Incident Response Manager
$110,800–$226,400 year
On-siteChicago, Illinois, United States or Denver, Colorado, United States
Job Summary
Incident Response Manager at Crowe leading client-facing cybersecurity incident response engagements. Oversees complex investigations involving ransomware, data breaches, insider threats, cloud compromises, and advanced threat activity; directs forensic investigations, threat hunting, containment, eradication, and recovery; provides executive briefings to CISOs, CIOs, legal counsel, and boards; develops and maintains incident response playbooks and service offerings; mentors incident responders and supports business development through proposals and client discussions; travel as required.
Required Qualifications
- 7+ years of cybersecurity experience with at least 3 years focused on incident response, digital forensics, threat hunting, or cyber defense operations
- Demonstrated experience leading complex incident response engagements from initial detection through recovery
- Experience managing project teams, mentoring technical staff, and coordinating cross-functional stakeholders
- Strong leadership, decision-making, and risk management capabilities
- Excellent communication skills with the ability to present technical findings to executive and non-technical audiences
- Ability to manage competing priorities and multiple concurrent engagements
- Strong understanding of networking, operating systems, identity systems, cloud technologies, and cybersecurity principles
- Experience utilizing SIEM platforms such as Splunk, Elastic, Microsoft Sentinel, or FortiSIEM
- Experience utilizing EDR platforms such as CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, or Carbon Black
- Proficiency with scripting and automation using PowerShell, Python, Bash, or similar technologies
- Strong documentation and report-writing capabilities
- Willingness to travel approximately 15% or more as required
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.