IT Cyber Defense Lead (Hybrid Office Schedule)
- Hiring from
- United States
- Work type
- Hybrid
- Posted
- Oct 3, 2026
AFL manufactures industry-leading fiber optic cable, connectivity and accessories and provides engineering and installation services for some of the largest telecom customers in the world. Our company was founded in 1984 with a single fiber optic cable and today, we manufacture thousands of products, generate an excess of $4B in revenue, and employ approximately 12,000 associates worldwide. At AFL, we recognize that our employees are our greatest asset. We hire and train each individual, investing in them to ensure success in their careers. With a commitment to professional development and growth, let us connect you to your next career opportunity.
What We Offer:
- A hybrid in office schedule for qualifying employees
- Flexible time off policy
- 401K Company match (up to 4% - dollar for dollar)
- Professional development, training, and tuition reimbursement programs
- Excellent medical, dental, vision, and life insurance policy options
- Opportunities for career advancement with an industry leading company!
We are seeking a Cyber Defense Lead to join our global IT organization in Duncan, SC. Under general direction, this role leads security operations covering threat monitoring, investigation, and response across AFL’s global organization. The incumbent owns the security platform stack, governs the managed detection and response provider, and serves as incident commander during high severity events. This role works independently and sets the technical direction for how AFL detects and responds to threats.
Responsibilities
- Own administration, tuning, and roadmap for the endpoint detection, identity protection, and security analytics platform stack, including log source onboarding and telemetry coverage.
- Serve as incident commander for high severity security events. Coordinate technical response, containment decisions, and business communication. Run post-incident reviews and drive corrective actions to closure.
- Govern the managed detection and response provider relationship. Review escalation quality, response times, and handoff accuracy in recurring service reviews.
- Own the agentic triage and case management capability. Define agent scope, guardrails, and human approval gates, and measure autonomous accuracy before expanding autonomy.
- Maintain and improve detection content. Write new detections, tune noisy ones, and map coverage to MITRE ATT&CK to identify and close gaps.
- Develop automation playbooks and API integrations across detection, response, and service management platforms to reduce analyst touch time.
- Operationalize threat intelligence and conduct proactive threat hunts against defined hypotheses.
- Define and report security operations metrics, including mean time to detect, mean time to respond, escalation volume, false positive rate, and detection coverage.
- Build and maintain runbooks, severity criteria, escalation paths, and on-call procedures. Contribute to incident response tabletop exercises and business resiliency planning.
- Partner with Systems, Network, and Application teams on control gaps surfaced during investigations, and support incident documentation for audit, cyber insurance, and customer assessments.
Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity or equivalent work experience required.
- Five or more years in security operations, with three or more in a senior or lead capacity.
- Hands-on administration of an endpoint detection and response platform at enterprise scale. CrowdStrike Falcon preferred.
- Hands-on incident response experience on business-impacting events, including containment, investigation, and post-incident review.
- Query language fluency for security analytics platforms, plus log source onboarding experience.
- Experience building or tuning detection content against production telemetry.
- Working knowledge of MITRE ATT&CK applied to coverage decisions, not just terminology.
- Clear written and verbal communication with technical staff and business leadership.
- One or more of the following certifications preferred but not required: CISSP, CISM, GCIA, GCIH, GCFA, GDAT, GCDA or vendor certifications for the deployed security platforms.
Personal Qualities
- Stays composed under pressure and makes sound containment decisions with incomplete information.
- Takes ownership of problems and follows them to resolution without prompting.
- Validates output from vendors, tools, and automation before acting on it.
- Builds working relationships with both technical and non-technical teams outside the security function.
- Communicates clearly, translating technical findings for engineers and for business leadership.
Working Conditions
- Hybrid schedule based onsite in Duncan, SC.
- Carries on-call responsibility. Requires availability outside standard business hours during active security incidents, which occur without notice and may extend across consecutive days.
- Standard office environment. Occasional access to manufacturing floors where hearing protection and personal protective equipment are required.
- Flexibility travel to AFL domestic and international sites if needed.