Remote job
Incident Response Manager - Security
Job details
About this role
Role overview
Lead the end-to-end response to security incidents, from alert assessment and initial containment through investigation, remediation, reporting, and post-incident improvement. This role combines incident command, security analysis, operational program development, and cross-functional coordination across a globally distributed environment.
Responsibilities
- Coordinate security incident response activities, assign workstreams, and drive timely resolution as incident response manager or incident commander. - Investigate threats and suspicious activity across client devices, system and data access, applications, networks, and other security-relevant sources while maintaining confidential documentation. - Analyze complex event data, develop queries and analytical approaches, and provide risk-based recommendations to help stakeholders prevent, detect, and respond to malicious activity. - Create and maintain incident response plans, runbooks, procedures, capabilities, and response techniques. - Partner with security engineering and data science teams to scale security-event analysis and protect systems, networks, and data. - Improve response metrics, reporting, processes, and team capability; mentor colleagues and support post-incident reviews.
Requirements
- At least 5 years of experience leading security incident response. - Bachelor’s or master’s degree in computer science or a related field, or equivalent practical experience. - Working knowledge of Python and SQL, with familiarity with additional programming languages. - Hands-on experience with log analysis, network security, digital forensics, and incident investigations. - Experience analyzing security events, troubleshooting security issues, correlating complex datasets, and developing automation for response processes. - Strong written and verbal communication skills, sound independent judgment, and the ability to identify relationships across internal, external, and threat-intelligence data.
Nice to have
- Broad security experience spanning endpoint, email, network, identity, cloud, vulnerability management, incident response, and threat intelligence. - Experience with data-processing or analytics platforms such as Databricks or Trino. - Familiarity with observability, security, or data-engineering tools such as Chronicle, osquery, LogScale, or Splunk.