Director of Cyber Defense (AI-Focused)
Gotham Technology Group · Irving, TX
Apply & track with Apply EdgeOur client is a growing, multi-entity organization that provides shared IT, security, and corporate services across a diverse portfolio of operating companies in financial services and technology. They are hiring a Director of Cyber Defense to lead their security operations function and build out a modern, AI-driven cyber defense program.This role reports directly to the CISO and owns the full cyber defense mission: threat detection, incident response, threat intelligence, and digital forensics, delivered across a multi-entity, multi-tenant environment that includes regulated financial companies.This is not a role for someone who just wants to run existing playbooks. The organization is bringing its SOC in-house, rolling out Microsoft Sentinel across the business, and actively building agentic AI capabilities into how it detects, triages, and responds to threats. They need a leader who can take an idea, sit down with engineers, build a prototype, test whether it actually works, and push it into production. Candidates who are strong on AI strategy but light on hands-on building are not a fit for this particular seat.What You'll DoOwn and mature the cyber defense function: detection engineering, incident response, threat intelligence, threat hunting, and digital forensics, across a multi-entity environment that includes regulated financial companiesLead the transition from an outsourced SOC to an internal one, building the team and the operating model along the wayDesign and deploy agentic AI capabilities for alert triage, investigation, and response, with real human oversight built in, not a chatbot bolted onto existing toolsGuide the organization's Microsoft Sentinel rollout and ensure it fits into a broader security architecture spanning Azure, Defender, and Entra IDSet governance for how AI is used in security operations, including data handling and acceptable useOwn incident response across the portfolio, including major incident command and post-incident reviewsBuild out the threat intelligence and proactive threat hunting programRepresent cyber defense to entity leadership, legal, compliance, and the boardBuild, coach, and grow a high-performing team as the SOC evolvesWhat You Bring10+ years in cyber defense or security operations, including at least 5 years leading teamsA track record of actually building or transforming a SOC, not just managing one that already existedReal, hands-on experience applying AI or automation to security operations; able to speak to something specific you built, not just a vision for where AI is headedDeep knowledge of the Microsoft security ecosystem (Sentinel, Defender, Entra ID); strong Splunk-based SOC/SIEM backgrounds will also be consideredExperience running security monitoring across multiple business units, entities, or a shared-services model; regulated industry experience (e.g., banking) is a plusStrong grasp of adversary tradecraft (MITRE ATT&CK) and modern SOAR platformsCISSP, CISM, GCIH, GCFA, or a similar certification (or the ability to obtain one)Comfortable communicating security posture and risk to both technical teams and executive leadership