Job SummaryAs a Cyber Security Incident Commander, you will be responsible for safeguarding our organization's digital assets by promptly identifying, analyzing, and responding to cyber security incidents. You will play a critical role in minimizing the impact of security breaches and preventing future incidents through proactive measures and continuous improvement of our incident response processes.
Responsibilities- Incident command & response
- Serve as incident commander for mid-tier and major incidents: own the full lifecycle and direct cross-functional workstreams (IT, Legal, Communications/PR, Engineering, executives).
- Monitor alerts and logs; triage and prioritize incidents by severity, criticality, and business impact.
- Execute incident response playbooks to contain, mitigate, and remediate breaches, then restore affected systems and close off unauthorized access.
- Act as primary point of contact to executive leadership and the CISO, translating technical events into business-impact briefings.
- Forensics & analysis
- Conduct host, network, memory, and cloud/hybrid forensics to determine root cause, scope, and extent of compromise - preserving evidence and maintaining chain of custody to legal and regulatory standards.
- Perform malware triage and static/dynamic analysis, including sandbox detonation, to establish capability and indicators of compromise.
- Integrate threat intelligence and proactively hunt for adversary TTPs mapped to MITRE ATT&CK.
- Leverage AI-enabled tooling to accelerate triage, enrichment, and investigation (AI First mindset).
- Readiness & continuous improvement
- Own post-incident reviews and root cause analyses; capture lessons learned and drive remediation to closure.
- Develop and mature incident-response playbooks, tabletop exercises, and readiness drills.
- Organize and execute security exercises including Purple Team Exercises, penetration tests, and audits.
- Define and report IR metrics (MTTD, MTTR) and major-incident tracking to leadership.
- Program & collaboration
- Prepare detailed incident reports covering timeline, impact, remediation, and lessons learned.
- Coordinate with external parties including law enforcement, regulators, and third-party vendors.
- Develop security policies, procedures, and best practices; perform risk assessments and audits for compliance with industry standards.
- Evaluate and recommend security technologies, partnering with IT to design and implement solutions.
- Lead and mentor junior analysts, fostering continuous learning.
- Stay current on emerging threats, vulnerabilities, and industry trends.
Qualifications- Bachelor's degree in Computer Science or related field.
- Advanced certifications such as CISSP or incident-response/forensics GIAC certifications (GCIH, GCFA, GCFE, GNFA) are preferred
- Minimum five years experience in Information Technology
- Minimum three years of direct IT Security experience in Cyber Security operations and Incident Response
- Experience performing event and log analysis including one or more of the following: Anti-Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security
- Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means
- Solid working knowledge of networking technology and tools, firewalls, proxies, IDS/IPS, encryption, SIEM and EDR
- Experience writing scripts, tools, or methodologies to enhance the investigative process
- Working knowledge of the MITRE ATT&CK framework and the NIST incident response lifecycle (NIST SP 800-61).
- Hands-on experience with industry-standard forensic toolsets and with cloud forensics across major cloud and productivity platforms.
- Familiarity with AI tools and an AI First mindset.
Pay is competitive and based on a number of job-related factors, including skills and experience. The starting pay rate/range at time of hire for this position in the posted location is $83,538.00 - $137,241.00 / year. The rate/range provided herein is the anticipated pay at the time of hire, and does not reflect future job opportunity.