Incident Command & Threat Hunting Operations Manager
Core
Lead hypothesis-driven threat hunting and major incident command operations to improve detection, containment, and operational rigor across distributed teams.
Role type
Senior IC Incident Command & Threat Hunting Operations Manager
Builds
Scalable incident response and threat hunting practices, audit-ready governance models, and cross-functional crisis response capabilities.
Domain
Cybersecurity / Security Operations / Incident Response
Deliverable
production ML models | infrastructure | client delivery
Required skills
Threat hunting, incident command, major incident governance, cross-functional coordination, post-incident review leadership, adversary TTPs understanding, operational framework design, crisis response management, team leadership, detection engineering, telemetry analysis, case management platforms.
Preferred skills
CISSP, CISA, CISM, SANS, OSCP, Security+ certifications, fraud/abuse ecosystem experience, detection automation pipelines.
Technologies
Kusto, ServiceNow, Azure, M365, Partner Center, SIEM, MFIRP, ICS.
Responsibilities
Ensure hunts are hypothesis-driven and measurable; own and evolve the Major Incident governance model; act as incident command authority for high-severity incidents; coordinate cross-functional response; sponsor post-incident reviews; drive clarity in ambiguity and resolve decision bottlenecks; build high-performing teams.
Seniority
Senior, hands-on IC with leadership responsibilities