Manager, Cyber Security Defense

TEKSYSTEMS INC.
Newport Beach, CA, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$181,240.0 - $240,000.0
Working hours
Regular working hours
Languages
English, Korean

Tech stack

Software System Penetration Testing Computing Platforms Code Review Cyber Security Intrusion Detection and Prevention Red Team (Cyber Security) Software Engineering Software Vulnerability Management Software Security Information Technology Cybercrime Cyber Warfare
+3 more
Blue Team (Cyber Security) Static Application Security Testing Dynamic Application Security Testing

Job description

TheCyber Security Defense Head of Department (HOD) will lead and mature our organization’s end-to-end defensive security capabilities. This leadership role oversees the Security Operations Center (SOC), Blue Team, Red Team, Penetration Testing, Incident Response, Threat & Vulnerability Management (TVM), Application Security, and Adversary Simulation functions. The ideal candidate is both a visionary leader and a seasoned technical expert capable of building high-performing teams, implementing modern security practices, and driving continuous improvement across all cyber defense operations functions. The key responsibilities of this role are as described below: Strategic Leadership & Governance Develop and execute the Cyber Defense strategy aligned with organizational goals, customer requirements and the evolving threat landscapes. *Establish frameworks, processes, and KPIs for SOC, Incident Response, TVM, AppSec, Red/Blue Teaming, and Adversary Simulation. *Serve as an advisor to the CISO and executive leadership on cyber risks, readiness, and emerging threats. Security Operations & Blue Team Oversight *Oversee 24x7 SOC operations, ensuring effective monitoring, detection, and response to security events, across levels 1-3. *Drive continuous enhancement of detection engineering, threat hunting, and security analytics. *Implement best-in-class security tooling, automation, and operational processes. Adversarial Security: Red Team & Penetration Testing *Lead internal Red Team and offensive security capabilities, including penetration testing. *Define testing methodologies, operational rules of engagement, and reporting standards. *Translate offensive findings into actionable improvements for defensive teams and architecture. Incident Response & Crisis Management *Oversee the Incident Response program, ensuring rapid and effective handling of security incidents. *Lead tabletop exercises, simulation drills, and readiness assessments. *Facilitate and lead high/critical incident responses, when the Incident Response Manager is unavailable. Coordinate with legal, communications, and executive stakeholders during major incidents. Threat & Vulnerability Management (TVM) *Own the enterprise-wide vulnerability management strategy, including prioritization, remediation, and reporting. *Drive continuous scanning, assessment, and metrics to reduce risk across infrastructure, applications, and cloud environments. *Collaborate with engineering and operations teams to ensure timely and effective remediation. *Facilitate and the zero-day vulnerability response process, when the Incident Response Manager is unavailable. Application Security (AppSec) *Lead the organization’s AppSec program, including secure SDLC practices, code reviews, SAST/DAST tools, and developer enablement. *Partner with software engineering to embed security into product and platform design. Adversary Simulation & Cyber Readiness *Develop and run adversary simulation programs that mimic real-world threat actors. *Use intelligence-led scenarios to evaluate detection capabilities, response effectiveness, and organizational resilience. *Skills cybersecurity, SOC, incident response, tvm Top Skills Details cybersecurity,SOC,incident response,tvm Additional Skills & Qualifications

Requirements

*Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as CISSP, CISM, OSCP/OSCE, GIAC (GSEC, GCIA, GCIH, GPEN, GXPN) are highly desirable. *Framework Experience: Familiarity with, and prior participation with FIRST (Forum of Incident Response and Security Teams) is preferred. *Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication.

About the company

We’re partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That’s the power of true partnership. TEKsystems is an Allegis Group company.

The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

About TEKsystems and TEKsystems Global Services

We’re a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We’re a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We’re strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We’re building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.

The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.

Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:05 min

Demonstrating automated defense strategies at prominent cybersecurity conferences

Ben Hopkins +1 · Coffee With Developers

56 sec

The hidden costs of delayed peer code reviews

Tim Gilboy Tim Gilboy

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

Videos

See all

Related articles

See all