Director, Cyber Defense

Genuine Parts

Atlanta (GA)

On-site

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Genuine Parts is seeking a Director of Cyber Defense to lead the enterprise cyber defense function across detection, incident response, threat intelligence, threat hunting, and DFIR. You will direct 24x7 global IT security monitoring for a multi-entity environment and drive AI-enabled security initiatives with human oversight.

You will build and coach a high-performing team, align security operations with regulatory requirements, and report posture to executives and boards.

Qualifications

  • Bachelor’s degree in computer science, information security, or related field; advanced degree a plus.
  • 10+ years of progressive experience in cyber defense or security operations, with 5+ years leading teams.

Responsibilities

  • Own and mature the enterprise cyber defense function across detection, incident response, threat intelligence, threat hunting, and DFIR.
  • Direct 24x7 global IT security monitoring across a multi-tenant environment.
  • Lead AI adoption with agentic cyber defense models and human-in-the-loop controls.
  • Establish governance for AI in cyber defense (model risk, data handling, auditability).
  • Own the enterprise incident response framework, run major incident command, drive post-incident reviews.

Skills

Cyber defense leadership
Incident response
Threat intelligence
Threat hunting
AI/ML in security
Security operations
SIEM/SOAR strategy
Team leadership

Education

Bachelor's degree in CS/InfoSec

Tools

Microsoft Sentinel
Microsoft Defender
Entra ID
SOAR platforms
KQL
Python
PowerShell

Job description

The Position

The Director of Cyber Defense reports to the Chief Information Security Officer and operates within the Office of the CISO. This role owns the full cyber defense mission: threat detection, incident response, threat intelligence, threat hunting, and digital forensics. The Director is accountable for global IT security monitoring across this multi-entity, multi-tenant environment, ensuring consistent visibility, detection coverage, and response readiness regardless of where in the ecosystem a threat emerges. The ideal candidate pairs deep operational cyber defense expertise with a demonstrated record of building teams, transforming operating models, and applying security operations at scale.

Responsibilities
  • Cyber defense leadership: Own and mature the enterprise cyber defense function, spanning detection engineering, incident response, threat intelligence, threat hunting, and DFIR, setting strategy, standards, and operational metrics across the Ecosystem.
  • Global monitoring across a diverse ecosystem: Direct 24x7 global IT security monitoring across a multi-tenant environment serving a diverse ecosystem of companies, including regulated financial entities, ensuring consistent telemetry coverage, detection fidelity, and response SLAs for every entity.
  • Agentic cyber defense: Lead the organization in AI adoption by architecting and delivering an agentic cyber defense model, deploying AI agents for alert enrichment, triage, investigation, detection engineering, and automated response, with clearly defined human-in-the-loop controls, guardrails, and escalation paths.
  • Secure AI: Establish and enforce governance for AI used in cyber defense (model risk, data handling, auditability, and acceptable use), and defend the enterprise's AI estate, including AI gateways, model endpoints, agent frameworks, and AI-enabled SaaS, against emerging threats such as prompt injection, model abuse, and data exfiltration.
  • Incident response: Own the enterprise incident response framework and entity-specific playbooks; lead major incident command, coordinate cross-entity response, and drive post-incident reviews, root cause analysis, and control improvements.
  • Detection and automation engineering: Direct SIEM/SOAR strategy and engineering, driving AI/ML-enhanced detections, behavioral analytics, and intelligent automation to improve signal-to-noise ratio and reduce time to detect and respond.
  • Threat intelligence and hunting: Mature the threat intelligence program with PIR-driven collection and dissemination, and lead proactive, hypothesis-driven threat hunting across the ecosystem.
  • Stakeholder engagement: Partner with entity leadership, IT, engineering, legal, and compliance; represent cyber defense in architecture reviews and risk governance forums; report operational posture and metrics to executive leadership and boards.
  • Team leadership: Build, coach, and retain a high-performing cyber defense team; accurately assess performance, develop talent, and evolve roles as agentic capabilities reshape the operating model.
  • Regulatory alignment: Ensure monitoring and response capabilities satisfy regulatory obligations across the portfolio, including federally regulated banking entities, and support audits, examinations, and legal matters as required.
Requirements

Bachelor’s degree in computer science, Information Security, or a related field; advanced degree a plus. 10+ years of progressive experience in cyber defense or security operations, including 5+ years leading teams, with direct accountability for detection, incident response, and threat intelligence functions. Demonstrated experience applying AI/ML and automation to security operations, and a credible vision for building agentic cyber defense capabilities with appropriate human oversight. Working knowledge of AI security and governance: securing LLM/agentic workloads, AI gateways, and model endpoints, and familiarity with frameworks such as the NIST AI RMF, MITRE ATLAS, and the OWASP Top 10 for LLM Applications. Deep expertise in the Microsoft security ecosystem (Sentinel, Defender suite, Entra ID) and modern SOAR platforms; proficiency with KQL, Python, and PowerShell. Experience running security monitoring at scale in multi-tenant, multi-entity, or shared-services environments; exposure to regulated industries (e.g., OCC/FDIC-supervised banking) strongly preferred. Experience implementing and operationalizing enterprise data classification and protection programs, including sensitivity labeling, data loss prevention, and data security posture management (e.g., Microsoft Purview, DSPM platforms), with the ability to align detection and response priorities to data classification tiers. Strong understanding of data protection controls across cloud and endpoint environments, including encryption, key management, data residency, and insider risk monitoring, and their application in regulated and multi-entity contexts. Strong command of adversary tradecraft and frameworks including MITRE ATT&CK, and experience operationalizing threat intelligence. Possession of, or ability to obtain, professional certifications such as CISSP, CISM, GCIH, GCFA, or equivalent. Strong knowledge of security, regulatory, and control frameworks such as NIST CSF, ISO 27001, CIS, and GDPR. Exceptional communication skills, with the ability to convey security and risk concepts to technical teams, executives, and boards. High level of personal integrity and the ability to professionally handle confidential matters. Strong coaching and team-building skills, with the ability to motivate others through direct and indirect reporting relationships to achieve objectives.

GPC conducts its business without regard to sex, race, creed, color, religion, marital status, national origin, citizenship status, age, pregnancy, sexual orientation, gender identity or expression, genetic information, disability, military status, status as a veteran, or any other protected characteristic. GPC's policy is to recruit, hire, train, promote, assign, transfer and terminate employees based on their own ability, achievement, experience and conduct and other legitimate business reasons.

Since 1928, GPC has set the standards for performance and value for our customers and our stakeholders. Today, we’re proud to say we’re the largest global auto parts network and a leading industrial parts distributor, one that offers rewarding careers that combine small company feel with a global scale. Our strengths are in the relationships we build and the value we deliver by merging local expertise with a global force.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Cyber Defense
Director, Cyber Defense

USA GPC Genuine Parts Company • United States

On-site
USD 180,000 - 240,000
Director, Cyber Defense
Director, Cyber Defense

Genuine Parts Company • Atlanta (GA)

On-site
USD 180,000 - 260,000
Director of Cyber Defense & AI-Driven Incident Response
Director of Cyber Defense & AI-Driven Incident Response

USA GPC Genuine Parts Company • United States

On-site
USD 180,000 - 240,000
VP & Chief Information Security Officer - Global Industrial
VP & Chief Information Security Officer - Global Industrial

Motion • Birmingham (AL), Northern (KY)

On-site
USD 250,000 - 350,000
VP & Chief Information Security Officer - Global Industrial
VP & Chief Information Security Officer - Global Industrial

Motion Industries (MOT) • Alabama

On-site
USD 180,000 - 280,000
Healthcare coverage
401(k)
Tuition reimbursement
+3
IAM Sr Engineer - Global Industrial
IAM Sr Engineer - Global Industrial

Motion • Birmingham (AL)

On-site
USD 90,000 - 150,000
Healthcare coverage
401(k)
Tuition reimbursement
+1
Cyber Operations Engineer (IR) Lead - Global Industrial
Cyber Operations Engineer (IR) Lead - Global Industrial

Genuine Parts Company • Alabama

On-site
USD 110,000 - 165,000
Healthcare coverage
401(k)
Tuition reimbursement
+3
VP & Chief Information Security Officer - Global Industrial
VP & Chief Information Security Officer - Global Industrial

Motion Industries • Birmingham (AL)

On-site
USD 180,000 - 280,000
Cyber Operations Engineer (IR) Lead - Global Industrial
Cyber Operations Engineer (IR) Lead - Global Industrial

Motion • Birmingham (AL)

On-site
USD 90,000 - 135,000
Cyber Operations Engineer (IR) Lead - Global Industrial
Cyber Operations Engineer (IR) Lead - Global Industrial

Motion Industries • Birmingham (AL)

On-site
USD 90,000 - 150,000