
Manager, Incident Response
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in India.
• Lead and nurture teams of analysts within the Critical Incident Response Team.
• Manage daily CIRT operations across various teams, overseeing staffing, coverage, workload distribution, prioritization, and service-level performance.
• Provide advanced technical guidance and function as Incident Commander for intricate or high-severity situations.
• Oversee investigation, containment, eradication, recovery, and communication with customers until resolution.
• Establish and uphold operational and investigative quality benchmarks.
• Ensure that approved processes, playbooks, documentation, case evaluations, and post-incident actions are executed with precision.
• Utilize operational, quality, response-time, capacity, and customer outcome metrics to manage performance and foster improvements.
• Maintain coverage of skills, plans for onboarding and training, incident exercises, tooling requirements, and updates to playbooks.
• Act as a senior escalation point for customer issues, significant findings, delivery risks, and resource conflicts.
• Simplify complex technical issues into clear updates and actionable decisions for both technical and executive stakeholders.
• Collaborate with Threat Intelligence, Security Operations Center, Detection Engineering, Product, and other teams.
• Promote continuous enhancement and standardization through improved workflows, automation, training, and service upgrades.
• Over 7 years of experience in cybersecurity operations, incident response, digital forensics, or a related field.
• Minimum of 2 years of experience in a leadership role overseeing people, teams, or operational functions.
• Proven experience managing incident response operations across multiple simultaneous engagements.
• Strong technical expertise in endpoint, network, and cloud security.
• Capability to investigate indicators of compromise, identify scope and root causes, and lead containment, eradication, and remediation efforts.
• Experience serving as an Incident Commander or a senior technical escalation point during critical incidents.
• Leadership experience in areas such as coaching, performance management, career development, recruitment or onboarding, and team building.
• Proficiency in utilizing operational metrics, quality reviews, and customer feedback to implement improvements in a security operations or managed services setting.
• In-depth understanding of attacker tools, tactics, and procedures, including persistence, lateral movement, credential theft, ransomware, and evasion techniques.
• Familiarity with the MITRE ATT&CK framework.
• Exceptional written and verbal communication abilities.
• Strong analytical and problem-solving skills.
• A degree in Information Technology, Computer Science, or a related area, or equivalent relevant work experience.
• Preferred advanced cybersecurity certifications, such as GCFE, GCFA, GCIH, or CISSP.
• Experience working with distributed, global, or 24x7 incident response or security operations teams.
• Proficient with SIEM, EDR, forensic collection, and threat intelligence platforms.
• Practical experience with OSQuery, SQL, PowerShell, KQL, CyLR, Velociraptor, or similar tools.
• Experience in developing incident response playbooks, training programs, tabletop exercises, or readiness initiatives.
• Remote-first working model.
• Employee-led diversity and inclusion networks.
• Annual charity and fundraising initiatives.
• Volunteer days.
• Global employee sustainability initiatives.
• Global fitness and trivia competitions.
• Global wellbeing days.
• Monthly wellbeing webinars and training.
• Equality of opportunity and reasonable adjustments in the recruitment process.
Centene Corporation
Antares Consulting
Dominion National
Get handpicked remote jobs straight to your inbox weekly.