes.

Travel, Motor Vehicle Record & Physical/Environment Requirements:

  • Ability to travel up to 20-30% of the time, including international travel to Danaher operating company, R&D, SOC, and manufacturing locations globally.

It would be a plus if you also possess previous experience in:

  • Demonstrated accomplishments applying AI and agentic SOC approaches across the log management and detection lifecycle — for example, LLM-assisted alert triage and investigation, agentic hunt and response workflows, natural-language detection authoring, automated parser generation, or AI-driven noise reduction and false-positive suppression, with measurable improvements in MTTD, MTTR, or analyst capacity.
  • Experience building or operating a modern security data lake or federated SIEM architecture that separates hot detection tier from long-term investigative and compliance storage.
  • Experience integrating detection and response across IT and OT/ICS environments, and across connected product / IoT telemetry.
  • Experience within a diversified, multi-business-unit organization operating with a decentralized business model (e.g., Danaher Business System or an equivalent operating system).
  • Professional certification such as CISSP, CISM, GCIA, GCIH, GCFA, or GNFA. Experience presenting to boards, audit committees, or executive risk committees. Join our winning team today. Together, we’ll accelerate the real-life impact of tomorrow’s science and technology. We partner with customers across the globe to help them solve their most complex challenges, architecting solutions that bring the power of science to life. For more information, visit www.danaher.com .
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Director, Global Cyber Detection & Response
Senior Director, Global Cyber Detection & Response

Danaher Corporation • Kraków

Remote
PLN 320,000 - 560,000
Associate SOC Analyst (f/d/m)
Associate SOC Analyst (f/d/m)

Danaher Corporation • Kraków

On-site
PLN 60,000 - 90,000
Global Cyber Defense Director - Remote, 24/7 SOC & IR
Global Cyber Defense Director - Remote, 24/7 SOC & IR

Danaher Corporation • Kraków

Remote
PLN 320,000 - 560,000
Associate SOC Analyst (f/m/d)
Associate SOC Analyst (f/m/d)

Danaher • Kraków

On-site
PLN 60,000 - 100,000
Associate SOC Analyst (f/m/d)
Associate SOC Analyst (f/m/d)

Danaher Corporation • Kraków

Hybrid
PLN 70,000 - 100,000
Senior Global Cyber Defense Director (Remote, 20% Travel)
Senior Global Cyber Defense Director (Remote, 20% Travel)

Danaher Corporation • Warszawa

Remote
PLN 699,000 - 932,000
SOC Analyst (Shift Lead) (f/m/d)
SOC Analyst (Shift Lead) (f/m/d)

Danaher • Poland

On-site
PLN 120,000 - 180,000
Manager, Cybersecurity Automation
Manager, Cybersecurity Automation

Danaher • Kraków

On-site
PLN 220,000 - 360,000
Global Lead, Attack Surface Management (f/m/d)
Global Lead, Attack Surface Management (f/m/d)

Radiometer • Polska

Hybrid
PLN 180,000 - 280,000
Global Lead, Attack Surface Management (f/m/d)
Global Lead, Attack Surface Management (f/m/d)

Danaher Corporation • Warszawa

Remote
PLN 180,000 - 280,000