Qualifications
Responsibilities
Benefits
Job Description:
Lead, Cyber Incident Coordination
Enterprise Security Incident Management (ESIM)
Thomson Reuters' Information Security Risk Management team is seeking a Lead, Cyber Incident Coordination to help mature and improve enterprise incident management capabilities.
This is a coordination and process-focused role rather than a hands-on technical forensics role. The Lead, Cyber Incident Coordination will help direct and organize the response to major cyber incidents, ensuring teams remain aligned, actions are tracked, communications are clear, and business impact is minimized.
In this role, you will serve as a key point of contact during significant security events. You will support the Director, Cyber Incident Management, in driving timely and effective incident response activities; facilitate coordination among technical and business stakeholders; maintain incident records; manage communications and reporting; and ensure corrective actions are completed following an incident.
The role reports directly to the VP of Cyber Defense and works closely with the Director, Cyber Incident Management, who leads the ESIM function.
Key Responsibilities:
Coordinate cyber incident management activities throughout the full incident lifecycle, from activation of cross-functional partners through incident closure.
Facilitate incident bridges, command calls, and working sessions by maintaining structure, tracking decisions, assigning owners and timelines, and ensuring stakeholders understand their roles and the path to resolution.
Support incident management calls chaired by the Chief Information Security Officer by documenting action items, confirming ownership and deadlines, and tracking actions through completion.
Coordinate smaller working groups formed during incidents and provide visibility into their tasks, owners, progress, and dependencies.
Own and maintain the incident record, including timestamped observations, actions, contacts, decisions, and other relevant documentation.
Prepare and manage incident collateral, including executive communications, status reports, fact summaries, and materials required to support notification or disclosure obligations.
Deliver clear written and verbal updates to executive and business stakeholders throughout the incident lifecycle.
Lead post-incident reviews by reconstructing timelines, identifying detection gaps, response delays, and communication breakdowns, and translating findings into corrective actions with accountable owners.
Track long-term remediation activities and partner with risk management and technical teams to ensure complex issues are resolved after incident closure.
Design and facilitate two executive-level tabletop exercises annually, including scenario development, timed injects, facilitator and observer materials, after-action reports, and improvement plans.
Support assessment of incident management and response capabilities against recognized frameworks and partner with security teams to drive cross-functional process improvements.
Maintain ESIM documentation, including SharePoint sites, incident records, runbooks, escalation lists, contact lists, and exercise materials.
Track and report performance measures that demonstrate improvement in areas such as corrective action closure rates and repeat incident rates.
Participate as part of a 24x7 global incident response team on an escalation basis for major incidents, including off-hours or weekend support as needed.
Required Qualifications:
Bachelor's degree or equivalent relevant experience.
Three or more years of experience supporting or leading processes, programs, or operations within Information Technology, Information Security, risk management, or a related field.
Experience participating in or facilitating a major incident bridge, command call, war room, or similar high-pressure coordination environment.
Demonstrated ability to coordinate stakeholders, including senior leaders, without direct authority.
Working knowledge of an incident management framework, such as NIST SP 800-61 or ITIL Major Incident Management, including severity classification and escalation criteria.
Sufficient technical knowledge to understand and accurately document active cyber incident response discussions, risks, actions, and decisions.
Ability to create concise, accurate executive communications and status updates under time pressure.
Strong ability to translate complex technical issues into clear, actionable information for business and executive audiences.
Excellent written and verbal communication skills, with the ability to develop reports and presentations for executive audiences.
Strong organizational, critical-thinking, and attention-to-detail skills, especially when maintaining records that may be relied upon for evidentiary or regulatory purposes.
Proficiency with Microsoft 365 tools, including SharePoint, Teams, and Microsoft Office.
Ability to work effectively in a dynamic environment with ambiguity, competing priorities, and rapid turnaround times.
Strong interpersonal and stakeholder-management skills, with the ability to influence and execute across multiple teams.
Flexibility to support off-hours and weekend incident response activities when necessary.
Preferred Qualifications:
Bachelor's degree in Information Technology, Information Systems, Cybersecurity, or a related field.
Experience leading or supporting cyber security incident response programs or enterprise major incident management processes.
Experience designing or facilitating tabletop exercises, simulations, crisis-management exercises, or structured training programs.
Experience developing post-incident review processes, corrective action plans, and long-term remediation tracking.
Familiarity with executive crisis communications, regulatory notification processes, or enterprise risk management practices.
Experience supporting incident response maturity assessments and process improvement initiatives.
Familiarity with security operations, threat detection, digital forensics, vulnerability management, or other cybersecurity functions.
#LI-LP2
This posting is for proactive recruitment purposes and may be used to fill current openings or future vacancies within our organization.
What’s in it For You?
In the United States, Thomson Reuters offers a comprehensive benefits package to our employees. Our benefit package includes market competitive health, dental, vision, disability, and life insurance programs, as well as a competitive 401k plan with company match. In addition, Thomson Reuters offers market leading work life benefits with competitive vacation, sick and safe paid time off, paid holidays (including two company mental health days off), parental leave, sabbatical leave. These benefits meet or exceeds the requirements of paid time off in accordance with any applicable state or municipal laws. Finally, Thomson Reuters offers the following additional benefits: optional hospital, accident and sickness insurance paid 100% by the employee; optional life and AD&D insurance paid 100% by the employee; Flexible Spending and Health Savings Accounts; fitness reimbursement; access to Employee Assistance Program; Group Legal Identity Theft Protection benefit paid 100% by employee; access to 529 Plan; commuter benefits; Adoption & Surrogacy Assistance; Tuition Reimbursement; and access to Employee Stock Purchase Plan.Thomson Reuters complies with local laws that require upfront disclosure of the expected pay range for a position. The base compensation range varies across locations. For any eligible US locations, unless otherwise noted, the base compensation range for this role is $118,400 USD - $219,800 USD. For Ontario, Canada, the base compensation range for this role is $140,000 CAD - $175,000 CAD. Base pay is positioned within the range based on several factors including an individual’s knowledge, skills and experience with consideration given to internal equity. Base pay is one part of a comprehensive Total Reward program which also includes flexible and supportive benefits and other wellbeing programs. This role may also be eligible for an Annual Bonus based on a combination of enterprise and individual performance.
About Thomson Reuters
Similar Jobs

More Jobs at Thomson Reuters





More Information Technology Jobs