Senior Director - Cyber Defense Engineering
AmerisourceBergen
2d ago
0DevUnited Stateshimalayas
Cyber-DefenseCybersecuritySecurity-EngineeringInformation-SecurityDetection-EngineeringSecurity-Engineering-DirectorDirector-Of-Security-EngineeringDirector
Job Description
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!Job DetailsSummary:The Senior Director of Cyber Defense Architecture & Engineering leads the strategy, design, engineering, and continuous improvement of enterprise detection, response, and threat mitigation capabilities across the enterprise. This role is accountable for building or integrating resilient, intelligence-driven, automated cyber defense platforms spanning endpoint, network, cloud, identity, data, and SaaS environments. This role is responsible for building strong partnerships with technology teams, other corporate support functions, and other Information Security organizations to protect the corporate brand, data, and assets and is responsible for the design, implementation, operation, and maintenance of an information security framework, processes, and systems, that protect the business, services, information and systems against unauthorized use, disclosure, modification, damage, and loss.The position partners closely with the CISO, Cyber Defense Sr. Leadership, other Information Security Sr. Leaders, and other Technology Leadership teams to establish a vision and strategy required to ensure scalable, measurable, and continuously improving defense capabilities across the applicable security domain in collaboration with other information security domain leaders and partner organizations. Our employee experience is a strategic priority for our company. Our leaders are accountable for leading with purpose, fairness, and equity. They are responsible for building and developing diverse teams, maintaining a safe and inclusive environment, setting clear priorities, and holding self and team accountable for executing with excellence.Primary Responsibilities:Define and execute the enterprise cyber defense architecture strategy aligned to threat landscape and risk appetite in collaboration with Cyber Defense senior leadership.Develop layered defense models across endpoint, network, cloud, identity, and SaaS.Establish and document detection engineering standards and reference architectures.Present defense posture maturity, risk trends, and roadmap to executive leadership.Establish the enterprise detection engineering program and lead evaluation of new tools and technologies to support the Cyber Defense ecosystem.Define logging standards and telemetry requirements across platforms.Collaborate & partner with key stakeholder to oversee use case lifecycle management (creation, tuning, retirement).Standardize MITRE ATT&CK mapping across detections.Reduce false positives while increasing true positive detection rates in collaboration with Cyber Defense teams.Oversee or drive a collaborative approach to architecture and engineering of:SIEM platformsSOAR playbooksEDR/XDR solutionsNDR solutionsEmail security and anti-phishing platformsDeception technologiesThreat intelligence platformsSecurity data lakes and analytics platformsIntegrate defense controls across:Public cloud environments (AWS, Azure, GCP)Hybrid data centersSaaS platformsEnterprise networks, endpoints and mobileOT/IoT (in partnership with OT sr. cybersecurity leadership)Additional Responsibilities: Drive automation, AI/ML integration, and policy-as-code for response workflows in collaboration with Cloud Security and other senior security leaders.Enable automated containment and remediation capabilities.Partner with Incident Response and Cyber Counter Adversary leadership for operational efficiency and maturity uplifts.Support purple team exercises to validate detection and response effectiveness.Integrate strategic, tactical, and operational threat intelligence into engineering roadmap.Translate threat actor activity into detection content and control enhancements.Support M&A security integrations and divestiture disentanglement.Ensure compliance with global regulatory regimes (e.g., HIPAA, GDPR, SOX, FDA/GxP where applicable).Establish KPIs, OKRs, and performance dashboards.Establish control validation framework.Lead breach simulation and continuous control monitoring as needed to support Cyber Defense senior leadersReport measurable defense maturity to executive leadership and other senior leaders.Lead global team of detection engineers, platform engineers, and automation specialists.Establish engineering career paths and succession planning.Enterprise financial management and planning experience.Follows information security trends within and outside of work with executive leadership to strategize and recommend changes and updates to company.Qualifications:Education:Master’s Degree in Business Administration, Computer Science, Information Technology or any other related disc
