Introduction
Responsibilities
At IBM, the Senior Manager, Cyber Threats inspires, engages and motivates their staff to deliver practical, real-world benefits to the defense of IBM’s cyber security. This is a high-visibility role with the potential to make a real difference within one of the technology sector’s most well-established companies. The role reports to the Vice President of Cyber Security Defense and has three primary responsibilities:
- First-line manager to the TI team, which comprises a multi-disciplinary group of analysts, investigators and related technical specialists.
- First-line manager to the TH Manager, who in turn manages the TH practitioners. The Senior Manager is the de facto Second-line Manager of the TH team.
- Overall technical and business area lead for Threats, setting direction and strategy for Threats to inform and shape IBM’s defensive cyber security posture.
Your Role And Responsibilities
The Cyber Security Threats Senior Manager plays an important role in the wider cyber security operations leadership team – providing advice, guidance and support on intelligence, hunting and wider threat-related matters. The Senior Manager sets the Threats strategy, which includes enacting specific elements and contributing to medium/long-term objectives. The Senior Manager is responsible for fulfilling the objectives of the Cyber Security Defense Vice President, which may include specific task-level delegations and representing IBM in external matters.
The Senior Manager ensures the team is contributing accurate, relevant and reliable Threats ‘products’ – specifically:
- Ensuring both teams’ focus is set appropriately.
- Maintaining overall control of the Threats backlog.
- Balancing the need to address short term ‘tactical’ questions with the need to establish practical, appropriate and effective priorities that fulfil IBM’s cyber defense needs.
- Collaborating with the TH Manager to set and execute the priorities and direction for the threat hunters.
- Ensuring the unique skills and capabilities of all team members are used to best effect.
- Ensuring timely collection, processing, analysis and dissemination of intelligence to the right audience. This is vital in ensuring threats are identified quickly and efficiently.
- Performing disposition of intelligence to establish its relevance to the corporation – crucially, providing context to all-source intelligence to inform the specific threat to IBM and what mitigation options are available.
The Cyber Security Threats Manager is responsible for building and maintaining the Intelligence collection and dissemination plan - aligned with the ISTAR framework - to support the IBM’s Cyber Defense strategy. A vital part of the Senior Manager’s role is understanding the needs and priority requirements of Threats “end-users” – including the other cyber defense teams. Here, the Senior Manager is also part ‘Product Owner’ and is responsible for the developing and maintaining relationships with end-users for mutual benefit. To do this, they must have a sound appreciation of the work performed by other teams and the pressures they face.
Finally, the Senior Manager may also lead work with external agencies – such as ENISA and the NCFTA. At times, this may require them to represent IBM within external communities, which includes conferences and partnership programs.
Preferred Education
Bachelor's Degree
Required Technical And Professional Expertise
- Deep, demonstrable knowledge of cyber security threats – including attack methods, patterns and practices, adversaries – capabilities, motivations and opportunities, malicious software / living off the land, adversary infrastructure.
- Deep knowledge in the decomposition of threats and modeling them to design, implement, tune and manage cyber security defenses.
- Thorough, demonstrable understanding of Threat Intelligence practices and tradecraft.
- Understanding and practical awareness of Threat Hunting practices and tradecraft, as required to support the Threat Hunt team and set overall direction for the Threats team.
- Experience working with external partners including government agencies.
Preferred Technical And Professional Experience
- Experience with IBM technologies – hardware and software.
- Experience with prototyping and creating early-stage IT infrastructure.
- Experience applying AI technologies to reduce toil and in solving practical cyber threats-related problems.
- Strong investigative experience.
- Experience in software development, security within the development lifecycle and Continuous Integration / Continuous Delivery technologies.
- Experience working with cyber-physical security teams.
- Experience leading and maintaining external partnerships and related programs.