Skip to content

Senior Director, Global Cyber Detection & Response

Pall Corporation

ISR RemoteRemote

Bring more to life.

At Danaher, our work saves lives. And each of us plays a part. Fueled by our culture of continuous improvement, we turn ideas into impact — innovating at the speed of life.

Our 60,000+ associates work across the globe at more than 15 unique businesses within life sciences, diagnostics, and biotechnology.

Are you ready to accelerate your potential and make a real difference? At Danaher, you can build an incredible career at a leading science and technology company, where we're committed to hiring and developing from within. You'll thrive in a culture of belonging where you and your unique viewpoint matter.

Learn about the Danaher Business System which makes everything possible.

The Senior Director, Global Cyber Detection & Response is responsible for building and operating Danaher's global threat detection and incident response capability across our operating company portfolio. This leader owns the strategy, engineering, and day-to-day operations of the enterprise SIEM and detection platform, the detection engineering discipline, the security operations center (SOC), and the incident response function. The role is accountable for how quickly Danaher sees, understands, and stops threats across cloud, on-premises, endpoint, identity, OT/ICS, and product environments.

This position reports to the Chief Information Security Officer (CISO) and is part of the Global Information Security organization, located in Washington, D.C. and will be a remote role, with regular travel required to Danaher operating company and manufacturing locations globally.

Possible locations:

Israel: remote

Poland: Kraków onsite or remote

In this role, you will have the opportunity to:

  • Own Danaher's global Incident Detection & Response program, including strategy, roadmap, execution, and operational effectiveness across cloud, endpoint, identity, network, OT/ICS, and product environments, ensuring rapid threat detection, investigation, containment, eradication, recovery, and continuous improvement.
  • Lead the architecture, implementation, and operation of the enterprise detection ecosystem, including SIEM, security data lake, UEBA, SOAR, EDR/XDR, and related platforms, with accountability for platform strategy, tiering, retention, scalability, telemetry architecture, and cost governance.
  • Own the end-to-end telemetry and detection engineering lifecycle, including log source onboarding, parsing, normalization, data quality monitoring, telemetry controls, MITRE ATT&CK-aligned use case development, detection content engineering, validation, tuning, coverage measurement, and retirement of detections.
  • Build, lead, and continuously mature a global 24x7 cyber defense organization, including SOC analysts, detection engineers, incident responders, threat hunters, and automation engineers across multiple regions and management layers, while driving operational excellence, workforce development, and organizational scalability.
  • Drive adoption of AI, agentic SOC workflows, automation, and threat-informed defense capabilities, integrating threat intelligence, proactive threat hunting, automated enrichment, alert triage, investigation, response orchestration, and advanced detection techniques to improve security outcomes and analyst effectiveness.
  • Establish and govern enterprise incident response and cyber crisis management processes, including executive communications, legal and regulatory coordination, third-party incident response providers, tabletop exercises, audit support, and partnerships with operating company leadership during major incidents.
  • Define, govern, and communicate enterprise cyber defense performance, including MTTD, MTTR, ATT&CK coverage, telemetry health, analyst efficiency, false-positive reduction, backlog management, and overall program effectiveness, while partnering with OpCo CISOs, CIOs, plant leaders, product teams, executive leadership, and audit/risk committees to embed detection and response capabilities across Danaher's global businesses.

The essential requirements of the job include:

  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related field (or equivalent professional experience) and 12+ years of information security experience, including direct ownership of security operations, detection engineering, and/or incident response within a global organization.
  • Demonstrated success standing up, migrating, or modernizing enterprise-scale SIEM environments (e.g., Splunk, Microsoft Sentinel, Google SecOps/Chronicle, Elastic, Panther), including data pipelines, telemetry ingestion, parsing, normalization, and detection content ownership.
  • Deep expertise across the full detection engineering lifecycle, including use case intake, backlog prioritization, MITRE ATT&CK-aligned detection development, correlation and analytic rule authoring, validation, detection-as-code, CI/CD for detections, tuning, and coverage measurement.
  • Proven leadership of a 24x7 Security Operations Center (SOC) and incident response function, including major incident command, executive communications, investigations, and coordination with legal, privacy, compliance, and regulatory stakeholders.
  • Hands-on experience with modern cyber defense technologies, including SOAR and security automation, EDR/XDR, cloud-native detection across AWS, Azure, and GCP, identity threat detection, and modern log pipeline technologies such as Cribl, Kafka, and streaming ETL.
  • Demonstrated ability to lead large-scale information security organizations through multiple layers of management, building and directing globally distributed teams across multiple regions, sites, and business environments.
  • Experience operating within highly complex, multi-country enterprises spanning 50+ countries, with responsibility for delivering consistent cybersecurity capabilities, governance, and operational outcomes across diverse geographic and organizational landscapes.

Travel, Motor Vehicle Record & Physical/Environment Requirements:

  • Ability to travel up to 20-30% of the time, including international travel to Danaher operating company, R&D, SOC, and manufacturing locations globally.

It would be a plus if you also possess previous experience in:

  • Demonstrated accomplishments applying AI and agentic SOC approaches across the log management and detection lifecycle — for example, LLM-assisted alert triage and investigation, agentic hunt and response workflows, natural-language detection authoring, automated parser generation, or AI-driven noise reduction and false-positive suppression, with measurable improvements in MTTD, MTTR, or analyst capacity.
  • Experience building or operating a modern security data lake or federated SIEM architecture that separates hot detection tier from long-term investigative and compliance storage.
  • Experience integrating detection and response across IT and OT/ICS environments, and across connected product / IoT telemetry.
  • Experience within a diversified, multi-business-unit organization operating with a decentralized business model (e.g., Danaher Business System or an equivalent operating system).
  • Professional certification such as CISSP, CISM, GCIA, GCIH, GCFA, or GNFA.
  • Experience presenting to boards, audit committees, or executive risk committees.

Join our winning team today. Together, we’ll accelerate the real-life impact of tomorrow’s science and technology. We partner with customers across the globe to help them solve their most complex challenges, architecting solutions that bring the power of science to life.

For more information, visit www.danaher.com.

Seen 3 hours ago · Pall Corporation postings close after a median of 29 days.

Original posting on Pall Corporation's site ↗

Posting text belongs to the employer. Removal requests: contact us.

One job at a time

One posting. One CV. $25.

Pick the job you actually want and we write for it.

Get my CV for this job