freehire launches on Product Hunt on 26 August.

Follow →

Cyber Defense Manager

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cyber Defense Manager based in Switzerland.

As a Cyber Defense Manager, you will lead and strengthen a resilient security operations capability responsible for protecting a complex digital environment.
You will oversee detection engineering, SOC operations, incident response, and exposure remediation, ensuring threats are identified and contained quickly and effectively.
The role combines hands-on security expertise with people leadership, operational ownership, and continuous improvement.
You will establish strong detection and response practices while using threat intelligence and real-world incidents to strengthen defensive controls.
Working across IT, Platform, Product, GRC, Legal, and business teams, you will coordinate critical incidents and drive remediation of high-impact risks.
You will also build and develop a high-performing Cyber Defense team while providing clear visibility into security performance and risk posture.
This is an opportunity to shape a mature, threat-informed security function in a fully remote European environment.

Accountabilities:

  • Own Cyber Defense operations across SOC activities, detection engineering, incident response, threat detection, and exposure remediation.
  • Lead alert-triage quality, escalation processes, incident command, and coordinated response activities to ensure threats are handled rapidly and effectively.
  • Establish and continuously improve incident response standards, runbooks, playbooks, and operational procedures.
  • Prioritize critical vulnerabilities and security exposures based on asset criticality, exploitability, business impact, and risk.
  • Manage Cyber Defense dashboards, operational metrics, remediation tracking, and follow-up processes to maintain clear visibility into the security posture.
  • Partner with IT, Platform, Product, GRC, Legal, and business stakeholders during security incidents, investigations, and remediation initiatives.
  • Lead and develop the Cyber Defense team, including hiring, onboarding, coaching, mentoring, performance management, and retention of security talent.
  • Improve detection coverage across the environment by designing, validating, tuning, and expanding detection capabilities.
  • Reduce false positives and improve detection quality while maintaining effective coverage against relevant attack scenarios.
  • Use threat intelligence, incident findings, and lessons learned to continuously strengthen detection logic, response playbooks, and security controls.
  • Report on Cyber Defense performance, major incidents, operational metrics, and overall risk posture to security leadership and relevant executive stakeholders.
  • Drive measurable improvements in metrics such as mean time to detect (MTTD), mean time to respond (MTTR), detection coverage, and exposure aging.
  • Requirements:

    • 10+ years of professional experience in Information Security, Cybersecurity, or a closely related discipline.
    • 3+ years of experience in a security management or team-lead position with direct people-management responsibilities.
    • Hands-on experience managing SOC operations, leading incident command, coordinating response activities, and improving MTTD and MTTR.
    • Strong expertise in designing, validating, maintaining, and tuning detection logic across SIEM, EDR, and cloud environments.
    • Deep understanding of security runbook development, alert triage, incident response, and false-positive reduction.
    • Strong knowledge of common attack scenarios, including account takeover, credential theft, privilege escalation, and data exfiltration.
    • Ability to map detection strategies and coverage to threat models such as MITRE ATT&CK.
    • Experience prioritizing vulnerabilities and exposures using CVSS, asset criticality, exploitability, and business impact.
    • Hands-on experience with at least one enterprise SIEM platform such as Splunk, Microsoft Sentinel, Chronicle, or Elastic, as well as SOAR tooling.
    • Understanding of cloud-native security controls and monitoring across AWS, GCP, or Azure environments.
    • Strong knowledge of IAM, PAM, SSO, and identity-related attack vectors relevant to detection and response.
    • Ability to define, track, interpret, and communicate security KPIs and operational dashboards to both technical teams and executive stakeholders.
    • Strong leadership and communication skills, with the ability to coordinate effectively across multiple functions during high-pressure situations.
    • Upper-Intermediate or higher English proficiency.
    • Fluent Ukrainian.
    • Experience in fintech, e-commerce, or other high-risk environments with complex threat landscapes is a strong advantage.
    • Previous hands-on experience as a SOC Analyst, Incident Responder, Detection Engineer, or similar technical security role is desirable.
    • Experience building a SOC or Cyber Defense function from the ground up, or significantly maturing an existing capability, is a plus.
    • Familiarity with threat intelligence platforms and threat-informed defense methodologies is beneficial.
    • Relevant certifications such as CISSP, CISM, GIAC GSOM, GCED, GCIH, or equivalent are advantageous.
    • Benefits:

      • Fully remote working opportunity within Europe.
      • 20 paid vacation days per year.
      • 10 paid sick leave days per year.
      • Paid public holidays according to the approved company holiday calendar.
      • Medical budget to support healthcare needs.
      • Dedicated professional education budget for continuous learning and career development.
      • Language learning budget to support professional and personal development.
      • Wellness budget that can be used toward gym memberships, sports equipment, and related wellbeing expenses.
      • Opportunity to work in a leadership role with significant influence over Cyber Defense strategy, operations, and team development.
      • Exposure to complex security challenges and the opportunity to continuously improve detection, response, and risk-management capabilities.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

What this application asks

lever

Resume/CV, Full name, Email, Phone, Current location, Current company

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available