Hub International Limited

Manager, Security Incident Response

Hub International Limited$130K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in technology or equivalent experience
  • 10+ years of experience with programming/scripting languages (Powershell, Python, shell scripting)
  • Extensive knowledge of TCP/IP, DNS, CDN, HTTP, WAF, OAuth, SAML protocols
  • 3+ years working with cloud infrastructure (AWS, Azure, GCP)
  • 5+ years with Microsoft Active Directory/Entra and O365 services
  • Hands-on experience with SIEM, EDR, and SOAR platforms
  • Experience in digital forensics and incident response (DFIR) including log analysis and evidence handling

Responsibilities

  • Manage the Security Incident Response Team to address security threats
  • Oversee the full incident response lifecycle from detection to post-incident review
  • Provide 24/7 emergency support for critical incidents
  • Collaborate with IT to ensure compliance with corporate security policies
  • Mentor team members and facilitate continuous professional growth
  • Create scalable incident response processes and playbooks
  • Conduct post-incident reviews to improve processes and outcome

Benefits

  • Comprehensive health/dental/vision/life/disability insurance
  • Flexible Spending Accounts (FSA) and Health Savings Accounts (HSA)
  • 401(k) retirement plan
  • Paid time off including vacation, sick days, and holidays
  • Eligible for annual bonuses, equity, and commissions
Full Job Description
Job Description

Job Description

In this role, you will manage the Security Incident Response team; for detecting and identifying cyber threats, as well as containment and remediation of these threats. This role owns the full incident response lifecycle-detection, triage, containment, eradication, recovery, and post-incident review-and is responsible for building a scalable Incident Response function that pairs reactive response capability with proactive detection engineering and threat hunting. The Manager ensures investigations are conducted with sound forensic methodology, including log and audit-trail analysis across cloud and on-premises platforms, accurate scoping of impacted systems and accounts.

Objectives of this Role
  • Manages and is responsible for the successful completion of all tasks in assigned projects.
  • Lead and manage a Security Incident Response Team focused on responding to security threats and maintaining HUB's critical threat detection and response suite of security applications.
  • Available 24/7 for any critical incidents that may arise that require immediate resolution, providing leadership and direction to a multi-disciplinary IT team.
  • Work with IT teams to ensure managed environments and procedures comply with defined corporate security policies.
  • Mentor and develop team members to help foster individuals' professional growth.
  • Engage with teams to practice continuous improvement in processes and tooling.
  • Supervises assigned operations team members and performs personnel actions including hiring, individual goal tracking, training, performance evaluation.
  • Maintains current knowledge of relevant technology, bringing forth ideas for modernization and improvement.
  • Identify potential technical issues and assist in engineering possible solutions
  • Engage with management regularly with reports on project status, activities, and achievements
  • Lead "Technical Archeology" efforts (Platform and System Decomposition), in respect to gaps identified during incident response activities.
  • Lead the creation of security incident response processes and playbooks that are scalable, consistent, repeatable, and supportable.
  • Direct forensic investigations of security incidents, including analysis of cloud audit logs (e.g., Microsoft 365 Unified Audit Log), endpoint and network telemetry, and identity activity, to identify indicators of compromise, establish attack timelines, and determine scope of impact.
  • Design and maintain a tiered escalation framework and on-call rotation so that incidents are routed to the appropriate analyst and management level based on severity and business impact.
  • Drive maturity of the Incident Response and Detection Engineering functions against a KPI-based roadmap, tracking metrics such as mean time to detect (MTTD), mean time to respond (MTTR), alert triage volume, and case closure rates.
  • Balance the team's dual-track structure of reactive Incident Response and proactive Detection Engineering/threat hunting, ensuring each track has clear ownership, workflows, and staffing.
  • Conduct post-incident reviews and root-cause analysis to capture lessons learned, close process gaps, and feed findings back into playbooks and detection content.

Daily and Monthly Responsibilities
  • Communicate with stakeholders to assist in the identification of business, technical, and operational requirements.
  • Analysis, of root-cause analysis for service interruption, to establish preventive measures, mitigations, or needed changes.
  • Evaluate security applications, infrastructure and associated costs at regular intervals
  • Be responsible for analysis and recommendation of configuration changes, process improvements or visibility enhancements to the support and scaling of HUB's security response.
  • Triage and prioritize incoming security alerts and incidents daily, assigning severity and escalating to the appropriate analyst or on-call tier.
  • Perform or oversee forensic log review for active investigations (e.g., Microsoft 365 Unified Audit Log, EDR, network/firewall logs), documenting findings and preserving evidence in line with chain-of-custody practices.
  • Report monthly on incident response KPIs, including mean time to detect (MTTD), mean time to respond (MTTR), incident volume, and case closure rates, to leadership.
  • Facilitate tabletop exercises and periodic playbook/runbook reviews to validate incident response readiness and identify process gaps.


Skills and Qualifications
  • Bachelor's degree in technology or applicable experience.
  • 10+ Years of experience with programming/scripting languages (Powershell, python, shell scripting)
  • Extensive experience with: TCP/IP, DNS, CDN, HTTP, WAF, OAuth, SAML
  • 3+ years of experience with cloud infrastructure as a service (AWS, Azure, GCP)
  • 5+ years of experience with Microsoft Active Directory/Entra and O365 services and technology
  • 5+ years of experience with security platforms, automation tooling
  • Hands-on experience with SIEM, EDR, and SOAR platforms for detection, alerting, and investigation.
  • Experience conducting digital forensics and incident response (DFIR), including log analysis, timeline reconstruction, and evidence handling with chain-of-custody rigor.
  • Working knowledge of incident response frameworks (e.g., NIST 800-61, SANS) and experience developing incident response playbooks and runbooks.
  • Experience building or maturing an incident response team, including defining KPIs/metrics and driving a maturity roadmap.
  • Collaboration, prioritization, and adaptability skills
  • Desire to continuously develop your skills and knowledge


The expected salary range for this position is $ 130,000 to $150,000 and will be impacted by factors such as the successful candidate's skills, experience and working location, as well as the specific position's business line, scope and level. HUB International is proud to offer comprehensive benefit and total compensation packages which could include health/dental/vision/life/disability insurance, FSA, HAS and 401(k) accounts, paid-time-off benefits such as vacation, sick, personal, floating holidays and company holidays. In addition, eligible annual bonuses, equity and commissions may be available for some positions.

Department Information Technology

Required Experience: 5-7 years of relevant experience

Required Travel: Negligible

Required Education: Bachelor's degree (4-year degree)

About Hub International Limited

Hub International Limited is a leading full-service global insurance broker providing property and casualty, life and health, employee benefits, investment and risk management products and services. With more than 13,000 employees in offices located throughout North America, Hub's vast network of specialists provides peace of mind on what matters most by protecting clients through unrelenting advocacy and tailored insurance solutions.
Learn more about Hub International Limited
Size
13,000 employees
Industry
Founded
1998

Similar Jobs

More Jobs at Hub International Limited

More Information Technology Jobs

Find similar Manager, Security Incident Response jobs: