1

Cyber Defense Operator Jobs (NOW HIRING)

Director, Cyber Defense

Concord, NC

$103K - $139K/yr

The Role The Director, Cyber Defense, leads Kyndryl's operational defense mission across a globally ... than operating in isolation from it. * Strong command of incident response methodologies and ...

Director, Cyber Defense

New York, NY

$121K - $164K/yr

The Role The Director, Cyber Defense, leads Kyndryl's operational defense mission across a globally ... than operating in isolation from it. * Strong command of incident response methodologies and ...

Director, Cyber Defense

Los Angeles, CA

$119K - $161K/yr

The Role The Director, Cyber Defense, leads Kyndryl's operational defense mission across a globally ... than operating in isolation from it. * Strong command of incident response methodologies and ...

Cyber Defense Operations Lead

Austin, TX · On-site

$287K - $351K/yr

Cyber Defense Operations Lead Collaborate with Innovative 3Mers Around the World Choosing where to ... operating rhythms. * Oversee monitoring, incident response coordination, detection engineering ...

Cyber Defense Analysts - Senior

Washington, DC · On-site

$113K - $146K/yr

Support and contribute to the development and maintenance of SOC Standard Operating Procedures ... Ensure all cyber defense activities comply with applicable federal cybersecurity frameworks ...

Showing results 41-60

Cyber Defense Operator information

See salary details

$34K

$112.9K

$176K

How much do cyber defense operator jobs pay per year?

As of Aug 6, 2026, the average yearly pay for cyber defense operator in the United States is $112,871.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is the difference between Cyber Defense Operator vs Cyber Security Analyst?

AspectCyber Defense OperatorCyber Security Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, GIAC certifications
Work EnvironmentOperational security teams, SOCs, incident response centersSecurity teams, risk management departments, consulting firms
Primary FocusMonitoring, detecting, and responding to cyber threats in real-timeAnalyzing security data, assessing vulnerabilities, developing security policies

While both roles focus on cybersecurity, a Cyber Defense Operator primarily handles real-time threat detection and incident response, working within security operations centers. In contrast, a Cyber Security Analyst often focuses on analyzing security data, assessing risks, and developing security strategies. Both roles require similar certifications and work in related environments, but their day-to-day responsibilities differ in scope and focus.

What skills and qualifications are needed to be a cyber defense operator?

To thrive as a Cyber Defense Operator, you need expertise in network security, threat analysis, and incident response, often supported by a degree in cybersecurity or computer science and relevant certifications like CompTIA Security+ or CISSP. Familiarity with security information and event management (SIEM) tools, intrusion detection systems (IDS), and malware analysis platforms is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for this role. These skills and qualities are vital for detecting, mitigating, and communicating about cyber threats to protect organizational assets.

What is a cyber defense operator?

Cyber Defense Operators are professionals responsible for protecting an organization’s digital infrastructure from cyber threats, such as hacking, malware, and unauthorized access. They monitor network activity, investigate security incidents, and implement measures to prevent cyberattacks. These specialists use various tools and techniques to detect vulnerabilities and respond quickly to security breaches, ensuring the safety and integrity of sensitive information. Cyber Defense Operators often work as part of a larger cybersecurity team and are essential for maintaining robust information security in today’s digital world.

What challenges does a cyber defense operator face when responding to security incidents?

Cyber Defense Operators often navigate challenges such as rapidly evolving threats, incomplete or ambiguous data, and the need to coordinate with multiple teams under time pressure. Responding effectively requires balancing thorough investigation with swift action to contain threats and minimize damage. Clear communication with IT, management, and sometimes external stakeholders is essential, as is the ability to adapt to new attack vectors and technologies. Continual learning and staying updated on the latest threat intelligence are key to success in this dynamic environment.
More about Cyber Defense Operator jobs
What job categories do people searching Cyber Defense Operator jobs look for? The top searched job categories for Cyber Defense Operator jobs are:
Infographic showing various Cyber Defense Operator job openings in the United States as of August 2026, with employment types broken down into 40% Full Time, 58% Part Time, 1% Contract, and 1% Nights. Highlights an 99% Physical, and 1% Remote job distribution, with an average salary of $112,871 per year, or $54.3 per hour.

Director, Cyber Defense

Kyndryl

Concord, NC

$103K - $139K/yr

Full-time

Posted 24 days ago


Kyndryl rating

7.2

Company rating: 7.2 out of 10

Based on 11 frontline employees who took The Breakroom Quiz

133rd of 221 rated it services


Job description

Who We Are

At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities.

The Role

The Director, Cyber Defense, leads Kyndryl's operational defense mission across a globally distributed security organization. This role reports to the Vice President and Deputy CISO, Cyber Operations.

You will own the full incident response lifecycle, run follow-the-sun security operations across AMER, EMEA, and APAC, direct the cyber threat intelligence program, and drive the conversion of that intelligence into the detection coverage and defensive architecture that protect Kyndryl's global enterprise estate. You will set the engineering discipline that keeps detection content tested, version-controlled, and continuously validated against the adversary. During major security incidents, you will exercise cross-functional coordination authority to drive rapid, disciplined response. The window between vulnerability and exploit is compressing as adversaries adopt AI-accelerated tooling. This role exists to keep Kyndryl's defense ahead of that curve.

What You'll Do:

  • Lead 24/7 global security operations through a follow-the-sun model spanning AMER, EMEA, and APAC regions.
  • Own the full incident response lifecycle, triage through post-incident review, with forensic preservation standards maintained throughout.
  • Coordinate with the Incident Commander function with clear escalation authorities, runbooks, and cross-functional coordination protocols for cybersecurity incidents.
  • Direct the Cyber Threat Intelligence program and own the intelligence-to-defense loop: convert prioritized adversary intelligence into detection requirements, control coverage decisions, and changes to the defensive architecture.
  • Govern ATT&CK-aligned detection coverage on measured efficacy, and stand up continuous validation through adversary emulation and detection testing to prove that intelligence-driven defenses fire against the techniques they target.
  • Set detection-as-code discipline across the detection lifecycle: version-controlled content, release rigor, automated testing, and telemetry quality standards, executed jointly with the SIEM, SOAR, & Agent Development team that owns the underlying pipeline and platform.
  • Drive operational measurement toward compressing the defender's detect-decide-act cycle against AI-accelerated adversaries, not raw response speed alone.
  • Coordinate with Vulnerability Management on remediation prioritization and exploitability-informed sequencing. This role does not own the vulnerability management function.
  • Collaborate with the AI-Driven Cyber Defense team to integrate automation and ML into defensive operations.
  • Build and develop a globally diverse team, investing in their growth across technical, analytical, and leadership competencies.

What You Bring:

  • Proven ability to lead security operations and incident response at enterprise scale, with the composure and decision quality to perform under pressure.
  • Strong command of threat-informed defense: translating intelligence into detection coverage and architecture decisions, anchored in MITRE ATT&CK, with kill chain analysis as a supporting lens for mapping attacker progression.
  • Working command of detection engineering practice: detection-as-code, content lifecycle management, and validation discipline, partnering with platform engineering rather than operating in isolation from it.
  • Strong command of incident response methodologies and escalation processes.
  • A leadership style that builds operational discipline without stifling initiative. You want your team thinking, not just executing.
  • Experience running geographically distributed teams with the cultural awareness that global operations demand.
  • The ability to communicate effectively with technical teams and executive leadership alike.

    Kyndryl currently does not require employees to be fully vaccinated against COVID-19, however, if you are hired to work at a client, customer, or partner location, you may be required to show proof ofvaccinationto align with their respective COVID-19vaccinationpolicies. Those who believe they are eligible may apply for a medical or religious accommodation prior to the start of employment.

    Who You Are

    Requirements:

    • 12+ years in cybersecurity operations, incident response, threat intelligence, or SOC leadership, with at least 5 years in a senior leadership role over a globally distributed team.
    • Demonstrated track record leading a cyber defense or security operations program at comparable scale and complexity, defending a hybrid or multi-cloud enterprise estate.
    • Experience operationalizing threat intelligence into detection coverage and defensive architecture, with familiarity in detection engineering and continuous validation practice.
    • Dedication to continuous learning through a combination of self-directed, certification, military, and formal education sources.

    The compensation range for the position in the U.S. is $200,800 to $375,600 based on a full-time schedule.Your actual compensation may vary depending on your geography, job-related skills and experience. For part time roles, the compensation will be adjusted appropriately. The pay or salary range will not be below any applicable state, city or local minimum wage requirement.

    Being You

    Diversity is a whole lot more than what we look like or where we come from, it's how we think and who we are. We welcome people of all cultures, backgrounds, and experiences. But we're not doing it single-handily: Our Kyndryl Inclusion Networks are only one of many ways we create a workplace where all Kyndryls can find and provide support and advice. This dedication to welcoming everyone into our company means that Kyndryl gives you - and everyone next to you - the ability to bring your whole self to work, individually and collectively, and support the activation of our equitable culture. That's the Kyndryl Way.

    What You Can Expect

    With state-of-the-art resources and Fortune 100 clients, every day is an opportunity to innovate, build new capabilities, new relationships, new processes, and new value. Kyndryl cares about your well-being and prides itself on offering benefits that give you choice, reflect the diversity of our employees and support you and your family through the moments that matter - wherever you are in your life journey. Our employee learningprograms give you access to the best learning in the industry to receive certifications, includingMicrosoft, Google, Amazon, Skillsoft, and many more. Through our company-wide volunteering and giving platform, you can donate, start fundraisers, volunteer, and search over 2 million non-profit organizations. At Kyndryl, we invest heavily in you, we want you to succeed so that together, we will all succeed.

    Get Referred!
    If you know someone that works at Kyndryl, when asked 'How Did You Hear About Us' during the application process, select 'Employee Referral' and enter your contact's Kyndryl email address.


    What Kyndryl employees say

    Pay

    Benefits

    Hours and flexibility

    Workplace

    Get the full story on Breakroom


    Kyndryl logo

    About Kyndryl

    Sourced by ZipRecruiter

    Kyndryl is a market leader that thinks and acts like a start-up. We design, build, manage, and modernize the mission-critical technology systems that the world depends on every day.

    Industry

    It services

    Company size

    10,000+ Employees

    Headquarters location

    New City, NY, US

    Year founded

    2021

    Social media