Director of Cyber Defense & Operations
Job description
About the role
You will own how Nscale detects, responds to, and recovers from serious cyber events across enterprise, cloud, production, data centre, and operational technology environments. This is an operator's role, not an engineering role, and you will lead incident command, escalation discipline, on-call health, case quality, resilience, and the operating relationship with our managed provider. You will work directly with the CISO, executive team, service owners, and the Enterprise Security, Platform and Product Security, Identity and PAM, and CISO office pillars to close capability gaps. Your operational judgement and communication under pressure will shape how Nscale manages material incidents, demonstrates recovery readiness, and permanently removes recurring security problems. This is one of the most externally visible roles in the security organisation, requiring frequent briefings to the CISO, executive team, board, customers, auditors, and insurers.
Key facts
What you'll do
Establish follow-the-sun coverage, with North America first and a second hub in Singapore or India scoped and hiring within your first 60 days.
Lead response operations across two hubs, setting escalation standards and maintaining on-call health, handover quality, and case quality.
Manage the operating relationship with our contracted managed provider, including measurable service expectations, evidence standards, and a plan to bring the work in-house over time.
Maintain an operating model in which the in-house security agent and managed provider hold level 0 and level 1 around the clock, while your team handles escalations rather than watching a queue.
Publish and operate a repeatable severity and incident command model covering authority, roles, escalation, containment, evidence, recovery, and post-incident learning.
Establish a named command rotation and test escalation paths.
Serve as one of the incident commanders and lead alongside the executive team while material incidents remain unresolved.
Brief the CISO weekly, the executive team and board quarterly, and customers, auditors, insurers, and regulators as required.
Set cyber resilience standards for recovery priorities, critical dependencies, recovery objectives, and evidence that plans survive contact.
Challenge service-owner assumptions while keeping accountability for system recovery with the relevant service owners.
Ensure continuity of the security function during identity outages, communications failure, destructive attack, or compromise of primary security tooling.
Run a standing programme of tabletops, technical simulations, and recovery tests that produces prioritised, funded remediation work.
Close the operational technology and building management coverage gap, neither of which is currently visible to the detection stack.
Ensure every escalation exits as an engineering artifact and measure success through the share of escalations permanently solved rather than tickets closed.
Set priority intelligence requirements that connect real threat actors, campaigns, and exposure to decisions.
Convert incidents, investigations, intelligence, and exercise findings into prioritised engineering demand, tested detections, and regression tests.
Define operational requirements, validate that delivered capabilities work, and measure whether they reduce risk without owning the engineering build.
Hire, level, coach, and develop a team across time zones, including succession planning and performance management.
Own budget and vendor decisions for the function.
Lead the cyber defense section of the monthly operations review and make it the place the CISO steers from.
Name Nscale's most critical services, their recovery objectives and dependencies, and the highest-risk readiness gaps within your first 90 days.
Requirements
12+ years in security operations, incident response, cyber defense, or resilience leadership, including 5+ years leading teams.
You have personally commanded serious incidents with material customer, legal, regulatory, or reputational consequences.
You communicate with exceptional clarity to executives, boards, customers, legal teams, auditors, insurers, and regulators while facts are still evolving.
You have built and scaled teams through hiring, levelling, coaching, succession planning, and handling underperformance; experience leading across time zones is a strong plus.
You bring real depth in business continuity and disaster recovery, with the technical credibility to challenge recovery plans that will not survive contact.
You have run tabletops, technical simulations, and recovery tests that produced funded change rather than reports alone.
You demonstrate operational rigour through runbooks, handovers, on-call health, case quality, escalation standards, and audit-ready evidence.
You have an automation-first instinct and respond to recurring toil by building or automating it away rather than defaulting to a tool purchase or additional headcount.
You understand modern attacker behaviour across identity, endpoint, cloud, SaaS, production, and third parties, and have held third-party monitoring or response providers to clear standards.
You have experience with operational technology, industrial control systems, building management systems, converged IT and OT response, data centres, HPC, sovereign cloud, destructive-event recovery, outsourced-to-insourced transitions, or multi-region, regulated, or pre-IPO environments is strongly valued; certifications are useful but not required.
Practical notes
LENGTH: 700-900 words. No HTML, no markdown, no em dashes.
Output the page only.