cyber defense lead - EMEA
RandstadgroepnlRole Title: Cyber Defense Lead – EMEA
Location: Portugal
Employment Type: Full-time
Role Scope: What This Role Is vs. Is Not
Important Note: This is an Operational Security Leadership & Incident Management role, NOT a hands-on Tier-1 SOC Analyst or Content Engineering role. You will translate global strategy into regional execution, coach a team of 7 engineers, and act as Incident Commander during critical cyber events.
What You Will Achieve
Drive Operational Excellence: Manage the day-to-day operations of the EMEA Cyber Defense Center (CDC) in alignment with global SOC strategies set by the Global Head of Security Operations.
Lead & Mentor: Lead, coach, and balance workloads for a dedicated team of 7 Cyber Defense Engineers.
Ensure 24/7 Global Continuity: Participate in "Follow-the-Sun" shift handovers with counterpart leads in AMER and APAC to maintain uninterrupted global security coverage.
Command Cyber Response: Serve as the regional escalation point and Incident Commander for high-severity cyber events and incident response operations.
Optimize SOC Capabilities: Analyze post-incident outcomes to drive workflow enhancements, detection tuning, and automation across our security stack.
Key Metrics You'll Own
Incident Response Efficiency: Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) across the EMEA region.
Team Performance & Delivery: Resource utilization, development goals, and operational output for 7 direct reports.
Compliance & Governance: Alignment of regional operations with ISO 27001, CIS Controls, NIST CSF, and internal Randstad policies.
Stakeholder Reporting: Delivery of clear, high-impact security posture updates to C-level executives and regional IT leadership.
What You Need to Succeed
Leadership Experience: Proven track record leading and managing SOC/security engineering teams in complex enterprise environments.
Incident Commander Expertise: Strong operational background in threat detection, response, and leading large-scale cyber incident response operations.
Hybrid SOC Knowledge: Experience working with internal teams alongside external MSSP partners (Tier-1 triage).
Security Framework Mastery: Deep familiarity with ISO 27001, NIST CSF, CIS Controls, and MITRE ATT&CK frameworks.
Certifications: CISM, CISSP, GCIH, or equivalent senior security certifications are highly valued.
Language: Professional fluency in English (written and spoken).
Why Join Randstad?
Competitive Compensation: Competitive base salary, variable performance pay, and access to Randstad's Employee Share Purchase Plan.
Flexibility with Intentionality: Hybrid/remote work environment that prioritizes work-life balance and autonomous execution.
Career Growth: Opportunities for continuous skill-building, executive mentorship, and global mobility within the world's leading talent organization.
apply today to join the team:
Reach out to our recruitment business partner, jennifer.roberts@randstadsourceright.co.uk for the full job spec and a confidential discussion