Jobs and Careers
MS

Associate Director, Cybersecurity Operations

MSD
United StatesRemotefull_timeVerifiedPosted 12 Nov 2025
💰 $219,700/yr($139,600/yr$219,700/yr)

About the role

Job Description

The ideal candidate for this role will be an experienced incident response analyst with extensive detection development experience across various enterprise technologies.  This individual will be responsible for designing, developing and enhancing threat detection capabilities across the organizations detection platforms while providing incident response experience during critical incidents, and providing mentorship to junior analysts.  The primary focus for this role will be the creation and optimization of threat detection use cases, leveraging advanced tools and techniques to identify and mitigate cyber threats in real time through collaboration with cross-functional teams to ensure that the threat detection solutions align with the organization's security strategy. This position will consider remote work approval for the right candidate.


Essential Responsibilities

  • Design and implement advanced detection architectures across the organization's security landscape, utilizing SIEM, EDR, XDR and cloud security platforms.

  • Lead the development and refinement of complex, high-fidelity detection use cases, custom correlation rules, and detection models tailored to the organization's unique risk profile and threat landscape.

  • Continuously enhance and optimize detection techniques, reducing alert fatigue and improving detection accuracy.

  • Identify and develop improvement initiatives within the Detection and Response team, implementing best practices and optimizing processes to enhance security capabilities.

  • Lead investigations into critical incidents, coordinate containment and eradication activities, and ensure recovery aligns with NIST incident response framework principles.

  • Leverage SOAR platforms to automate triage, enrichment, and response workflows for improved Incident Response efficiency.

  • Utilize AI-based tools such as Agentic AI and Co-pilot to enhance investigation speed, threat hunting, and reporting accuracy.

  • Leverage MDR capabilities to enhance detection and response workflows and streamline investigation prioritization.

  • Use endpoint protection and diagnostic tools such as Microsoft Defender for Endpoint (MDE) and CrowdStrike to conduct forensic analysis and validate root causes.

  • Partner with internal stakeholders, leadership, and external partners to provide situational awareness and actionable recommendations.

  • Support junior analysts through coaching, technical guidance, and knowledge sharing to build overall Incident Response capability and mature the threat detection posture.

Core Competencies

  • Expert understanding of attack lifecycles, network telemetry, endpoint data, and adversarial tactics mapped to MITRE ATT&CK.

  • Proven ability to lead the full incident lifecycle, following NIST best practices from identification through post-incident recovery.

  • Ability to design and optimize automated response workflows in SOAR tools to reduce response time and analyst fatigue.

  • Comfortable integrating AI and machine learning tools into investigative processes to improve detection accuracy and reduce false positives.

  • Understands the business impact of identified threats and aligns response actions to minimize operational risk.

  • Proactively evaluates emerging technologies and integrates them into Incident Response operations.

Technical Knowledge & Skills

  • Experience with SIEM platforms such as Microsoft Sentinel for event correlation and detection engineering.

  • Strong knowledge of SOAR technologies for orchestration and response automation.

  • Familiarity with endpoint detection and response (EDR) tools such as MDE, CrowdStrike and Sysinternals.

  • Working knowledge of AI-powered analysis and automation tools including Agentic AI and Co-pilot.

  • Understanding of key cybersecurity frameworks and standards: NIST Incident Response Framework, MITRE ATT&CK, and ISO 27001.

  • Experience with scrip

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

MSD

View company profile →