SOC Incident Commander

Altice USA

$83K — $137K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science or related field
  • Preferred advanced certifications like CISSP or GIAC (GCIH, GCFA, GCFE, GNFA)
  • 5+ years in Information Technology
  • 3+ years in Cyber Security operations and Incident Response
  • Experience with log analysis tools such as Anti-Virus, IDS, Firewalls
  • Strong communication skills, capable of conveying complex ideas clearly
  • Proficient in networking technologies, SIEM, and EDR systems

Responsibilities

  • Serve as incident commander for mid-tier and major incidents
  • Monitor alerts and triage incidents based on severity and criticality
  • Execute incident response playbooks to mitigate breaches and restore systems
  • Act as primary contact for executive leadership regarding security incidents
  • Conduct forensic analysis to determine scope and root causes of compromises
  • Integrate threat intelligence for proactive ability to hunt adversaries
  • Lead post-incident reviews and manage continuous improvement processes

Benefits

  • Professional development opportunities and advanced training
  • Collaboration with multi-disciplinary teams
  • Access to cutting-edge AI tools and security technologies
  • Visibility and interaction with executive leadership
  • Mentorship opportunities for junior analysts to encourage growth
Full Job Description
Job Summary

As a Cyber Security Incident Commander, you will be responsible for safeguarding our organization's digital assets by promptly identifying, analyzing, and responding to cyber security incidents. You will play a critical role in minimizing the impact of security breaches and preventing future incidents through proactive measures and continuous improvement of our incident response processes.

Responsibilities

  • Incident command & response
  • Serve as incident commander for mid-tier and major incidents: own the full lifecycle and direct cross-functional workstreams (IT, Legal, Communications/PR, Engineering, executives).
  • Monitor alerts and logs; triage and prioritize incidents by severity, criticality, and business impact.
  • Execute incident response playbooks to contain, mitigate, and remediate breaches, then restore affected systems and close off unauthorized access.
  • Act as primary point of contact to executive leadership and the CISO, translating technical events into business-impact briefings.
  • Forensics & analysis
  • Conduct host, network, memory, and cloud/hybrid forensics to determine root cause, scope, and extent of compromise - preserving evidence and maintaining chain of custody to legal and regulatory standards.
  • Perform malware triage and static/dynamic analysis, including sandbox detonation, to establish capability and indicators of compromise.
  • Integrate threat intelligence and proactively hunt for adversary TTPs mapped to MITRE ATT&CK.
  • Leverage AI-enabled tooling to accelerate triage, enrichment, and investigation (AI First mindset).
  • Readiness & continuous improvement
  • Own post-incident reviews and root cause analyses; capture lessons learned and drive remediation to closure.
  • Develop and mature incident-response playbooks, tabletop exercises, and readiness drills.
  • Organize and execute security exercises including Purple Team Exercises, penetration tests, and audits.
  • Define and report IR metrics (MTTD, MTTR) and major-incident tracking to leadership.
  • Program & collaboration
  • Prepare detailed incident reports covering timeline, impact, remediation, and lessons learned.
  • Coordinate with external parties including law enforcement, regulators, and third-party vendors.
  • Develop security policies, procedures, and best practices; perform risk assessments and audits for compliance with industry standards.
  • Evaluate and recommend security technologies, partnering with IT to design and implement solutions.
  • Lead and mentor junior analysts, fostering continuous learning.
  • Stay current on emerging threats, vulnerabilities, and industry trends.


Qualifications

  • Bachelor's degree in Computer Science or related field.
  • Advanced certifications such as CISSP or incident-response/forensics GIAC certifications (GCIH, GCFA, GCFE, GNFA) are preferred
  • Minimum five years experience in Information Technology
  • Minimum three years of direct IT Security experience in Cyber Security operations and Incident Response
  • Experience performing event and log analysis including one or more of the following: Anti-Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security
  • Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means
  • Solid working knowledge of networking technology and tools, firewalls, proxies, IDS/IPS, encryption, SIEM and EDR
  • Experience writing scripts, tools, or methodologies to enhance the investigative process
  • Working knowledge of the MITRE ATT&CK framework and the NIST incident response lifecycle (NIST SP 800-61).
  • Hands-on experience with industry-standard forensic toolsets and with cloud forensics across major cloud and productivity platforms.
  • Familiarity with AI tools and an AI First mindset.

Pay is competitive and based on a number of job-related factors, including skills and experience. The starting pay rate/range at time of hire for this position in the posted location is $83,538.00 - $137,241.00 / year. The rate/range provided herein is the anticipated pay at the time of hire, and does not reflect future job opportunity.

Similar Jobs

More Jobs at Altice USA

More Information Technology Jobs

Find similar SOC Incident Commander jobs: