Overview
In this role, you own the RESPOND product lifecycle to modernize Security Operations with AI-augmented incident response. You’ll define strategy for tooling, automation, and evidence workflows across global SOC, DFIR, and Threat Response teams. You lead the multi-year roadmap for response capabilities and govern automation and AI adoption within regulatory contexts. You’ll partner with detection teams to ensure automation-ready outcomes and report progress to executives.
Responsibilities
- Own and execute the multi-year strategy and roadmap for incident response tooling, automation, and AI augmentation across Security Operations
- Define and maintain the RESPOND capability taxonomy aligned to NIST CSF, NIST SP 800-61r3, MITRE ATT&CK and D3FEND
- Set roadmap for SOAR platforms (Splunk SOAR, Microsoft Sentinel SOAR/Logic Apps), case management, evidence collection, and orchestration
- Define and oversee SOAR playbook automation, documentation, and execution
- Define AI augmentation incident response strategy including agentic AI workflows, LLM-assisted triage, notebooks, and autonomous response patterns
- Establish governance for AI-assisted actions compliant with regulations and audits
- Define requirements and oversee automation pipelines, notebooks, enrichment services, and analyst tooling
- Maintain centralized libraries of response tools and notebooks deployable via EDR, SOAR, and endpoint management
- Drive tooling and integration strategy across EDR, XDR, SIEM, identity, cloud, network, ticketing, and AI platforms
- Partner with detection team to ensure detections are output as automatable, AI-consumable artifacts
- Define KPIs and OKRs for response product effectiveness (MTTR, automation coverage, toil reduction, containment time)
- Manage vendor relationships, evaluations, POCs, and procurement for response and AI tooling
- Govern RESPOND backlog and lead agile delivery; present capabilities to executives, auditors, and regulators
Key requirements
- Extensive security operations, incident response, DFIR, or automation engineering experience
- 3+ years in a product, architecture, or capability ownership role
- Hands-on expertise with SOAR tools (playbooks, integrations, apps/connectors)
- Experience delivering AI-augmented incident response at an enterprise scale
- Knowledge of MCP server architectures and agentic frameworks for SOC
- Deep IR lifecycle expertise (triage to post-incident) and DFIR across endpoints, networks, cloud, identity, and SaaS forensics
- Proficiency in Python and PowerShell; ability to review code
- Experience with EDR live response and custom tooling
- Knowledge of SOC concepts (tiered case management, detection-as-code, response-as-code) and modernization programs (SOC 2.0/3.0)
- Regulatory awareness and ability to align with audit requirements
- Cross-functional collaboration
- Strategic thinking
- Influence without authority
- SOAR platforms (Splunk SOAR, Microsoft Sentinel SOAR)
- Case management and evidence collection
- AI augmentation and prompt engineering
Threat Response Technology and Capabilities Product Owner employer: MasterCard
Mastercard is an exceptional employer that fosters a culture of innovation and collaboration, making it an ideal place for a Director of Software Engineering. With a strong emphasis on employee growth, you will have access to cutting-edge tools and resources, as well as opportunities to mentor and lead talented teams across diverse geographies. The company's commitment to data-driven decision-making and AI-assisted development ensures that you will be at the forefront of technological advancements in a dynamic and supportive environment.