Global Director of Autonomous Incident Response and Forensic Analysis
$203,000–$249,000 year
HybridTempe, Arizona, United States or Jersey City, New Jersey, United States
Job Summary
Direct and mature a 24/7 global incident response and digital forensics operating model, including intake, investigation, containment/eradication coordination, and recovery validation across multiple environments. Own functional strategy, multi-year roadmap, and KPI/OKR outcomes for incident response and forensics, while partnering with the SOC Director to define handoffs and implement feedback loops that improve detection fidelity. Lead, mentor, and scale high-performing global teams; define operating rhythms, coverage models, escalation paths, and on-call expectations. Serve as a lead escalation contact in a 24/7 environment; guide appropriate resources to resolution. Provide executive-level oversight for audit, risk, and regulatory engagements related to cyber operations; ensure processes, evidence, and metrics meet policy and compliance requirements. Drive AI-assisted, human-in-the-loop incident response and forensics initiatives, including evidence/artifact enrichment, timeline reconstruction, case summarization, correlation across telemetry sources, and response recommendations with analyst validation and governance. Establish governance for IR playbooks/runbooks, case management workflows, evidence handling and retention, and chain-of-custody practices to ensure investigations are consistent, defensible, and repeatable. Provide incident command leadership for high-severity events; coordinate containment and recovery execution with infrastructure, identity, endpoint, cloud, application, legal, privacy, and communications stakeholders. Oversee third-party IR/forensics capabilities and managed services (as applicable) to ensure coverage, quality, evidence standards, and alignment to enterprise policies and SLAs. Build an IR operations analytics program to measure and continuously improve containment speed, investigation throughput, backlog health, automation effectiveness, and quality of outcomes across regions and shifts. Lead incident readiness and validation exercises (e.g., tabletop exercises and technical simulations with relevant teams), and ensure post-incident reviews drive measurable improvements to controls, detections, and response procedures. Build and maintain forensic readiness capabilities, including standardized collection methods, artifact baselines, and investigative playbooks to accelerate
Required Qualifications
- Bachelor's degree in Information Technology, Cyber Security, Computer Science, or related discipline or equivalent work experience
- 7+ years of experience working in the Cybersecurity Operations or Information Security
- Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position.
Desired Qualifications
- Relevant technical and industry certifications, such as CISSP, ISSMP, GCIA, CISM, CEH, GCFA, GCIH, or GSEC are preferred
- Experience in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, or Incident Response and Forensics preferred
- Experience with security data collection, analysis and correlation
- Well-developed analytic, qualitative, and quantitative reasoning skills
- Demonstrated creative problem-solving abilities
- Security event monitoring, investigation, and overall incident response process
- Strong time management skills to balance multiple activities and lead junior analysts as needed
- Understanding of offensive security to include common attack methods
- Understanding of how to pivot across multiple datasets to correlate artifacts for a single security event
- A diverse skill base in both product security and information security including organizational structure and administration practices, system development and maintenance procedures, system software and hardware security controls, access controls, computer operations, physical and environmental controls, and backup and recovery procedures
- Detailed knowledge and experience in security and regulatory frameworks (ISO 27001, NIST 800 series, FFIEC, SOC2, FedRAMP, STAR, etc.)
- Ability to guide and mentor junior analysts in investigations
- Understanding of enterprise detection and response technologies and processes (advanced threat detection tools, intrusion detection/prevention systems, network packet analysis, endpoint detection and response, firewalls, Anti malware/anti-virus, Security Information and Event Management tools, etc.)
- Experienced with Endpoint Detection & Response, email security, web application firewall, and cloud security tooling
- Ability to perform risk analysis utilizing logs and other information compiled from various sources
- Understanding of network protocols, operating systems (Windows, Unix, Linux, MacOS, databases), and mobile device security
- Knowledge of the various types of cyber-attacks and their implementations
- A fundamental understanding of enterprise cybersecurity frameworks such as MITRE ATT&CK and Cyber Kill Chain
- Ability to document and explain technical details in a concise, understandable manner
- Experience in operational processes such as security monitoring, data correlation, troubleshooting, security operations, etc.
- Preferred experience with Torq, 7AI, CrowdStrike, Tanium, Snowflake, Splunk, and ELK
- Scripting/programming experience preferred
- Bachelor's degree in Computer Science or a closely-related discipline, or an equivalent combination of formal education and experience
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.