Back to all jobs
C

Cyber Threat Detection & Response Team Lead

Control Risks

United StatesRemote7mo ago
Employment
Full-time
Seniority
Lead

About the role

The Cyber Detection and Response Team Lead will play a pivotal role in building and leading a world-class Detection and Response Team (DART) for a major client of Control Risks. This is a hands-on technical leadership role responsible for standing up the team from the ground up; developing strategy, building capabilities, and leading a team of security professionals to proactively detect, investigate, and respond to cyber threats across the client's environment.

This position works in close partnership with the client's Security Engineering team to ensure detection and response capabilities are deeply integrated into the broader security architecture. The Team Lead provides technical direction and operational oversight on all detection and response matters, ensuring the protection of the client's systems, networks, data, and cloud environments. The role supports a strong first-line ownership model by partnering with technology and business stakeholders to embed security into planning, development, and operational activities.

  • Working closely with client stakeholders and the Security Engineering team, build, manage, and scale a Cyber Detection and Response Team (DART) from the ground up.
  • Define and implement the DART's operational model, including tiered escalation paths, on-call rotations, and coordination protocols with Security Engineering, IT, Legal, Risk, and other business stakeholders.
  • Lead the development of Standard Operating Procedures (SOPs) for detection and response activities, including tooling integration, reporting lines, and out-of-hours incident protocols.
  • Establish and continuously refine incident response playbooks aligned to the MITRE ATT&CK framework and the client's specific threat landscape.
  • Serve as Incident Commander for critical and high-severity cyber security incidents, directing technical response across forensics, network, endpoint, cloud, and identity workstreams.
  • Lead on managing the most severe cyber security incidents, including supporting responders with reporting, executive updates, root cause analysis, and remediation recommendations.
  • Oversee the triage of cyber events, ensuring rapid identification, investigation, containment, and remediation.
  • Lead proactive threat hunting operations to identify potential compromises, undetected adversary activity, and gaps in detection coverage.
  • Integrate threat intelligence into DART workflows and leverage intelligence to inform response and prevention strategies.
  • Team Lead Support
  • Conduct regular check-ins, provide coaching and feedback, manage performance reviews and improvement plans, and support career development with the members of your team.
  • Serve as the main liaison between team members and the ECS program management team, ensuring timely program and personnel updates and controlling quality on client deliverables.
  • With the support of the Talent Acquisition team, participate in hiring processes ensuring team resourcing aligns with client expectations and program needs.
  • Lead onboarding tasks (e.g., joiner tickets, scheduling, equipment, success plans), manage offboarding logistics and leaver tickets, and ensure operational continuity.
  • Manage team schedules, approve PTO, ensure timesheet compliance, and maintain a consistent high-quality service to the client.
  • Working closely with the ECS program management team, align on overall program strategy and priorities to create clear, actionable team deliverables.

Requirements

  • 10+ years of progressive experience in cybersecurity, with significant depth in incident response, detection engineering, SOC operations, or cyber defense.
  • 3+ years in a leadership role managing or building a detection and response, SOC, or incident response team.
  • Deep, hands-on knowledge of incident response, digital forensics, malware analysis, and threat hunting methodologies.
  • Hands-on experience with detection and response technologies including SIEM (e.g., Splunk, Microsoft Sentinel), SOAR, EDR/XDR (e.g., CrowdStrike, SentinelOne), NDR, IDS/IPS, and log management platforms.
  • Strong understanding of the MITRE ATT&CK framework, NIST Cybersecurity Framework (800-61, 800-53), and industry best practices for incident response lifecycle management.
  • Proven experience working in close partnership with Security Engineering teams to develop and tune detection logic, automate response workflows, and harden security architecture.
  • Ability to translate complex technical exploit chains and risks into business-impact narratives for executive leadership (C-Suite, Board-level).
  • Experience building operational processes, escalation frameworks, and playbooks from the ground up.
  • Strong understanding of cloud security (AWS, Azure, GCP) and modern enterprise environments including identity platforms, zero trust architecture, and containerized workloads.
  • Familiarity with threat intelligence platforms (e.g., Recorded Future, OpenCTI, MISP) and integrating CTI into detection and response workflows.
  • Understanding of legal and regulatory frameworks around SOC and incident response activities across multiple jurisdictions.
  • Relevant certifications: CISSP, CISM, GIAC (GCIH, GCFA, GCIA, GSOM), or equivalent.

Benefits

Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarized in the full job offer.

  • Medical Benefits, Prescription Benefits, FSA, Dental Benefits, Vision Benefits, Life and AD&D, Voluntary Life and AD&D, Disability Benefits, Voluntary Benefits, 401 (K) Retirement, Nationwide Pet Insurance, Employee Assistance Program.
  • As an equal opportunities employer, we encourage suitably qualified applicants from a wide range of backgrounds to apply and join us and are fully committed to equal treatment, free from discrimination, of all candidates throughout our recruitment process.

The base salary range for this position is $160,000-185,000 per year. Exact compensation offered may vary depending on job-related knowledge, skills, and experience.

Control Risks is committed to a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age or veteran status. If you require any reasonable adjustments to be made in order to participate fully in the interview process, please let us know and we will be happy to accommodate your needs.

Control Risks participates in the E-Verify program to confirm employment authorization of all newly hired employees. The E-Verify process is completed during new hire onboarding and completion of the Form I-9, Employment Eligibility Verification, at the start of employment. E-Verify is not used as a tool to pre-screen candidates. For more information on E-Verify, please visit www.uscis.gov.

Perks & benefits

  • 401k
  • Vision Insurance
  • Dental Insurance
  • Medical Insurance
  • Paid Time Off

479,000+ hidden jobs like this

Control Risks and thousands of companies post here first — often days before LinkedIn or Indeed. Your first 5 applications are free; go Pro to apply without limits.

Everything Pro unlocks:

  • Unlimited applications — free stops at 5
  • Track every application in one place
  • Apply straight to the source, one click
  • Save & organize roles you love
  • Roles pulled from company boards before the big sites

Weekly

$9.99
$4.99/week

For an active search. Cancel anytime.

Most popular

Monthly

$24.99
$12.99/month

The smart pick. Save 35% vs weekly.

Lifetime

$99
$49.99once

Pay once. Every future feature, forever.