SOC Incident Commander

Optimum

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science or related field.
  • Advanced certifications such as CISSP or GIAC (GCIH, GCFA, GCFE, GNFA) preferred.
  • Minimum five years of experience in Information Technology.
  • At least three years of direct IT Security experience in Cyber Security operations and Incident Response.
  • Experience with event and log analysis using security tools in large enterprise environments.
  • Strong communication skills for conveying complex information clearly.
  • Solid knowledge of networking technologies, firewalls, and SIEM/EDR tools.
  • Hands-on experience with forensic toolsets and cloud forensics.

Responsibilities

  • Serve as incident commander for mid-tier and major incidents, directing cross-functional teams.
  • Monitor alerts and logs; triage and prioritize incidents based on severity and business impact.
  • Execute incident response playbooks to contain and remediate breaches, restoring affected systems.
  • Conduct forensics to determine root cause and scope of compromises, preserving evidence.
  • Perform malware analysis to establish indicators of compromise and threat capabilities.
  • Own post-incident reviews, capturing lessons learned and driving remediation efforts.
  • Develop and mature incident-response playbooks and conduct security exercises.

Benefits

  • Opportunity to lead and shape incident response processes.
  • Access to advanced AI-enabled tools for investigation.
  • Collaboration with cross-functional teams and external partners.
  • Professional development through mentoring junior analysts.
  • Engagement in continuous learning and staying current with industry trends.
Full Job Description
Job Summary

As a Cyber Security Incident Commander, you will be responsible for safeguarding our organization's digital assets by promptly identifying, analyzing, and responding to cyber security incidents. You will play a critical role in minimizing the impact of security breaches and preventing future incidents through proactive measures and continuous improvement of our incident response processes.

Responsibilities

  • Incident command & response
  • Serve as incident commander for mid-tier and major incidents: own the full lifecycle and direct cross-functional workstreams (IT, Legal, Communications/PR, Engineering, executives).
  • Monitor alerts and logs; triage and prioritize incidents by severity, criticality, and business impact.
  • Execute incident response playbooks to contain, mitigate, and remediate breaches, then restore affected systems and close off unauthorized access.
  • Act as primary point of contact to executive leadership and the CISO, translating technical events into business-impact briefings.
  • Forensics & analysis
  • Conduct host, network, memory, and cloud/hybrid forensics to determine root cause, scope, and extent of compromise - preserving evidence and maintaining chain of custody to legal and regulatory standards.
  • Perform malware triage and static/dynamic analysis, including sandbox detonation, to establish capability and indicators of compromise.
  • Integrate threat intelligence and proactively hunt for adversary TTPs mapped to MITRE ATT&CK.
  • Leverage AI-enabled tooling to accelerate triage, enrichment, and investigation (AI First mindset).
  • Readiness & continuous improvement
  • Own post-incident reviews and root cause analyses; capture lessons learned and drive remediation to closure.
  • Develop and mature incident-response playbooks, tabletop exercises, and readiness drills.
  • Organize and execute security exercises including Purple Team Exercises, penetration tests, and audits.
  • Define and report IR metrics (MTTD, MTTR) and major-incident tracking to leadership.
  • Program & collaboration
  • Prepare detailed incident reports covering timeline, impact, remediation, and lessons learned.
  • Coordinate with external parties including law enforcement, regulators, and third-party vendors.
  • Develop security policies, procedures, and best practices; perform risk assessments and audits for compliance with industry standards.
  • Evaluate and recommend security technologies, partnering with IT to design and implement solutions.
  • Lead and mentor junior analysts, fostering continuous learning.
  • Stay current on emerging threats, vulnerabilities, and industry trends.


Qualifications

  • Bachelor's degree in Computer Science or related field.
  • Advanced certifications such as CISSP or incident-response/forensics GIAC certifications (GCIH, GCFA, GCFE, GNFA) are preferred
  • Minimum five years experience in Information Technology
  • Minimum three years of direct IT Security experience in Cyber Security operations and Incident Response
  • Experience performing event and log analysis including one or more of the following: Anti-Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security
  • Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means
  • Solid working knowledge of networking technology and tools, firewalls, proxies, IDS/IPS, encryption, SIEM and EDR
  • Experience writing scripts, tools, or methodologies to enhance the investigative process
  • Working knowledge of the MITRE ATT&CK framework and the NIST incident response lifecycle (NIST SP 800-61).
  • Hands-on experience with industry-standard forensic toolsets and with cloud forensics across major cloud and productivity platforms.
  • Familiarity with AI tools and an AI First mindset.

Similar Jobs

More Jobs at Optimum

More Information Technology Jobs

Find similar SOC Incident Commander jobs: