Advanced Cyber Defense Practice Lead
The Opportunity: Shape and deliver Booz Allen’s advanced cyber defense capabilities, working closely with internal CTO and R&D to develop and implement solutions for CISOs, cyber defense leaders, and security operations teams. Design next‑generation operating models, modernize SOC and Fusion Center capabilities, and strengthen detection engineering and use‑case lifecycle management. Guide modern SOC, Cyber Fusion Center, and detection and response transformation initiatives for large multinational enterprises across select international regions, including Europe, North America, and Asia. Drive adoption of AI‑enabled and agentic SOC concepts in practical, mission‑focused ways. Lead the building or transforming of SOC, CSIRT, or cyber defense functions in complex enterprise environments. Lead solution design, proposal shaping, high‑impact technical engagement, and client delivery. Manage and grow a team while supporting business development, thought leadership, and overall operational excellence.
You Have
- 12+ years of experience leading modern SOC, Cyber Fusion Center, CSIRT, cyber defense, or detection and response programs in large, complex enterprise environments
- 5+ years of experience designing and implementing SOC or Cyber Fusion Center operating models, including governance, workflows, escalation paths, coverage models, and performance metrics
- Experience in detection engineering and use‑case lifecycle management, including triage, tuning, enrichment, prioritization, and measurement across enterprise telemetry
- Experience with advanced cyber defense tools and enablers such as security telemetry pipelines, AI‑enabled SOC workflows, automation, machine learning, and behavioral or anomaly analytics
- Experience advising senior stakeholders, including CISOs and cyber defense leaders, on strategy, maturity, gaps, target‑state design, and actionable improvement roadmaps
- Experience with SIEM, SOAR, XDR, EDR, NDR, IAM, cloud security platforms, and enterprise security technologies
- Experience developing proposals, technical solution narratives, roadmaps, business cases, and client‑ready presentations
- Experience coaching and leading multidisciplinary technical teams, and operating effectively in a high‑growth, entrepreneurial environment
- Ability to lead client delivery, including solution architecture, technical execution, engagement leadership, and quality oversight
- Bachelor's degree
Nice If You Have
- Experience translating enterprise cyber defense into client delivery, including executive facilitation, structured problem solving, stakeholder alignment, and polished written and verbal communication, and applying MITRE ATT&CK, cyber kill chain concepts, threat intelligence, threat hunting, purple teaming, adversary emulation, deception, exposure management, or related threat-informed methodologies to improve detection and response
- Experience with cyber defense maturation journeys, operating model transformation, Cyber Fusion Center design, CSIRT development, security operations modernization, or managed detection and response transformation
- Experience with cloud security operations, SaaS security, identity-centric detection and response, OT/ICS cyber defense, or large-scale hybrid enterprise security environments
- Experience across both production security data pipelines and AI/ML-enabled detection or prioritization, including where advanced analytics are useful and where rules, signatures, automation, or human judgment remain necessary
- Experience creating thought leadership, presenting at industry events, leading technical workshops, or supporting market-facing cyber defense campaigns that build credibility with CISO and cyber defense communities
- Ability to travel up to 25% of the time based on client and business needs, and adapt global methodologies to regional market needs, regulatory expectations, language requirements, and client operating environments
- Ability to engage senior stakeholders while maintaining credibility with technical SOC and cyber defense teams
- Possession of strong executive communication skills
- Master’s degree CISSP, CISM, GIAC, GCIH, GCIA, GMON, GCTI, SANS, CREST, OSCP, Splunk, Cloud Security, or similar Certifications
Identity Statement
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
About Booz Allen
Booz Allen is an advanced technology company. We build commercial-grade products and solutions for America’s most critical defense, civil, and national security priorities.
Know Your Rights Poster Accommodations
Applicants who need a reasonable accommodation for any part of the application, hiring, or employment process because of a disability, a sincerely held religious belief, practice, or observance, or as otherwise required by applicable law should contact the Booz Allen Help Desk by calling 1-877-927-8278 or sending an email to helpdesk@bah.com. We will review requests on an individualized basis and provide reasonable accommodations consistent with applicable law.
Data Privacy
For more information on how Booz Allen uses your information, please see our Careers Privacy Policy.
#J-18808-Ljbffr
Advanced Cyber Defense Practice Lead in Linton employer: Booz Allen Hamilton
Booz Allen is an exceptional employer, offering a dynamic work environment in The Hague, South Holland, where innovation meets collaboration. With a strong focus on employee growth, we provide opportunities to lead cutting-edge projects in Post Quantum Cryptography, ensuring our team members are at the forefront of technological advancements. Our inclusive culture fosters creativity and encourages professional development, making it a rewarding place for those looking to make a meaningful impact in the field of cybersecurity.