Cyber Defense Manager
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cyber Defense Manager based in France.
As a Cyber Defense Manager, you will lead and strengthen a resilient security operations capability responsible for protecting a complex digital environment.
You will oversee detection engineering, SOC operations, incident response, and exposure remediation, ensuring threats are identified and contained quickly and effectively.
The role combines hands-on security expertise with people leadership, operational ownership, and continuous improvement.
You will establish strong detection and response practices while using threat intelligence and real-world incidents to strengthen defensive controls.
Working across IT, Platform, Product, GRC, Legal, and business teams, you will coordinate critical incidents and drive remediation of high-impact risks.
You will also build and develop a high-performing Cyber Defense team while providing clear visibility into security performance and risk posture.
This is an opportunity to shape a mature, threat-informed security function in a fully remote European environment.
Accountabilities:
- Own Cyber Defense operations across SOC activities, detection engineering, incident response, threat detection, and exposure remediation.
- Lead alert-triage quality, escalation processes, incident command, and coordinated response activities to ensure threats are handled rapidly and effectively.
- Establish and continuously improve incident response standards, runbooks, playbooks, and operational procedures.
- Prioritize critical vulnerabilities and security exposures based on asset criticality, exploitability, business impact, and risk.
- Manage Cyber Defense dashboards, operational metrics, remediation tracking, and follow-up processes to maintain clear visibility into the security posture.
- Partner with IT, Platform, Product, GRC, Legal, and business stakeholders during security incidents, investigations, and remediation initiatives.
- Lead and develop the Cyber Defense team, including hiring, onboarding, coaching, mentoring, performance management, and retention of security talent.
- Improve detection coverage across the environment by designing, validating, tuning, and expanding detection capabilities.
- Reduce false positives and improve detection quality while maintaining effective coverage against relevant attack scenarios.
- Use threat intelligence, incident findings, and lessons learned to continuously strengthen detection logic, response playbooks, and security controls.
- Report on Cyber Defense performance, major incidents, operational metrics, and overall risk posture to security leadership and relevant executive stakeholders.
- Drive measurable improvements in metrics such as mean time to detect (MTTD), mean time to respond (MTTR), detection coverage, and exposure aging.
- 10+ years of professional experience in Information Security, Cybersecurity, or a closely related discipline.
- 3+ years of experience in a security management or team-lead position with direct people-management responsibilities.
- Hands-on experience managing SOC operations, leading incident command, coordinating response activities, and improving MTTD and MTTR.
- Strong expertise in designing, validating, maintaining, and tuning detection logic across SIEM, EDR, and cloud environments.
- Deep understanding of security runbook development, alert triage, incident response, and false-positive reduction.
- Strong knowledge of common attack scenarios, including account takeover, credential theft, privilege escalation, and data exfiltration.
- Ability to map detection strategies and coverage to threat models such as MITRE ATT&CK.
- Experience prioritizing vulnerabilities and exposures using CVSS, asset criticality, exploitability, and business impact.
- Hands-on experience with at least one enterprise SIEM platform such as Splunk, Microsoft Sentinel, Chronicle, or Elastic, as well as SOAR tooling.
- Understanding of cloud-native security controls and monitoring across AWS, GCP, or Azure environments.
- Strong knowledge of IAM, PAM, SSO, and identity-related attack vectors relevant to detection and response.
- Ability to define, track, interpret, and communicate security KPIs and operational dashboards to both technical teams and executive stakeholders.
- Strong leadership and communication skills, with the ability to coordinate effectively across multiple functions during high-pressure situations.
- Upper-Intermediate or higher English proficiency.
- Fluent Ukrainian.
- Experience in fintech, e-commerce, or other high-risk environments with complex threat landscapes is a strong advantage.
- Previous hands-on experience as a SOC Analyst, Incident Responder, Detection Engineer, or similar technical security role is desirable.
- Experience building a SOC or Cyber Defense function from the ground up, or significantly maturing an existing capability, is a plus.
- Familiarity with threat intelligence platforms and threat-informed defense methodologies is beneficial.
- Relevant certifications such as CISSP, CISM, GIAC GSOM, GCED, GCIH, or equivalent are advantageous.
- Fully remote working opportunity within Europe.
- 20 paid vacation days per year.
- 10 paid sick leave days per year.
- Paid public holidays according to the approved company holiday calendar.
- Medical budget to support healthcare needs.
- Dedicated professional education budget for continuous learning and career development.
- Language learning budget to support professional and personal development.
- Wellness budget that can be used toward gym memberships, sports equipment, and related wellbeing expenses.
- Opportunity to work in a leadership role with significant influence over Cyber Defense strategy, operations, and team development.
- Exposure to complex security challenges and the opportunity to continuously improve detection, response, and risk-management capabilities.