Manager, Security Incident Response
Core
Manage the Security Incident Response team to detect, contain, and remediate cyber threats, owning the full incident lifecycle from detection to post-incident review.
Role type
Manager, Security Incident Response (IC)
Builds
Scalable incident response function, detection engineering, and threat hunting capabilities
Domain
Cybersecurity, Cloud Infrastructure, Digital Forensics
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response lifecycle management, forensic log analysis, threat hunting, playbook development, team leadership, KPI tracking, root cause analysis, cloud infrastructure management, security automation, digital forensics
Preferred skills
Technical archeology, process modernization, stakeholder communication
Technologies
Microsoft 365 Unified Audit Log, EDR, SIEM, SOAR, AWS, Azure, GCP, Microsoft Active Directory/Entra, O365, Powershell, Python, Shell scripting, TCP/IP, DNS, WAF, OAuth, SAML
Responsibilities
Lead and manage the Security Incident Response Team; conduct forensic investigations and log analysis; design and maintain incident response processes and playbooks; drive maturity of detection engineering and threat hunting functions; balance reactive response and proactive detection tracks; report on incident response KPIs; facilitate tabletop exercises and root cause analysis.
Seniority
Manager, hands-on IC with team leadership