Cybersecurity Incident Response Commander

ISA Cybersecurity

$135K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in cybersecurity, with 7+ years in incident response and digital forensics.
  • Proven experience as Incident Commander for high-severity incidents like ransomware and data breaches.
  • Expert understanding of the incident response lifecycle and digital forensic methodologies.
  • Hands-on skills in various forensic processes across multiple environments including cloud platforms.
  • Knowledge of relevant standards like NIST SP 800-61 and ISO 27001:2022.
  • Ability to communicate complex cybersecurity concepts to non-technical stakeholders effectively.
  • CISSP certification required; additional relevant certifications preferred.

Responsibilities

  • Serve as Incident Commander for IR Retainer and Emergency engagements.
  • Lead comprehensive digital forensic investigations across various tech terrains.
  • Ensure legal compliance through proper chain-of-custody management.
  • Develop and refine DFIR processes and procedures.
  • Conduct incident reviews and present findings to stakeholders.
  • Educate clients and internal teams on best practices for incident response.
  • Integrate threat intelligence to enhance incident analysis.

Benefits

  • Remote-first work environment with minimal office presence required.
  • Collaborative office space for occasional team meetings and social events.
  • Opportunities for professional development and career advancement.
  • Inclusive culture fostering team-building activities throughout the year.
  • Flexibility in work hours and arrangements to support work-life balance.
Full Job Description
About the Role:

The Cybersecurity Incident Response (IR) Commander is the technical and operational authority for ISA Cybersecurity's Digital Forensics & Incident Response (DFIR) function and holds expert-level command of the Security Incident Response (SIR) service during client engagements. The role is structured as a Subject Matter Expert and Incident Commander rather than a line-management position: technical authority, judgment under pressure, and external-grade SME presence are the primary contributions.

The IR Commander leads the Response side of ISA's Protect-Detect-Respond operating model through influence, process and playbook ownership, and direct command on every Emergency and IR Retainer engagement. People-leadership behaviors including coaching analysts, championing career pathways, and modelling composure under stress are valued and expected to grow over time, but formal direct reports are not a requirement of the role at hire. Development and ongoing evolution of the Incident Response program is subject to the final authority of the Senior Director, DFIR Services who provides strategic direction and ultimate accountability for the program's scope, structure, and priorities.

This role reports to the Senior Director, DFIR Services. The successful candidate will have extensive experience in personally commanding and leading ransomware, business email compromise, data exfiltration, and complex multi-vector engagements, and will be recognized externally as a subject-matter expert in incident response and digital forensics.

Responsibilities:
  • Serve as Incident Commander for all IR Retainer engagements and Emergency IRs delivered by ISA Cybersecurity.
  • Lead digital forensic investigations across endpoint, server, network, mobile, and cloud sources.
  • Ensure chain-of-custody discipline suitable for legal proceedings.
  • Develop, manage, and continuously refine DFIR processes, procedures, playbooks, and runbooks (DFIR policy authorship is out of scope and sits with other functions).
  • Conduct regular reviews and updates to DFIR people, processes, and technologies to ensure alignment with organizational objectives and the evolving threat landscape.
  • Present incident and digital evidence reports to key stakeholders including law enforcement, legal counsel, and clients; Lead post-incident reporting and client walk-throughs and translate lessons learned into process, playbook, tooling, and training improvements.
  • Educate internal and external stakeholders on incident identification and response best practices.
  • Support presales activities including proposals, Statements of Work (SOWs), and RFP responses.
  • Own the technical quality of the DFIR practice in alignment with the Security Incident Response (SIR) service card.
  • Integrate threat intelligence into incident analysis and feed TTPs back into detection content and hunting hypotheses.
  • Identify, define, track, and report on DFIR metrics; run continuous-improvement cycles against them to drive service-quality and operational outcomes.
  • Lead and manage the IR readiness program including IR Plan engagements, Tabletop Exercises (TTX), and Playbook development and/or validation.
  • Serve as a senior client-facing voice during engagements and a trusted advisor between them; brief executives, boards, regulators, legal counsel, and law enforcement as required.
  • Represent ISA externally as a recognized DFIR subject matter expert - publications, speaking engagements, industry forums, IR community participation, etc.
  • Collaborate closely with SOC leadership, analysts, and Service Owners to ensure incident response remains tightly integrated with detection capabilities and aligned to the broader evolution of ISA's service portfolio.
  • Coach DFIR analysts and Incident Managers through technical authority, case-based pairing, and matrix influence; participate in hiring panels and rotation planning.


Qualifications:
  • 10+ years of progressive experience in cybersecurity, with at least 7 years in incident response and digital forensics roles.
  • Demonstrated experience as Incident Commander on multiple high-severity engagements (e.g., ransomware, BEC, APT intrusion, large-scale data breach).
  • Expert-level knowledge of the incident response lifecycle, containment and eradication strategies, and digital forensic methodologies.
  • Hands-on expertise across host, network, memory, mobile, and cloud forensics, including chain-of-custody discipline suitable for legal proceedings.
  • Proficient working with Windows, Linux, and MacOS
  • Experience with multi-cloud forensics (AWS, Azure, GCP, Microsoft 365, Google Workspace) and SaaS-platform investigations.
  • Experience with OSINT (Open-Source Intelligence), including gathering and correlating publicly available information to support threat actor attribution, infrastructure mapping, and exposure analysis, and translating findings into actionable intelligence for client engagements.
  • Working knowledge of multiple security control families such as EDR, SIEM, SOAR, NDR, identity, email security, DLP, and their use during response.
  • Deep familiarity with MITRE ATT&CK and current ransomware/APT TTPs.
  • Working knowledge of NIST SP 800-61, ISO 27035, ISO 27001:2022, NIST CSF, SOC 2, and CSA CCM.
  • Demonstrated ability to identify, define, track, and report on operational and service-quality metrics, and to run continuous-improvement cycles against them.
  • Excellent leadership-by-influence, executive communication, and stakeholder management skills; must be able to communicate clearly under pressure and to non-technical audiences.
  • Trusted advisor presence; ability to brief client executives and boards on cyber risk, governance, and resilience between as well as during incidents.
  • Bachelor's degree in computer science, Information Security, or related field, or equivalent professional experience.
  • CISSP (required).
  • Willingness to participate in 24x7 on-call rotation for IR Retainers and Emergency IRs.
  • Ability to obtain Government of Canada security clearance.
  • Strong English language skills, written and verbal.

Nice to Have
  • People leadership experience including coaching, mentoring, performance feedback, hiring panels, even where the role has not formally carried direct reports.
  • Experience leading or contributing to MSSP service delivery including contractual SLAs, RACI models, 24x7 operations, and onboarding/transition workflows.
  • Recognized externally as a subject matter expert through published research, conference talks, MITRE ATT&CK contributions, media commentary, or industry awards.
  • Experience supporting law enforcement engagements (RCMP NC3, CCCS/CCIRC, FBI Cyber), Anton Piller orders, expert witness testimony, or regulatory investigations.
  • Experience with dark web monitoring and social-media threat monitoring.
  • Multilingual capability is an asset.

Certifications
  • Required: CISSP
  • Strongly preferred: GCIH, GCFA, GCIA, GX-FA, GSE
  • Preferred: OSCP, CISM, CCSP, EnCE, CHFI, ECIH
  • Cloud (any of): AWS Security Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer


We operate in a remote-first environment. Office presence is typically less than 20% of the time, varying by role and work requirements. Our office space, located at Bloor and Islington, is a collaborative space designed for in-person meetings and drop-ins. We enjoy hosting in-person quarterly townhalls and social events throughout the year to encourage teambuilding and collaboration.

Vacancy Status: This posting is for an existing vacancy.
Salary Range: $135,000-$157,500- $180,000

AI Disclosure: ISA Cybersecurity does not currently use artificial intelligence tools as part of our recruitment process.

Similar Jobs

More Jobs at ISA Cybersecurity

More Information Technology Jobs

Find similar Cybersecurity Incident Response Commander jobs: