Senior Director of Cyber Defense
- Salary
- $221.1K–$367K
- Hiring from
- United States
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
The Senior Director, Cyber Defense is responsible for Entrata’s information security defenses, cyber defense strategy, and incident response program. This role leads the capabilities required to detect, investigate, contain, and recover from security events across Entrata’s technology environment.
The Senior Director partners with leaders across Security, Technology, Engineering, Infrastructure, Product, Compliance, Legal, and Communications to strengthen Entrata’s security posture and operational resilience. This role establishes the processes, technology, communication channels, and cross-functional discipline necessary to respond effectively to cyber threats while ensuring appropriate coverage across regions and time zones.
Responsibilities
Define and execute Entrata’s cyber defense strategy and multi-year operational roadmap aligned with enterprise risk. Serve as Incident Commander for significant security incidents—coordinating technical response, triage, containment, eradication, recovery, and business decisions.
Lead detection, alerting, and investigation across the technology stack. Create and maintain incident response playbooks, runbooks, severity levels, decision rights, regional time-zone handoffs, and escalation paths.
Serve as the frontline executive interface for enterprise clients during active incidents, delivering transparent technical briefings, root-cause analyses (RCAs), and post-incident remediation updates. Partner with Legal, Privacy, Communications, and Customer Success on crisis messaging.
Establish and present strategic cyber metrics, threat assessments, and operational maturity benchmarks to executive leadership, audit committees, and board stakeholders.
Drive continuous maturity across threat detection and response to align with enterprise compliance frameworks, regulatory standards, and third-party audit requirements while making timely, risk-based decisions in high-stress environments.
Proactively leverage approved GenAI tools to automate routine tasks while serving as the "Human-in-the-Loop" to audit outputs, maintain prompt competency, and enforce strict data governance and PII protection protocols.
Minimum Qualifications
Proven track record leading enterprise security operations, incident response, or cyber defense programs.
Expert-level incident command and incident response skills in high-stakes environments.
Demonstrated experience in direct, customer-facing executive engagement and client briefings during high-severity incidents.
Demonstrated background building or maturing SOC/IR organizations within enterprise environments subject to rigorous audit, compliance, and governance controls.
Deep, comprehensive understanding of information security principles, threat vectors, controls, technologies, and operating models.
Exceptional executive-level communication, crisis management, workload prioritization, and decision-making capabilities under pressure.
Preferred Qualifications
Experience leading cyber defense and incident command within multi-tenant, cloud-native SaaS platforms (AWS, Azure, GCP).
Hands-on leadership implementing security automation (SOAR), modern SIEM/XDR analytics, threat intelligence, and proactive threat hunting programs (e.g., MITRE ATT&CK framework).
In-depth familiarity with SOC 2 Type II, ISO 27001, NIST CSF, FedRAMP, GDPR, and CCPA regulatory environments.
Master’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
AI & Operational Fluency
AI Integration: Proactively leverages company-approved GenAI tools to automate routine tasks and accelerate high-value deliverables.
Strategic Oversight: Functions as the "Human-in-the-Loop," taking full accountability for auditing AI outputs for factual accuracy, brand alignment, and the removal of hallucinations.
Data Governance: Adheres strictly to AI security protocols, ensuring no proprietary or Personally Identifiable Information (PII) data is exposed to unauthorized models.
Prompt Competency: Demonstrates the ability to craft clear, context-rich prompts to achieve consistent, high-quality results across various business domains.