Senior Cyber Defense Manager - Incident Response
Core
Lead the Cyber Incident Response Program, overseeing the full incident lifecycle, managing detection capabilities, and transitioning MSSP services.
Role type
Senior Cyber Defense Manager (Incident Response)
Builds
Incident response playbooks, detection engineering improvements, and MSSP service transitions
Domain
Cybersecurity / Incident Response / Threat Detection
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Incident response lifecycle management, forensic analysis, SIEM/EDR/XDR configuration, MSSP transition management, team leadership, executive reporting, regulatory compliance alignment
Preferred skills
Regulated industry experience, hands-on Splunk/Elastic/CrowdStrike/Sentinel experience, SOC/IR function maturation
Technologies
SIEM, EDR, XDR, SOAR, Threat Intelligence Platforms, Splunk, Elastic, CrowdStrike, Microsoft Defender, Sentinel
Responsibilities
Oversee incident response lifecycle (preparation, identification, containment, eradication, recovery, lessons learned), manage day-to-day IR operations including triage and forensic analysis, develop and test IR playbooks and escalation procedures, drive detection engineering improvements (SIEM tuning, threat intel integration), lead MSSP services transition and governance, build and mentor the IR team, serve as primary point of contact for major incidents and brief executives, align practices with NIST/ISO/MITRE standards
Seniority
Senior, hands-on IC with leadership responsibilities