This Role is Tailor-Made for You Because:You are a technically authoritative cybersecurity leader who understands that modern threat management is driven by identity, data, configuration integrity, attack paths, and adversary behavior, not security tool accumulation.
You have deep expertise across cloud, identity, applications, infrastructure, AI-enabled environments, and enterprise data platforms and know how to translate threat intelligence and adversary insights into meaningful detection, response, governance, and risk-management outcomes.
This role leads the organization's threat management function and is accountable for threat intelligence, threat modeling, detection engineering, adversarial validation, vulnerability management, incident response, crisis readiness, and threat capability maturity. You will drive a threat-informed security program that prioritizes real-world risk while remaining hands-on in technical decision making.
A Day in the Life:Lead Enterprise Threat Management- Own and mature the enterprise threat management program, including threat intelligence, threat modeling, detection engineering, incident response, adversarial validation, and risk-based vulnerability management.
- Identify relevant adversaries, attack techniques, and attack paths and ensure they influence security priorities, architecture decisions, and operational activities.
- Apply frameworks such as MITRE ATT&CK pragmatically to improve prevention, detection, response, and resilience.
Drive Detection Engineering & Threat Operations- Define and lead detection strategy across identities, endpoints, cloud platforms, networks, applications, data environments, and AI-enabled systems.
- Ensure identity telemetry, privilege use, token issuance, abnormal access patterns, workload behavior, and data access activities are first-class detection concerns.
- Remain hands-on in the design, tuning, validation, and continuous improvement of threat detections and hunting capabilities.
- Lead and mentor a Detection Engineer.
Own Threat Intelligence, Attack Path Analysis & Adversarial Validation- Establish and maintain a threat intelligence capability that translates emerging threats into operational improvements.
- Lead threat modeling and attack path analysis across Microsoft 365, GCP, enterprise applications, ERP platforms, CI/CD pipelines, and data environments.
- Own and actively challenge red team, purple team, penetration testing, and adversarial simulation activities to ensure findings result in measurable improvements.
Lead Incident Response & Crisis Readiness- Serve as the senior technical leader during cybersecurity incidents and direct technical response activities.
- Maintain relationships with MSSPs, legal counsel, communications teams, insurance providers, and executive leadership to ensure effective incident management.
- Design and facilitate consequence-driven tabletop exercises that test technical, operational, legal, and executive decision-making processes.
Drive Risk-Based Vulnerability Management- Own vulnerability and exposure management strategies that prioritize remediation using exploitability, attack-path significance, identity exposure, business impact, and threat intelligence rather than severity scores alone.
- Ensure remediation efforts focus on the vulnerabilities most likely to be exploited and cause meaningful business impact.
Influence Security Architecture & Governance- Provide threat-informed guidance to architecture, cloud, infrastructure, application, and data teams.
- Assess AI-related risks, data protection concerns, and emerging technology threats.
- Partner with compliance and audit teams to ensure PCI, SOX, privacy, and regulatory controls effectively reduce cyber risk.
Executive Reporting & Program Maturity- Develop executive-level threat and risk reporting that communicates detection effectiveness, incident readiness, control maturity, vulnerability exposure, and residual risk.
- Define and drive a threat capability maturity model spanning detection, response, threat intelligence, identity security, vulnerability management, and crisis preparedness.
To Land This Role:- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience.
- 10+ years of progressive experience in threat engineering, threat management, incident response, detection engineering, threat intelligence, or related cybersecurity disciplines.
- Deep expertise in threat modeling, threat hunting, adversarial techniques, attack path analysis, and threat-informed defense.
- Strong technical experience across cloud security, Microsoft 365, GCP, identity and access management, non-human identities, data security, CI/CD security, application security, and vulnerability management.
- Demonstrated experience leading major cyber incident response efforts and coordinating internal and external stakeholders during critical security events.
- Experience assessing AI-related security risks, AI-enabled threats, and emerging attack techniques.
- Proven ability to translate technical threats and vulnerabilities into prioritized remediation and business-focused risk decisions.
- Professional certifications such as CISSP, CRISC, CIPT, CCSP, or comparable credentials preferred.
- Offensive security certifications such as OSCP, GWAPT, GXPN, or similar are highly desirable.
What Success Looks Like in This Role- Threat management is intelligence-led, adversary-driven, and focused on the organization's most relevant attack paths.
- Threat intelligence directly informs detection improvements, remediation priorities, and risk decisions.
- Detection coverage continuously improves against meaningful attacker behaviors and techniques.
- Red, blue, and purple team activities result in measurable improvements to security controls, configuration, and response readiness.
- Vulnerability remediation reflects exploitability, exposure, business impact, and threat intelligence rather than severity scores alone.
- Incident response and crisis-management capabilities perform effectively under real-world conditions.
- Threat capability maturity advances year over year through measurable improvements in readiness, visibility, and risk reduction.
- Executive leadership receives clear, actionable reporting on threats, security effectiveness, and residual risk.
Why You'll Want to Join Our Team:Our Technology team has a clear mission: use technology to enable the business to operate efficiently while driving growth and profitability. We envision, we strategize, we engineer, we design, we build, we test, we support, and we serve. Our tools and systems impact every customer and every member of our team every day and our role is to make each engagement seamless and rewarding. As we build our in-house engineering teams, we are focused on further modernizing our platforms, leveraging our data analytics capabilities and creating a transformational customer experience. Come join us!
How We Work Together- Adaptable - We change before we have to
- Entrepreneurial - We own it
- Collaborative - There's no "I" in Tory
- Client & Brand Focused - We put ourselves in Tory's shoes
- Live the Values - We show up for each other
- Functional Expertise - We're constantly learning and growing
#TeamTory ValuesWe show up with honesty & kindness, act with integrity & compassion, work with passion & humility and lead with excellence & humor.
Compensation RangeThe compensation range for this position is 165,000.00 USD - 200,000.00 USD. Our offer will be based on your relevant experience and work location.
Benefits InformationWe offer a generous set of benefits to help you take care of your health, create financial security, and achieve wellness in all areas of your life. Here are highlights of key benefits available to all eligible Tory Burch team members.