Incident Response (IR) Manager
$120,000–$145,000 year
RemoteUnited States
Job Summary
Lead the Incident Response team of 20 specialists by providing oversight, leadership, and administrative management. Deliver robust operational planning, metrics, and reporting to support audits and maturity efforts using Microsoft tools. Ensure complete delivery of contract deliverables including strategy documentation, playbooks, incident tickets, after action reports, forensics reports, and executive briefings. Support Tier-1 detection and response operations to identify, triage, and mitigate malicious activities across client environments. Manage Tier-2 and Forensics services covering host, network, cloud, and malware investigations, alongside Counterintelligence and Insider Threat support. Proactively collaborate with Federal leadership to recommend ongoing improvements for IR capabilities.
Required Qualifications
- 5+ years' experience comprehensive cybersecurity operations leadership and management
- Bachelor's Degree or higher in relevant cybersecurity-related major
- Demonstrated expert-level delivery experience and knowledge of IR concepts, operations, outputs, and maturity levels
- Demonstrated expert-level delivery experience and knowledge of Forensics concepts, operations, outputs, and maturity levels
- Demonstrated expert-level delivery experience and knowledge of ticket management tools and practices; troubleshooting; investigations; computer networking; and operating systems
- Demonstrated expert-level technical ability/aptitude, demonstrated through prior technical experience and accomplishment
- Excellent critical thinking, analytic skills, and experience
- Excellent time management skills and experience
- Excellent management, teamwork, and interpersonal skills against difficult due dates and timelines
- Excellent customer service focus to meet the needs of internal and external customers
- Excellent presentation development and delivery skills
- Excellent program management, project management, and task tracking skills
- Ability to work on occasional weekends and holidays
- Ability to pass an HHS Tier-2 security clearance background investigation
Desired Qualifications
- One or more certifications in information security (such as CISSP, CISM, CompTIA Advanced Security Practitioner, CompTIA Security Analytics Expert, CCTHP, CySA+, Security+, etc.)
- Project Management Certifications (such as CAPM, PMP, ITIL etc.)
- Current Security clearance
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.