Vice President - Cyber Security (Operations)
Skills
About the role
Job Description: We are seeking a forward-thinking Cyber Security Operations Leader to lead and transform EXL's global Cyber Defense Center capabilities across mission-critical Security Operations, Threat Detection, Incident Response, Threat Intelligence, Digital Forensics, Security Automation, AI Security Monitoring, and Security Operations Assurance.
This role is responsible for evolving EXL's Cyber Defense Center (CDC) into an intelligence-driven, automation-first, and AI-augmented security operations capable of protecting a distributed enterprise comprising of cloud-native systems, Domain Platforms, BPaaS environments, AI-powered solutions, and critical business operations enabling our clients in regulated industries including Insurance, Banking & Financial Services, Healthcare, Energy & Utilities, Travel and Transportation.
The successful candidate will strengthen modern detection and response capabilities across traditional Technologies, Engineering Systems, COTS, Cloud, SaaS, and AI ecosystems while strengthening cyber resilience, operational robustness, and executive visibility into emerging cyber risks.
This leader will partner closely with Enterprise Security, Cloud Security Engineering, and Application Security within the Cyber Security functions and with cross-functions of Cloud Infrastructure, Data & AI teams, Analytics & AI Services and business stakeholders to continuously improve EXL's security posture and operational resilience while enabling secure innovation and digital transformation.
Responsibilities: Security Posture Monitoring, Incident Response and Crisis Management
Drive established enterprise Incident Response capability, including a dedicated Computer Incident Response Team (CIRT) with clearly defined roles, escalation procedures, and communication protocols for both internal and client-impacting incidents.
Develop, maintain, and regularly test comprehensive incident response playbooks covering the full spectrum of attack scenarios: ransomware, BEC, supply chain compromise, insider threats, DDoS, APT intrusions, data breaches, cloud credential compromise, AI model tampering, and client data exposure.
Serve as the executive incident commander during major security incidents (P1/P2), coordinating cross-functional response across Technology, Legal, Communications, HR, executive leadership, and Industry Security Business Partners for client-impacting events.
Lead post-incident reviews (PIRs) and blameless retrospectives, ensuring root cause analysis, lessons learned, and remediation actions are tracked to closure and fed back into detection engineering, cloud security, and application security (Pillar 6) improvement cycles.
Build and maintain a digital forensics capability for conducting investigations across endpoints, servers, cloud workloads, email systems, containers, and mobile devices
Establish relationships with external incident response retainers, law enforcement (FBI Cyber, CISA), and industry ISACs (FS-ISAC, H-ISAC, IT-ISAC) for coordinated threat response and intelligence sharing
2. Threat Intelligence & Proactive Threat Hunting
Build and operationalize a Cyber Threat Intelligence (CTI) program that collects, analyzes, and disseminates actionable intelligence from OSINT, commercial feeds (Google Mandiant, CrowdStrike Intel), dark web monitoring, industry ISACs, and government advisories.
Establish a proactive threat hunting program with dedicated hunters who develop hypotheses based on threat intelligence, MITRE ATT&CK TTPs, and environmental anomalies to identify threats that evade automated detection - including cloud-native and AI-specific hunting scenarios.
3. AI Security Operations and AI Threat Defense
Establish monitoring, detection, and response capabilities for AI-enabled applications, LLM platforms, AI agents, RAG architectures, model repositories, and AI runtime environments.
Develop detection coverage aligned to MITRE ATLAS, OWASP Top 10 for LLM Applications, and emerging AI threat frameworks
Lead operational readiness for AI-related incidents including prompt injection, model abuse, model theft, data leakage, excessive agency, privilege escalation, and AI supply-chain compromise.
Partner with Secure AI, Application Security, and Cloud Security teams to continuously improve AI runtime visibility, monitoring, and protection capabilities.
4. Managing Cyber Defense Center (CDC) Capability and Operational Leadership
Own and operate a 24x7x365 CDC with tiered analyst structure (L1/L2/L3) and MSP augmentation, ensuring continuous monitoring, detection, and response coverage across all enterprise and client-delivery environments globally.
Establish and enforce CDC performance standards including SLA targets for MTTD
Drive continuous CDC maturity improvement using SOC-CMM (SOC Capability Maturity Model), MITRE ATT&CK-based coverage assessments, and formal capability benchmarking against industry peers.
Manage CDC shift schedules, analyst burnout prevention programs, knowledge management (runbooks, wiki, playbook library), and cultural initiatives to sustain high-quality, 24x7 operations.
5. Detection Engineering and AI-Native Threat Detection
Lead the detection engineering to develop, testing, tuning, and maintaining detection rules, correlation logic, and behavioral analytics across Nextgen SIEM (Microsoft Sentinel), EDR, and cloud-native platforms.
Implement a detection-as-code methodology, version-controlling all detection content in Git, integrating detection rule CI/CD pipelines, and enabling peer review of detection logic before deployment to production.
Map detection coverage to both MITRE ATT&CK (cloud matrix, enterprise matrix) and MITRE ATLAS (AI-specific techniques), identifying and closing coverage gaps across all TTPs relevant to the organization’s data and AI threat profile.
Drive adoption of AI/ML-powered detection capabilities, including anomaly detection for cloud API behaviors, entity behavior analytics (UEBA) for insider threats, LLM-assisted alert triage, and automated alert correlation to reduce false positive rates by 30%+ year-over-year.
Oversee the deployment, integration, and optimization of the enterprise SIEM platform (Microsoft Sentinel), EDR/XDR (CrowdStrike, Microsoft Defender),
Develop detection content specifically for AI/ML workload threats: anomalous GPU utilization patterns, unauthorized model weight access, training data exfiltration, inference API abuse, and agentic AI permission escalation.
6. Security Automation & Orchestration (SOAR)
Lead the design and maturity of repetitive CDC workflows using Microsoft Sentinel and LogicApps to accelerate response times and improve analyst efficiency across the global SOC operation.
Develop and maintain automated playbooks for common alert types: phishing triage, malware detonation, account lockout, suspicious cloud API activity, BPaaS tenant isolation alerts, and AI workload anomaly alerts
Develop LLM-assisted automation capabilities, including natural language alert summarization, automated runbook generation from incident patterns, and AI-powered root cause analysis suggestions.
Measure and report on automation metrics including percentage of alerts auto-triaged, mean time saved per automated playbook, analyst capacity reclaimed through automation, and automation-driven false positive reduction.
Metrics, Reporting & Executive Communication
Develop and maintain a comprehensive Cyber operations metrics and KPI framework, providing real-time dashboards and monthly/quarterly executive reports to the CISO, CIO, and board of directors.
Translate operational telemetry, threat data, and incident patterns into strategic risk narratives that inform executive decision-making, board-level risk discussions, and security investment prioritization.
Produce client-facing security posture reports demonstrating CDC capabilities, incident response readiness, and compliance posture for client due diligence, RFP responses, and contractual attestations.
Manage the security operations budget ($5M-$12M+), including SOC staffing, MSSP contracts, SIEM/EDR/SOAR licensing, threat intelligence feeds, IR retainers, and training programs, demonstrating ROI on automation and tooling investments.
7. Team Leadership and Organizational Development
Recruit, develop, and retain a world-class security operations team of 20-35 professionals across CDC analysis, detection engineering, incident response, threat intelligence, forensics, and automation functions, supplemented by MSSP partners for L1 surge and off-hours coverage.
Establish a continuous training and certification program (SANS GIAC: GCIH, GCFA, GCIA, GCTI, GSOM; OSCP; BTL1/BTL2; CySA+; cloud security certs) and invest in hands-on training through cyber range exercises, CTF competitions, and AI-specific threat simulations
Qualifications: Proven track record of managing major security incidents (ransomware, APT, data breach, cloud credential compromise) from detection through recovery in environments with 5,000+ employees or equivalent complexity
Strong Understanding of Cyber Defense & Security Operations
Security Operations
Incident Response
Threat Hunting
Threat Intelligence
Detection Engineering
Digital Forensics
SOAR
Cloud Security Operations
AWS Security
Azure Security
GCP Security
Container Security
SaaS Security
AI Security Operations
AI Runtime Security
LLM Security Monitoring
Agentic AI Security
AI Threat Detection
MITRE ATLAS
AI Attack Simulation
Frameworks & Standards
MITRE ATT&CK
MITRE ATLAS
NIST CSF
NIST AI RMF
ISO 27001
SOC-CMM
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.