Job DescriptionWho are we looking for?We're looking for a
Manager of Cyber Defence Strategy and Operations to join our Information Systems team, based in Irvine, California.
As
Manager - Cyber Defence Strategy and Operations, you will own GHD's enterprise cybersecurity strategy and day-to-day operational resilience, and be the person who represents our cyber risk posture to the Chief Technology Officer, the IS Leadership Team and the Board Risk Committee. You will build genuine specialist depth beneath the Security Operations Centre, set and enforce enterprise security standards, and govern the security of an AI-era threat surface. This is both a strategic role and an operational command role, for a leader who is as credible in the boardroom as in the incident bridge.
Working with an energetic and high performing team, this position offers a variety of work and will see you involved in:- Develop and own GHD's multi-year cybersecurity strategy and target-state security architecture.
- Represent GHD's cyber risk posture to the CTO, the IS Leadership Team and the Board Risk Committee.
- Build specialist sub-teams (security architecture, vulnerability management, cyber GRC) to relieve the SOC of non-response work and restore true follow-the-sun coverage.
- Own the enterprise vulnerability-management programme and drive a measured remediation cadence with clear ownership.
- Command incident response for significant events, coordinating IT, Legal, HR and Communications.
- Define and govern the Zero Trust programme across GHD's Azure, identity and endpoint estate.
- Own GHD's AI security posture: agentic systems, non-human identities and shadow AI.
- Govern CMMC Level 2 and FedRAMP readiness as a commercial enabler for US Federal client work.
What you will bring to the team:- 12+ years in cyber security, including building and leading specialist sub-functions (not just running a single SOC), ideally in a large or global organisation.
- Deep expertise across security strategy, operations, threat intelligence, vulnerability management and architecture, spanning cloud (Azure), endpoint, network, identity, application and data.
- Strong Zero Trust and Microsoft security stack expertise (Defender, Sentinel, Entra ID, Purview).
- Hands-on experience with regulatory frameworks: CMMC Level 2, FedRAMP, ASD Essential Eight, ISO 27001 and NIST CSF.
- A track record of taking an organisation through a regulatory certification, and of presenting cyber risk to executive or board-level audiences.
- Incident command experience, and the ability to set enterprise standards without creating adversarial relationships.
- Certifications: CISSP, CISM or equivalent (required); CMMC Registered Practitioner or Professional (highly desirable); Microsoft SC-100 or AZ-500 (desirable).
Why you'll love this role:- Enterprise cyber leadership reporting to the CTO, with direct Board Risk Committee visibility.
- A build mandate: shape the strategy, the architecture and a genuine specialist team, not just keep the lights on.
- Security as a growth lever, with CMMC and FedRAMP readiness opening US Federal client work.
- The chance to define GHD's AI security posture at a pivotal moment for the threat landscape.
- A global remit, central to Strategy 2035, "We Master Technology."
If you want to lead cyber defence for a global organisation at a defining moment, we would love to hear from you. Apply now.The salary range for this position is $180,000 - $220,000. The posted salary range represents the expected hiring range for GHD locations in its major city centers. Ranges may vary for positions in other locations. At GHD, base salary is determined by your skills, experience, qualifications and work location. We are committed to offering competitive compensation and adhere to all relevant pay transparency legislation.