Job Summary
The Lead Cyber Incident Responder (T3) provides expert technical leadership during security incidents, driving rapid detection, triage, containment, eradication, and recovery activities. The role serves as the escalation point for complex incidents, maintains operational readiness of incident response capabilities, mentors responders, and ensures clear communication across technical and business stakeholders. The position also supports incident investigations, response automation, governance, reporting, readiness exercises, process improvement, and on-call operational leadership.
Key Responsibilities
• Lead and coordinate security incident response operations from initial alert triage through incident closure
• Maintain situational awareness of potential and active security incidents and escalate incidents in accordance with documented processes and procedures
• Validate and prioritize alerts from SIEM, EDR, NDR, SOAR, threat intelligence sources, and security hunting activities
• Conduct detailed incident investigations across endpoints, servers, cloud services, and network telemetry
• Direct containment actions including host isolation, account disablement, network blocking, identity access revocation, and emergency security control changes
• Ensure eradication and recovery activities are executed, validated, and documented
• Determine appropriate escalation paths and coordinate engagement with senior management, Legal, HR, DPO, Fraud, BCM, and third-party teams when required
• Own investigations from initial triage through recovery by identifying investigative leads, validating hypotheses, driving evidence collection, and pursuing relevant investigative avenues
• Maintain accurate and comprehensive case documentation, including investigative actions, decisions, evidence, rationale, timelines, containment actions, stakeholder communications, and recovery activities
• Maintain accurate incident timelines, chain-of-evidence discipline, and investigation notes in accordance with established processes, standards, and templates
• Identify and proactively coordinate the involvement of additional internal or external teams to accelerate investigation, containment, and recovery
• Drive incident battle rhythm, including situation updates, decision points, stakeholder engagement, and evidence-based impact assessments
• Define incident objectives, assign tasks, track outstanding actions, and maintain cross-team accountability
• Provide technical leadership for assigned incidents by directing investigative priorities and maintaining response momentum until objectives are achieved
• Communicate incident status, impact, and risk clearly to technical teams, senior stakeholders, and executives when required
• Continuously reassess incident priorities, identify blockers, follow up on assigned actions, and drive investigations toward containment and recovery
• Ensure lessons-learned sessions are completed and improvement actions are documented, tracked, and closed
• Collaborate with Cyber Threat Intelligence (CTI) teams to enrich investigations, validate Indicators of Compromise (IoCs), connect activity to adversary behavior, and develop threat-hunting hypotheses
• Recommend detection improvements, signature updates, and tuning based on incident findings
• Support tactical threat hunts and investigative pivoting based on novel attacker techniques identified during incidents
• Ensure required stakeholder notifications, approvals, and communications are initiated at the appropriate stages in accordance with response procedures and regulatory requirements
• Participate in vulnerability response and purple-team activities in collaboration with relevant security teams
• Recommend optimization and improvements for incident response tooling, including EDR, forensic toolkits, logging platforms, case management systems, and SOAR playbooks
• Lead the development, maintenance, and continuous improvement of incident response runbooks
• Identify automation opportunities to reduce manual effort and improve response speed
• Lead incident response tabletop exercises, live-action drills, simulations, and continuous improvement activities
• Support broader tabletop exercises, simulations, and purple-team activities to validate organizational readiness
• Produce high-quality incident reports, impact analyses, and executive summaries
• Track incident response metrics including MTTD, MTTA, MTTC, containment quality, repeat incident patterns, and root-cause themes
• Ensure incident response activities align with security policies, regulatory requirements, and evidentiary standards
• Provide assurance that security controls perform as expected during incidents and identify deviations requiring remediation
• Ensure complete and timely end-of-shift handovers and distribution of relevant incident information
• Support audit requests related to SOC, security monitoring, and incident response activities
• Drive incident response process improvements based on post-incident reviews and postmortem activities
• Mentor junior responders and analysts and provide coaching on investigative techniques, documentation quality, containment strategies, and stakeholder management
• Act as the escalation point for major incidents occurring outside standard business hours
• Promote operational readiness, professionalism, and evidence-based decision-making across the incident response team
• Participate in stakeholder meetings to review current activities, emerging threats, operational risks, ongoing investigations, and shift handovers
• Lead daily stand-ups to align responders on active cases, priorities, risks, ownership, and planned activities
• Ensure blockers are identified and addressed promptly
• Proactively ensure appropriate teams, including Legal, HR, DPO, Fraud, IT Operations, Identity, Cloud, and Network teams, are engaged when required
• Validate that critical issues are escalated promptly through appropriate channels and that relevant stakeholders remain informed
• Maintain situational awareness of significant alerts, ongoing incidents, and operational activity during on-call periods
• Ensure emerging patterns and significant operational context are properly documented and handed over between shifts
• Maintain continuous on-call coverage throughout assigned rotations and ensure complete handover of active incidents, ongoing activities, and operational context when coverage changes
Required Qualifications
• Strong experience in cybersecurity incident detection, investigation, triage, containment, eradication, and recovery
• Demonstrated experience leading complex security incidents and serving as a Tier 3 escalation point
• Strong experience with SIEM, EDR, NDR, SOAR, threat intelligence, and security monitoring technologies
• Experience conducting investigations across endpoints, servers, cloud environments, and network telemetry
• Strong understanding of incident response processes, investigative methodologies, evidence handling, and incident documentation
• Experience with host isolation, identity and access revocation, network blocking, and emergency security control changes
• Experience developing incident timelines, documenting investigative evidence, and maintaining chain-of-evidence discipline
• Strong understanding of incident command, stakeholder management, escalation, and cross-functional coordination
• Experience working with Cyber Threat Intelligence teams, Indicators of Compromise (IoCs), threat hunting, and adversary behavior analysis
• Experience developing and maintaining incident response runbooks and operational procedures
• Experience identifying automation opportunities and improving incident response processes
• Experience with incident response metrics, executive reporting, risk assessment, and post-incident reviews
• Strong communication skills with the ability to translate complex technical findings into clear information for technical and non-technical stakeholders
• Demonstrated leadership and mentoring capabilities
• Ability to work effectively under pressure while managing multiple incidents, priorities, and stakeholder requirements
• Ability to participate in on-call rotations and provide structured shift handovers