Company
ABB is a global industrial leader in automation, energy and robotics, present in over 100 countries. We are committed to technological innovation and the continuous improvement of processes through digital transformation.
Mission of the position and Location of the position:
We are looking for a Global Threat Manager – Detect & Response to lead and mature the capabilities of our Cyber Fusion Center (CFC) and Security Operations Center (SOC). You will shape strategy, oversee threat and risk management, and ensure coordinated incident response across ABB’s global footprint.
This role is 100% remote in Spain, with occasional interaction across time zones to align worldwide operations.
Description of responsibilities:
- Lead CFC & SOC capabilities: define roadmap, KPIs and operating model for both the Cyber Fusion Center and SOC.
- Strategic threat & risk management: develop and maintain a global threat landscape view, mapping critical risks to business priorities.
- Incident response oversight: ensure robust processes, playbooks and tooling are in place; coordinate major incident handling and post-mortem analyses.
- Stakeholder engagement: present risk briefings and recommendations to the CISO, executive leadership and regional security teams.
- Continuous improvement: drive program-level initiatives—automation, orchestration and hardening—to elevate detection and response maturity.
- Cross-functional collaboration: partner with Cyber Threat Intelligence, Technical Risk, Forensics and Business IS to deliver an integrated security posture.
Must haves:
- Experience: ≥15 years in Cybersecurity and IT services, with a proven track record leading Threat Intelligence, Incident Response or SOC teams.
- Certifications: CISSP, CISM, GSEC, GCIH or equivalent.
- Domain expertise: deep understanding of Information Security principles, Threat & Risk methodologies and major detection frameworks (e.g. MITRE ATT&CK).
- Technical fluency: hands-on familiarity with SIEM, EDR, SOAR and related security technologies.
- Communication: excellent ability to distill complex technical issues into clear, actionable executive reports.
- Languages: fluent in English (C1/C2) and high proficiency in Spanish.
Nice to have:
- Scripting or programming skills (Python, PowerShell) for automation.
- Experience with cloud security platforms (AWS, Azure, GCP).
- Additional vendor certifications (e.g. AWS Security Specialty, Azure Security Engineer).
- Familiarity with Agile/Scrum methodologies and PMP or PRINCE2 project management.
- Previous exposure to global digital transformation projects in industrial settings.