10279 - Security Incident Response Manager
$118,650–$182,710 year
On-siteIrvine, California, United States
Job Summary
Coordinate and support enterprise-wide cybersecurity incident response activities across the incident lifecycle, including detection, investigation, containment, remediation, and documentation. Monitor, analyze, and evaluate server, endpoint, network, and security event data to identify suspicious activity using SIEM, EDR, and related tools. Investigate security alerts and indicators of compromise, while supporting incident communications, escalation activities, and stakeholder coordination during cybersecurity events. Maintain and enhance the Security Incident Response Plan in alignment with NIST, ISO 27035, and MITRE ATT&CK, and participate in tabletop exercises and readiness assessments. Leverage threat intelligence to improve detection and response effectiveness while tracking incident response metrics and operational reporting requirements. Partner with internal teams, external vendors, and managed security service providers to ensure timely and effective response activities.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline
- 8+ years of experience in cybersecurity operations, incident response, security monitoring, threat detection, or a related information security function
- Experience participating in and coordinating cybersecurity incident investigations and remediation efforts
- Strong understanding of threat landscapes, attack vectors, malware behavior, indicators of compromise, and incident response methodologies
- Experience utilizing and interpreting security data from SIEM, EDR, and other security monitoring technologies
- Ability to analyze security events and communicate findings to stakeholders
Desired Qualifications
- Master's degree or higher in Cybersecurity, Information Technology, Computer Science, or a related discipline
- Industry-recognized certifications such as GCIH, GCFA, GCIA, GNFA, CISSP, CISM, Security+, or CySA+
- Experience working with MSSPs
- Experience supporting SIRP, readiness initiatives, and tabletop exercises
- Familiarity with AWS, Azure, and GCP
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.