Incident Manager

Lendistry

$118K — $136K *
US-AnywhereRemote in Los Angeles, CA
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years in incident response, GRC, or risk management, preferably in fintech or financial services.
  • Direct experience as an Incident Commander or similar role leading incident management.
  • Familiarity with compliance frameworks: SOC 2, GLBA Safeguards Rule; knowledge of ISO/IEC 27001.
  • Ability to build and track KPIs for incident response and compliance programs.
  • Strong documentation skills for creating audit-ready records under tight deadlines.
  • Professional certifications such as ICS-100/200 preferred.
  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience.

Responsibilities

  • Lead response for security and operational incidents with full command over response activities.
  • Develop and implement Incident Action Plans with clear ownership and timelines.
  • Make critical decisions under pressure, balancing safety and regulatory requirements.
  • Conduct post-incident reviews, implementing corrective actions to enhance future responses.
  • Coordinate physical security incident management with cross-functional teams and local authorities.
  • Serve as the central communication point between technical responders and non-technical stakeholders during incidents.
  • Maintain and update compliance documentation and ensure correlation between incident response and compliance programs.

Benefits

  • Comprehensive Medical, Dental, and Vision Insurance
  • Generous Paid Time Off, including Birthday Day Off
  • 12 Paid Company Holidays
  • 401(k) Match and Flexible Spending Accounts (FSA and HSA)
  • Paid Life and Disability Insurance
  • Pet Insurance
  • Employee Assistance Program (EAP)
  • Professional Development Courses
  • In-office snacks, drinks, and gym facilities
  • Engagement activities aimed at team building and morale support.
Full Job Description
This position is based onsite at our Los Angeles, CA location. Candidates must be able to work in-office as part of the role's regular schedule.

A Day in the Life

The Incident Manager leads the organization's security and operational incident response function while supporting the GRC program that keeps the company audit-ready. This role owns incident command from detection through resolution, directs cross-functional response across Security, Engineering, IT, Legal, Compliance, Communications, Facilities, HR, and Executive Leadership, and translates each incident into measurable improvement through KPIs, after-action documentation, and updated controls. The role also supports ongoing compliance obligations (SOC 2, GLBA Safeguards Rule, ISO/IEC 27001) so that incident response and compliance posture reinforce each other rather than operating as separate functions.

What You'll Be Doing

Incident Command & Crisis Leadership
  • Serve as Incident Manager for security and operational incidents, holding full command and control over response activities.
  • Build, execute, and maintain Incident Action Plans (IAPs) that give each response a clear structure, owner, and timeline.
  • Make time-sensitive decisions under pressure, weighing safety, regulatory exposure, and business continuity.
  • Lead post-incident reviews and drive corrective actions through to closure.
  • Run tabletop exercises and simulations to pressure-test playbooks and team readiness.


Physical Security Operations
  • Manage physical security incidents, including unauthorized access, safety threats, and facility disruptions.
  • Coordinate with Facilities, HR, Legal, and local authorities as needed during physical security events.
  • Ensure physical security controls align with cybersecurity, business continuity, and compliance programs.


Cross-Functional Collaboration
  • Act as the central point of coordination between technical responders and non-technical stakeholders during an incident.
  • Direct and coordinate Security Operations, Engineering, IT, Legal, Compliance, Communications, and Executive Leadership throughout the incident lifecycle.
  • Engage external parties - law enforcement, emergency services, regulators, and vendors - when an incident requires it.
  • Partner with Security, Engineering, and Compliance to keep response playbooks and escalation paths current.


Compliance Management
  • Support the SOC 2 compliance program (Type I and Type II) - assisting with control ownership, evidence collection, auditor coordination, and remediation tracking.
  • Support alignment with ISO/IEC 27001, including risk assessments, Statement of Applicability support, and control mapping.
  • Support GLBA Safeguards Rule obligations, including related vendor oversight and risk documentation.
  • Conduct periodic risk assessments and control-effectiveness reviews across people, process, and technology.
  • Support regulator, auditor, and customer due-diligence requests.


KPIs & Metrics
  • Define and track incident response metrics (e.g., time to detect, time to contain, time to resolve, recurrence rate) to measure program maturity.
  • Develop compliance KPIs (control exceptions, remediation aging, audit findings closure rate) for leadership reporting.
  • Use trend data from incidents and audits to prioritize control investment and process changes.
  • Report metrics and program status to Executive Leadership on a recurring cadence.


Documentation
  • Maintain incident response plans, IAP templates, and after-action reports.
  • Maintain GRC documentation - policies, standards, procedures, and the risk register - under a continuous-compliance model.
  • Document control evidence, audit responses, and remediation records to support SOC 2, ISO 27001, and GLBA audits.
  • Keep playbooks, escalation matrices, and contact trees current and accessible.


Your Areas of Knowledge and Expertise
  • 3-5 years of experience in incident response, GRC, or risk management, preferably in a regulated environment such as fintech or financial services.
  • Direct experience serving as Incident Commander or in a comparable incident leadership role, including running IAPs and post-incident reviews.
  • Familiarity with SOC 2 and GLBA Safeguards Rule compliance programs; working knowledge of ISO/IEC 27001.
  • Experience building and tracking KPIs/metrics for incident response and compliance programs.
  • Strong written documentation skills; comfortable producing audit-ready records under time pressure.
  • Professional certifications such as ICS-100/200 preferred.
  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience/certifications.


Why You'll Love Working Here:
  • Comprehensive Medical, Dental, and Vision Insurance
  • Generous Paid Time Off
  • Birthday Day Off
  • 12 Paid Company Holidays
  • 401(k) Match
  • FSA and HSA
  • Paid Life Insurance
  • Paid Disability Insurance
  • Pet Insurance
  • Employee Assistance Program (EAP)
  • Professional Development Courses
  • In Office Provided Snacks and Drinks
  • Gym Facilities (LA & Tustin/CEC Offices)
  • In Office Engagement Activities


Compensation Range

The US base salary range for this full-time position is $118,300-$136,300 annually.

Our salary ranges are determined by role, level, and location.

The range displayed on each job posting reflects the minimum and maximum base salary for new hires for the position across all US locations. Within the range, individual pay is determined by multiple factors like job-related skills, experience, and state of residence. Your recruiter can share more about the specific salary range during the interview process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include any variable compensation elements.

Physical Requirements

This is a stationary position that requires frequent sitting (approximately 95%), repetitive wrist motions, grasping, speaking, listening, close vision, and the ability to adjust focus. It also may require occasional standing, lifting, carrying of 20lbs or less, walking, kneeling, bending/stooping, twisting, pulling/pushing, and reaching above the shoulder. Employees in this position must be physically able to efficiently perform the essential functions of the position.

Similar Jobs

More Jobs at Lendistry

  • SBA Workout Manager
    $85K — $115K *
    Tustin, CA 92780 (Orange County)
    Finance & Insurance
    In-Person
  • SBA Workout Manager
    $85K — $115K *
    Los Angeles, CA 90011 (Los Angeles County)
    Finance & Insurance
    In-Person
  • Sr Closing Manager
    $85K — $110K *
    Tustin, CA 92780 (Orange County)
    Finance & Insurance
    Hybrid
  • Sr Closing Manager
    $85K — $110K *
    Los Angeles, CA 90011 (Los Angeles County)
    Finance & Insurance
    Hybrid
  • Accounting Analyst
    $76K — $87K *
    Tustin, CA 92780 (Orange County)
    Legal & Accounting
    In-Person

More Information Technology Jobs

Find similar Incident Manager jobs: