Cyber Operate Senior Manager- Detect and Respond
Deloitte US · Arlington Heights +75 · 1d ago
Are you passionate about leading the frontline defense against today's most sophisticated cyber threats – both known and unknown? Do you want to own and evolve an advanced operational threat defense capability, grounded in evidence-based knowledge of the threat landscape, that safeguards client data and is delivered to some of the world's leading organizations – not just as a project, but as an ongoing, mission-critical service? Are you energized by building high-performing teams, driving strategy for a growing service line, and being accountable for the outcomes that keep our clients secure?
If yes, then Deloitte's Cyber Detect and Respond team could be the place for you! Deloitte's Cyber Detect and Respond business is focused on enabling change to expand the scope of threat monitoring and managed Security Operations Center (SOC) services, helping organizations adapt to emerging infrastructural change and deliver lasting impact. Running our industry-leading managed services requires significant expertise, sound business judgment, and strong leadership of diverse, distributed teams.
We collaborate with teams from across our organization to bring the full breadth of Deloitte – its commercial and public sector expertise – to best support our clients. Our aspiration is to be the premier integrated services provider in helping to transform the cyber security services marketplace. Our team is client focused and mission driven. As an Associate Vice President (AVP) in Cyber Detect and Respond, you will own the delivery, strategy, and financial performance of managed SOC engagements, leading teams of managers and analysts – onshore and offshore – to solve some of today's toughest cybersecurity and organizational challenges.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As an AVP, Engineering Managed Services on the Cyber Detect and Respond team, you will be responsible for…
- Lead end-to-end managed Security Operations Center (SOC) delivery for assigned clients, including service-level agreement performance, service quality, protection of sensitive client data, and continuous improvement of detection and response capabilities
- Translate current threat intelligence into detection logic, use cases, response playbooks, and client reporting; expand coverage for known and novel threats through User and Entity Behavior Analytics (UEBA) and anomaly-based detection
- Set and execute roadmaps for Cyber Detect and Respond services, including delivery-model evolution, Security Information and Event Management (SIEM) modernization, cloud migrations, automation, and Security Orchestration, Automation, and Response (SOAR) capabilities
- Lead managers and analysts across onshore and offshore teams; oversee performance, development, escalation management, and complex incident investigation, mitigation, and remediation
- Own engagement financial performance and governance, including margin, utilization, staffing, forecasting, executive reporting, account planning, client relationships, growth opportunities, and Deloitte engagement-management requirements
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to mentor and provide clear guidance to others
The team
- Deloitte’s Cyber Operate team helps complex organizations more confidently pursue their growth, innovation and performance agendas through proactive management of the associated cyber risks. Our professionals provide advisory and implementation services that integrate risk, regulatory, and technology skills to help clients transform their legacy programs into proactive Secure.Vigilant.Resilient.™ cyber risk programs. Join the team developing the future state of cyber risk solutions.
Qualifications
Required:
- 10+ years of experience in security monitoring, security engineering, or security analytics, including experience leading managed Security Operations Center (SOC) or detection and response services
- 10+ years of experience leading cybersecurity managed-services delivery, Security Operations Center operations, or cybersecurity transformation programs with responsibility for client delivery, staffing, financial management, executive reporting, account planning, solution design, proposal development, pricing, or contracting
- Bachelor’s degree in computer science, information systems, information security, mathematics, decision sciences, risk management, mechanical engineering, electrical engineering, or industrial engineering
- Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Experience building or scaling a cybersecurity service-delivery model, including workforce planning across onshore and offshore teams
- Certified Information Systems Security Professional (CISSP), GIAC Certified Intrusion Analyst (GCIA), GIAC Continuous Monitoring Certification (GMON), or Certified Ethical Hacker (CEH) certification
- Experience with one or more of the following technologies: Security Information and Event Management (SIEM), Intrusion Detection Systems/Intrusion Prevention Systems (IDS/IPS), Data Loss Prevention (DLP), proxy platforms, Web Application Firewalls (WAF), Endpoint Detection and Response (EDR), anti-virus tools, sandboxing, network- and host-based firewalls, penetration-testing tools, or technologies used to identify Advanced Persistent Threats (APTs)
- Experience operationalizing threat intelligence by converting evidence-based research on existing and emerging threats into detection content, use cases, and client advisories
- Experience operating on-premises and cloud-based SIEM environments and Security Operations Center processes, including User and Entity Behavior Analytics (UEBA) and Security Orchestration, Automation, and Response (SOAR) capabilities
- Experience applying data-protection practices throughout security detection and investigation activities, and experience investigating network probing/scanning, Distributed Denial-of-Service (DDoS) attacks, and malicious-code activity across network infrastructure devices and protocols
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is 163,400 to 322,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.