





Medium: remote role at a known cybersecurity vendor with specialized senior IR requirements.
High: deep cybersecurity operations and incident response expertise required, limiting cross-industry transferability.
High: explicit 7+ years, required IR leadership, technical tool experience, and preferred certifications.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead and manage multiple squads within Cyber Incident Response Team (CIRT), overseeing daily operations including staffing, workload, prioritization, and service levels for concurrent customer incident engagements.
Serve as Incident Commander for high-severity cybersecurity incidents, coordinating investigation, containment, eradication, recovery, and communication until resolution.
Drive operational quality and continuous improvement using metrics and feedback to enhance workflows, automation, training, and response capabilities across the incident response function.
7+ years in cybersecurity operations, incident response, digital forensics or related discipline, including at least 2 years in team or operational leadership roles.
Proven experience managing incident response operations with responsibility for staffing, prioritization, service levels, and customer outcomes across multiple engagements.
Strong technical knowledge in endpoint, network, and cloud security; capable of investigating compromises, determining scope and root causes, and directing containment/remediation.
Degree in IT, Computer Science, or related field, or equivalent work experience; excellent written and verbal communication skills.
Experienced leader comfortable managing and coaching multiple distributed incident response squads with accountability for operational outcomes and performance metrics.
Technically proficient Incident Commander skilled in handling complex security incidents and communicating risk-based decisions to technical and executive stakeholders.
Practitioner with deep understanding of attacker tactics (MITRE ATT&CK), operationalizing incident investigation and containment, and driving continuous process and tooling improvements in a managed security environment.