Cyber Defense Team Lead

APi Construction Company

New Brighton (MN)

On-site

USD 127,000 - 191,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Comprehensive Insurance coverage
Access to corporate fitness center
401K with employer match
Generous paid time off
Growth opportunities

Job summary

A leading construction service firm is looking for a Cyber Defense Team Lead in New Brighton, MN. This role involves leading the North American cyber defense team, providing technical oversight, and guiding incident responses. Candidates should have strong incident response backgrounds, leadership abilities, and experience with Azure security technologies. The position offers a salary range of $127,000 to $191,000 with opportunities for bonuses and a comprehensive benefits package including insurance and 401K matching.

Qualifications

  • Experience as a Cyber Security Analyst, directly or within an MSSP.
  • Ability to lead and mentor junior analysts.
  • Strong incident response and decision-making skills.

Responsibilities

  • Lead the North America Cyber Defense analysts.
  • Serve as Lead Responder for security incidents.
  • Act as a technical escalation point for analysts.

Skills

Incident response background
Leadership abilities
Clear communication skills
Strong analytical skills
Experience with Azure security stack
Ability to work with MSSP

Tools

Azure Defender
AWS
KQL or equivalent

Job description

Why APi Group?

At APi Group, our enduring purpose is Building Great Leaders®. We grow our people and our business, invest in the safety and well‑being of our teams and communities, and connect through meaningful relationships that fuel progress. With over 500 locations worldwide, we are a global leader in safety and specialty services, driven by entrepreneurial spirit and a commitment to excellence.

Job Title: Cyber Defense Team Lead

The Cyber Defense Team Lead is a key leadership role within our global Cyber Defense Operations function. This position leads our North American cyber defense team, supporting all businesses across the US and Canada while providing day‑to‑day guidance, technical oversight, and clear direction across incident response, security operations, and analyst development.

This role is an excellent opportunity for an experienced Senior Analyst who is ready to step into formal leadership as part of a long‑term progression toward senior security leadership roles, including a potential future CISO path. You will bring strong technical credibility, calm decision‑making, concise communication, and the ability to help shape how our cyber defense capability evolves.

Working closely with colleagues in the UK and France, you will ensure consistent global standards, deliver high‑quality reporting, and drive continuous improvement across our operations.

What You Will Do
  • Team Leadership and People Management. Lead and manage the North America Cyber Defense analysts, providing clear direction, coaching, and day‑to‑1s, development conversations, and performance reviews to build capability and maintain high standards. Foster a confident, collaborative team that delivers consistent operational results.
  • Incident Response Leadership. Serve as Lead Responder for security incidents, providing calm, structured decision‑making under pressure. Lead post‑incident reviews, ensure lessons learned are captured, and coordinate closely with IT, Legal, Audit, and the DPO where required. Oversee the on‑call schedule and ensure high‑quality incident execution across the team.
  • Security Operations and Technical Oversight. Act as the technical escalation point for analysts, providing guidance on complex investigations and ensuring high standards of analysis. Partner with our global MSSP to improve alerting, tuning, and automation, and drive continuous optimization across our security operations. Support alignment with UK and European teams to maintain consistency in processes and outcomes.
  • Metrics, Reporting and Briefing. Own the North America contribution to the global Monthly Security Operations Brief, ensuring data is accurate, timely, and clearly explained. Work closely with international counterparts to ensure a consistent global view of cyber defense performance.
  • NIST Cybersecurity Framework Progress. Support delivery of the organization’s NIST CSF targets. Track assigned actions, monitor progress, and ensure tasks are completed to the required standard. Coordinate remediation work across teams, remove blockers where possible, and provide clear, regular updates to leadership.
  • Business Collaboration. Work closely with colleagues in the UK and France to ensure consistent processes and shared standards across global Cyber Defense Operations. Build strong working relationships with engineering, IT, HR, Legal, Audit, and other stakeholders to support smooth incident response and operational alignment. Represent the North America team in global discussions and help drive coordinated improvements across regions.
Required Skills and Experience
  • Previous experience as a Cyber Security Analyst, either directly within a business or providing a service within an MSSP.
  • Strong incident response background with clear evidence of sound judgment under pressure.
  • Proven ability to lead, mentor or guide junior analysts in day‑to‑day investigations.
  • Clear and concise written and verbal communication skills, with the ability to brief both technical and non‑technical audiences.
  • Ability to act as the technical escalation point for the security analysts for complex cases and operational decisions.
  • Experience with the Azure security stack (Defender, Sentinel, Purview) or comparable technologies such as AWS and other SIEM or SOAR at an advanced level.
  • Ability to work effectively with an MSSP and drive tuning, quality, and workflow improvements.
  • Strong analytical skills with the ability to produce actionable, insight‑driven recommendations.
Highly Advantageous
  • Experience with Azure Security, Microsoft Sentinel, or the broader Microsoft Defender ecosystem.
  • Knowledge of Entra ID, Purview, or related cloud security and governance tools.
  • Familiarity with KQL or equivalent query languages from platforms such as Splunk or Elastic.
  • Relevant certifications such as AZ-500, SC-200, GCIH, GCIA, GCED, or AWS Security credentials.
  • Experience contributing to or leading improvements in incident response processes, automation, or detection engineering.
Personal Attributes
  • Calm and composed under pressure, with the ability to make balanced, evidence‑based decisions.
  • Independent thinker who exercises good judgment and knows when to seek input from others.
  • Clear communicator who can distill complex issues into concise, practical actions.
  • Pragmatic, outcome‑focused, and able to build trust with colleagues across technical and non‑technical teams.
Benefits and Compensation

This role will be based out of our New Brighton office. The pay range is $127,000 - $191,000, depending on job‑related knowledge, skills, and experience. This position is eligible for annual bonus and profit sharing based on company performance in addition to other benefits that support the total well‑being of you and your family.

Some benefits include:

  • Comprehensive Insurance coverage, Medical, Dental, Vision, and more
  • Access to corporate fitness center
  • Wellness Program
  • 401K with employer match
  • Discounted company stock (Employee Stock Purchase Plan)
  • Profit Sharing
  • Generous paid time off
  • Growth opportunities through company sponsored leadership development courses and trainings
EEO Statement

APi Group is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and applicants. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

This position is not eligible for sponsorship.

All offers of employment are expressly contingent upon the satisfactory completion, in accordance with Company policy, of a pre‑employment drug screening and background check.

Equal Opportunity Employer, including disabled and veterans.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defense Team Lead
Cyber Defense Team Lead

APi Group • Minneapolis (MN)

On-site
USD 127,000 - 191,000
Comprehensive insurance coverage
Access to corporate fitness center
401(k) with employer match
+1
Cybersecurity Analyst
Cybersecurity Analyst

TurnPoint Services • Louisville (KY)

On-site
USD 70,000 - 100,000
Lead Cyber Defense Incident Responder TS/SCI
Lead Cyber Defense Incident Responder TS/SCI

S2i2, Inc • Arlington (VA)

On-site
USD 165,000 - 180,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Senior Detection and Response Analyst
Senior Detection and Response Analyst

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

The Nu-Age Group • Orlando (FL)

Hybrid
USD 80,000 - 90,000
15 days paid time off
Medical insurance stipend
Director, DFIR (Remote)
Director, DFIR (Remote)

Surefire Cyber Inc. • Northern (KY)

Hybrid
USD 150,000 - 190,000
Competitive pay
PTO
Medical & dental coverage
+2
Senior Cybersecurity Consultant, Blue Team Lead
Senior Cybersecurity Consultant, Blue Team Lead

Layer8security • Northern (KY)

Hybrid
USD 120,000 - 190,000
Medical insurance
Life insurance
Unlimited vacation
+2
Senior MDR Analyst
Senior MDR Analyst

Blackpoint Cyber • United States

On-site
USD 110,000 - 170,000
Health insurance
Vision insurance
Dental insurance
+2
Manager, MSIAM SOC Engineering
Manager, MSIAM SOC Engineering

Jobs Paloaltonetworks • California (MO)

Hybrid
USD 175,000 - 284,000