AFL Global

IT Cyber Defense Lead (Hybrid Office Schedule)

AFL Global • $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience.
  • 5+ years in security operations, with 3+ years in a senior or lead role.
  • Hands-on experience with enterprise-scale endpoint detection and response platforms, preferably CrowdStrike Falcon.
  • Proven incident response experience for business-impacting events, including containment and post-incident reviews.
  • Fluency in query languages for security analytics and experience with log source onboarding.
  • Experience in building or tuning detection content based on production telemetry.
  • Familiarity with MITRE ATT&CK for coverage decisions.

Responsibilities

  • Administer and tune the endpoint detection, identity protection, and security analytics platform stack.
  • Act as incident commander for high severity security events, coordinating technical responses and business communications.
  • Manage the relationship with the managed detection and response provider, ensuring quality and accuracy in service reviews.
  • Oversee agentic triage and case management, defining scopes and measuring accuracy.
  • Enhance detection content by writing new detections and tuning existing ones, mapping to MITRE ATT&CK.
  • Develop automation playbooks and API integrations to streamline processes.
  • Operationalize threat intelligence and conduct proactive threat hunts.

Benefits

  • Hybrid work schedule based in Duncan, SC.
  • On-call responsibility with availability required during active security incidents.
  • Standard office environment with occasional access to manufacturing floors requiring PPE.
  • Potential for travel to domestic and international sites.
Full Job Description
We are seeking a Cyber Defense Lead to join our global IT organization in Duncan, SC. Under general direction, this role leads security operations covering threat monitoring, investigation, and response across AFL's global organization. The incumbent owns the security platform stack, governs the managed detection and response provider, and serves as incident commander during high severity events. This role works independently and sets the technical direction for how AFL detects and responds to threats.

Responsibilities

  • Own administration, tuning, and roadmap for the endpoint detection, identity protection, and security analytics platform stack, including log source onboarding and telemetry coverage.
  • Serve as incident commander for high severity security events. Coordinate technical response, containment decisions, and business communication. Run post-incident reviews and drive corrective actions to closure.
  • Govern the managed detection and response provider relationship. Review escalation quality, response times, and handoff accuracy in recurring service reviews.
  • Own the agentic triage and case management capability. Define agent scope, guardrails, and human approval gates, and measure autonomous accuracy before expanding autonomy.
  • Maintain and improve detection content. Write new detections, tune noisy ones, and map coverage to MITRE ATT&CK to identify and close gaps.
  • Develop automation playbooks and API integrations across detection, response, and service management platforms to reduce analyst touch time.
  • Operationalize threat intelligence and conduct proactive threat hunts against defined hypotheses.
  • Define and report security operations metrics, including mean time to detect, mean time to respond, escalation volume, false positive rate, and detection coverage.
  • Build and maintain runbooks, severity criteria, escalation paths, and on-call procedures. Contribute to incident response tabletop exercises and business resiliency planning.
  • Partner with Systems, Network, and Application teams on control gaps surfaced during investigations, and support incident documentation for audit, cyber insurance, and customer assessments.


Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity or equivalent work experience required.
  • Five or more years in security operations, with three or more in a senior or lead capacity.
  • Hands-on administration of an endpoint detection and response platform at enterprise scale. CrowdStrike Falcon preferred.
  • Hands-on incident response experience on business-impacting events, including containment, investigation, and post-incident review.
  • Query language fluency for security analytics platforms, plus log source onboarding experience.
  • Experience building or tuning detection content against production telemetry.
  • Working knowledge of MITRE ATT&CK applied to coverage decisions, not just terminology.
  • Clear written and verbal communication with technical staff and business leadership.
  • One or more of the following certifications preferred but not required: CISSP, CISM, GCIA, GCIH, GCFA, GDAT, GCDA or vendor certifications for the deployed security platforms.


Personal Qualities

  • Stays composed under pressure and makes sound containment decisions with incomplete information.
  • Takes ownership of problems and follows them to resolution without prompting.
  • Validates output from vendors, tools, and automation before acting on it.
  • Builds working relationships with both technical and non-technical teams outside the security function.
  • Communicates clearly, translating technical findings for engineers and for business leadership.


Working Conditions

  • Hybrid schedule based onsite in Duncan, SC.
  • Carries on-call responsibility. Requires availability outside standard business hours during active security incidents, which occur without notice and may extend across consecutive days.
  • Standard office environment. Occasional access to manufacturing floors where hearing protection and personal protective equipment are required.
  • Flexibility travel to AFL domestic and international sites if needed.

About AFL Global

AFL Global is a leading provider of integrated solutions in the fiber optics industry. The company offers a wide range of products and services, including fiber optic cable, connectivity, and accessories, as well as engineering, installation, and maintenance services. AFL Global serves a variety of industries, including telecommunications, broadband, electric utility, and enterprise.
Learn more about AFL Global
Size
5,000 employees
Industry
Founded
1984

Similar Jobs

More Jobs at AFL Global

More Information Technology Jobs

Find similar IT Cyber Defense Lead (Hybrid Office Schedule) jobs: