Incident Response Manager
Core
Senior technical leader managing complex cybersecurity incident response engagements, mentoring responders, and acting as a trusted advisor to clients during crises.
Role type
Senior IC Incident Response Manager
Builds
Incident response playbooks, investigation reports, executive summaries, and client deliverables
Domain
Cybersecurity / Incident Response / Digital Forensics
Deliverable
client delivery
Required skills
Incident response leadership, forensic investigation, threat hunting, risk management, executive communication, project team management, legal/regulatory compliance, SIEM utilization, EDR utilization, scripting/automation
Preferred skills
Enterprise ransomware investigation, cyber resilience strategy, legal/cyber insurance coordination, team building, financial management of consulting engagements
Technologies
Splunk, Elastic, Microsoft Sentinel, FortiSIEM, CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, Carbon Black, PowerShell, Python, Bash, Windows, Linux, Active Directory, Microsoft Entra ID, Microsoft 365, AWS, Azure, Google Cloud
Responsibilities
Lead multiple concurrent incident response engagements involving ransomware, data breaches, insider threats, cloud compromises, and advanced threat actor activity; Provide executive-level briefings to CISOs, CIOs, legal counsel, and boards; Direct forensic investigations, threat hunting, containment, eradication, and recovery; Review and approve technical findings and client deliverables; Mentor Incident Response consultants and senior staff; Support business development through proposal development and strategic discussions; Contribute to thought leadership via whitepapers and presentations
Seniority
Senior, hands-on IC with leadership responsibilities