Cyber Instincts AB logo

Interim Cyber Defence Operations Lead

Hiring from
Sweden
Work type
Hybrid
Posted
Is this job info correct?
Show job description

About the assignment

We are looking for an experienced security operations leader to step in as interim Cyber Defence Lead for a global manufacturing company, covering for the regular manager during a planned leave. You will keep security operations running smoothly, lead the response when something serious happens, and strengthen how the team detects and follows up on threats.

  • Location: Stockholm, with remote work possible (up to 100%)

  • Start: 26 October 2026 (we are looking to fill this as soon as possible)

  • End: 31 August 2027

  • Scope: Full time (100%)

  • Working language: English

What you'll be doing

  • Leading and coordinating the security operations function (SOC) day to day

  • Owning incident management and threat follow-up from detection to closure

  • Helping lead P1 and major incidents when needed, sometimes outside office hours

  • Improving mean time to respond and recover (MTTR) and widening monitoring and detection coverage

  • Making sure incidents, threats, vulnerabilities and agreed actions are followed up on time

  • Coordinating with internal teams and external service providers, acting as the subject matter expert

  • Turning technical findings into clear actions and reporting for managers and stakeholders

What we're looking for

  • A strong background in SOC operations, incident response and cyber defence, with experience leading or coordinating a team

  • Hands-on experience with Microsoft Defender XDR, Microsoft Sentinel and Palo Alto (for example Cortex), or comparable enterprise XDR/SIEM platforms

  • Experience with vulnerability management and security monitoring

  • Understanding of modern identity risks, including privileged and non-human identities

  • Strong communication and stakeholder skills, and fluent English

  • A calm, structured and proactive approach under pressure

Nice to have

  • Experience from global or regulated organisations

  • Automation of triage and response

  • Certifications such as GCIH, GCIA or CISSP

Interested? Apply as soon as possible, as we review applications on a rolling basis and the assignment starts shortly.

Similar jobs

Apply for this job