Rodeo
Get started

Kyndryl

Director, Cyber Defense

London
Posted about 19 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Who We Are

At Kyndryl, we run and reimagine the mission-critical technology systems that drive advantage for the world’s leading businesses. We are at the heart of progress; with proven expertise and a continuous flow of AI-powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people—Kyndryls—that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well-being is prioritized and your potential can thrive.

The Role

The Director, Cyber Defense, leads Kyndryl's operational defense mission across a globally distributed security organization. This role reports to the Vice President and Deputy CISO, Cyber Operations.

You will own the full incident response lifecycle, run follow-the-sun security operations across AMER, EMEA, and APAC, direct the cyber threat intelligence program, and drive the conversion of that intelligence into the detection coverage and defensive architecture that protect Kyndryl's global enterprise estate. You will set the engineering discipline that keeps detection content tested, version-controlled, and continuously validated against the adversary. During major security incidents, you will exercise cross-functional coordination authority to drive rapid, disciplined response. The window between vulnerability and exploit is compressing as adversaries adopt AI-accelerated tooling. This role exists to keep Kyndryl's defense ahead of that curve.

What You'll Do:

  • Lead 24/7 global security operations through a follow-the-sun model spanning AMER, EMEA, and APAC regions.
  • Own the full incident response lifecycle, triage through post-incident review, with forensic preservation standards maintained throughout.
  • Coordinate with the Incident Commander function with clear escalation authorities, runbooks, and cross-functional coordination protocols for cybersecurity incidents.
  • Direct the Cyber Threat Intelligence program and own the intelligence-to-defense loop: convert prioritized adversary intelligence into detection requirements, control coverage decisions, and changes to the defensive architecture.
  • Govern ATT&CK-aligned detection coverage on measured efficacy, and stand up continuous validation through adversary emulation and detection testing to prove that intelligence-driven defenses fire against the techniques they target.
  • Set detection-as-code discipline across the detection lifecycle: version-controlled content, release rigor, automated testing, and telemetry quality standards, executed jointly with the SIEM, SOAR, & Agent Development team that owns the underlying pipeline and platform.
  • Drive operational measurement toward compressing the defender's detect-decide-act cycle against AI-accelerated adversaries, not raw response speed alone.
  • Coordinate with Vulnerability Management on remediation prioritization and exploitability-informed sequencing. This role does not own the vulnerability management function.
  • Collaborate with the AI-Driven Cyber Defense team to integrate automation and ML into defensive operations.
  • Build and develop a globally diverse team, investing in their growth across technical, analytical, and leadership competencies.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What You Bring:

  • Proven ability to lead security operations and incident response at enterprise scale, with the composure and decision quality to perform under pressure.
  • Strong command of threat-informed defense: translating intelligence into detection coverage and architecture decisions, anchored in MITRE ATT&CK, with kill chain analysis as a supporting lens for mapping attacker progression.
  • Working command of detection engineering practice: detection-as-code, content lifecycle management, and validation discipline, partnering with platform engineering rather than operating in isolation from it.
  • Strong command of incident response methodologies and escalation processes.
  • A leadership style that builds operational discipline without stifling initiative. You want your team thinking, not just executing.
  • Experience running geographically distributed teams with the cultural awareness that global operations demand.
  • The ability to communicate effectively with technical teams and executive leadership alike.

Requirements:

  • 12+ years in cybersecurity operations, incident response, threat intelligence, or SOC leadership, with at least 5 years in a senior leadership role over a globally distributed team.
  • Demonstrated track record leading a cyber defense or security operations program at comparable scale and complexity, defending a hybrid or multi-cloud enterprise estate.
  • Experience operationalizing threat intelligence into detection coverage and defensive architecture, with familiarity in detection engineering and continuous validation practice.
  • Dedication to continuous learning through a combination of self-directed, certification, military, and formal education sources.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Applications will be accepted on a rolling basis.

Being You

The “Kyn” in Kyndryl means kinship, which represents the strong bonds we have with each other, our customers and our communities. We focus on ensuring all Kyndryls feel included and we welcome people of all cultures, backgrounds, and experiences. Even if you don’t meet every requirement, we encourage you to apply. We believe in growth, and we’re excited to see what you can bring. At Kyndryl, employee feedback has told us that our number one driver of employee engagement is belonging. That sense of belonging — being a valued, respected, trusted member of the team — is fundamental to our culture and fueling great experiences for our customers. This dedication to welcoming everyone into our company means that Kyndryl gives you the ability to thrive and contribute to our culture of empathy and shared success. That’s The Kyndryl Way.

What You Can Expect

Your career with us isn’t just a job—it’s an adventure with purpose. We offer a dynamic, hybrid-friendly culture that supports your well-being and empowers you to grow. Our Be Well programs are thoughtfully designed to support your financial, mental, physical, and social health—because we know that when you feel your best, you do your best.

From your very first day, you’ll dive into impactful work that powers the systems our customers rely on every day. You won’t just contribute—you’ll make a difference, tackling meaningful projects that sharpen your skills and fuel your growth.

We’re here to champion your journey. With powerful tools to chart your career path, personalized development goals aligned with your ambitions, and continuous feedback to keep you inspired and on track, you’ll have everything you need to thrive and evolve. You’ll develop in-demand skills to grow your career and achieve your ambitions with access to cutting-edge learning opportunities—from certifications with Microsoft, Google, and Amazon to coaching and hands-on experiences. And through it all, you’ll be part of a culture that values empathy, restless learning, and a devotion to shared success.

We want you to thrive here—and we’re committed to helping you do just that. Ready to make an impact? Join us and help shape what’s next.

Get Referred!

If you know someone that works at Kyndryl, when asked ‘How Did You Hear About Us’ during the application process, select ‘Employee Referral’ and enter your contact's Kyndryl email address.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Security Operations
Incident Response
Cyber Threat Intelligence
Detection Engineering
MITRE ATT&CK
Detection-as-Code
SIEM
SOAR
Forensics
Vulnerability Management
Cloud Security
Leadership
Cross-functional Coordination
Adversary Emulation
Kill Chain Analysis
Strategic Planning

Location

London, England, United Kingdom

Sign up to applySee more jobs like this