> Markdown version of [/jobs/ext/2012321-manager-cyber-security-defense](https://www.wearedevelopers.com/jobs/ext/2012321-manager-cyber-security-defense). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Cyber Security Defense - **Company:** TEKSYSTEMS INC. - **Location:** Newport Beach, CA, United States - **Salary:** $181,240.0 - $240,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Computing Platforms, Code Review, Cyber Security, Intrusion Detection and Prevention, Red Team (Cyber Security), Software Engineering, Software Vulnerability Management, Software Security, Information Technology, Cybercrime, Cyber Warfare, Blue Team (Cyber Security), Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 10, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17881750?backUrl=%2Fcareer%2F17881750%2FManager-Cyber-Security-Defense-California-Irvine ## About the Role *Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as CISSP, CISM, OSCP/OSCE, GIAC (GSEC, GCIA, GCIH, GPEN, GXPN) are highly desirable. *Framework Experience: Familiarity with, and prior participation with FIRST (Forum of Incident Response and Security Teams) is preferred. *Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. ## Description TheCyber Security Defense Head of Department (HOD) will lead and mature our organization's end-to-end defensive security capabilities. This leadership role oversees the Security Operations Center (SOC), Blue Team, Red Team, Penetration Testing, Incident Response, Threat & Vulnerability Management (TVM), Application Security, and Adversary Simulation functions. The ideal candidate is both a visionary leader and a seasoned technical expert capable of building high-performing teams, implementing modern security practices, and driving continuous improvement across all cyber defense operations functions. The key responsibilities of this role are as described below: Strategic Leadership & Governance *Develop and execute the Cyber Defense strategy aligned with organizational goals, customer requirements and the evolving threat landscapes. *Establish frameworks, processes, and KPIs for SOC, Incident Response, TVM, AppSec, Red/Blue Teaming, and Adversary Simulation. *Serve as an advisor to the CISO and executive leadership on cyber risks, readiness, and emerging threats. Security Operations & Blue Team Oversight *Oversee 24x7 SOC operations, ensuring effective monitoring, detection, and response to security events, across levels 1-3. *Drive continuous enhancement of detection engineering, threat hunting, and security analytics. *Implement best-in-class security tooling, automation, and operational processes. Adversarial Security: Red Team & Penetration Testing *Lead internal Red Team and offensive security capabilities, including penetration testing. *Define testing methodologies, operational rules of engagement, and reporting standards. *Translate offensive findings into actionable improvements for defensive teams and architecture. Incident Response & Crisis Management *Oversee the Incident Response program, ensuring rapid and effective handling of security incidents. *Lead tabletop exercises, simulation drills, and readiness assessments. *Facilitate and lead high/critical incident responses, when the Incident Response Manager is unavailable. Coordinate with legal, communications, and executive stakeholders during major incidents. Threat & Vulnerability Management (TVM) *Own the enterprise-wide vulnerability management strategy, including prioritization, remediation, and reporting. *Drive continuous scanning, assessment, and metrics to reduce risk across infrastructure, applications, and cloud environments. *Collaborate with engineering and operations teams to ensure timely and effective remediation. *Facilitate and the zero-day vulnerability response process, when the Incident Response Manager is unavailable. Application Security (AppSec) *Lead the organization's AppSec program, including secure SDLC practices, code reviews, SAST/DAST tools, and developer enablement. *Partner with software engineering to embed security into product and platform design. Adversary Simulation & Cyber Readiness *Develop and run adversary simulation programs that mimic real-world threat actors. *Use intelligence-led scenarios to evaluate detection capabilities, response effectiveness, and organizational resilience. *Skills* cybersecurity, SOC, incident response, tvm *Top Skills Details* cybersecurity,SOC,incident response,tvm *Additional Skills & Qualifications* ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)