The Cyber Incident Lead will drive and coordinate our organization's cybersecurity incident response initiatives and is responsible for implementing a continuous testing strategy and conducting full-scale cyber exercises to identify and address inefficiencies and gaps in incident management. Based on these tests and exercises, the Cyber Incident Lead will design remediation plans with impacted groups to enhance their readiness and capabilities. This role will centralize the command center, streamline communication, and facilitate cross-functional collaboration among teams such as IAM, Infrastructure, and Network, ensuring comprehensive management of cyber incidents.
Key Responsibilities :
Management
- Lead and coordinate cross-functional response teams during cybersecurity incidents, ensuring timely decision-making and clear communication.
- Design, facilitate, and lead cyber tabletop exercises to test and enhance organizational preparedness, coordination, and decision-making under simulated attack scenarios.
- Develop and maintain the organization’s cyber incident response strategy, playbooks, and escalation protocols.
- Conduct regular incident response exercises and simulations to ensure readiness across technical and business teams.
- Mentor and guide incident response personnel, fostering a culture of preparedness, accountability, and continuous improvement.
Technical
Direct the technical investigation of security incidents, including root cause analysis, impact assessment, and containment strategies.Coordinate and oversee the documentation of activities, analysis, and remediation actions for cybersecurity incidents.Ensure incident documentation is thorough, accurate, and aligned with regulatory and legal requirements.Continuously evaluate and improve incident response tools, processes, and capabilities based on lessons learned and threat landscape evolution.Organizational
Serve as the primary liaison between technical teams, executive leadership, legal, communications, and external stakeholders during incidents.Communicate incident status, risks, and business impact clearly and effectively to both technical and non-technical audiences.Partner with IT, OT, and business units to ensure incident response coverage across all environments.Ensure compliance with internal policies, industry standards, and regulatory requirements related to incident response and breach notification.Lead post-incident reviews and drive remediation efforts to strengthen the organization’s cyber resilience.Requirements :
Bachelor’s degree in Cybersecurity, Information Assurance, or a related field completed and verified prior to start from an accredited institution8+ years of experience in cybersecurity, with 3+ years in a senior incident response or leadership roleMaster’s degree preferredProven experience leading major incident response efforts, including ransomware, insider threats, and supply chain attacksDeep knowledge of digital forensics, malware analysis, and incident containment strategiesFamiliarity with legal and regulatory requirements for breach notification and evidence handlingStrong leadership and crisis management skills, with the ability to coordinate across technical, legal, and executive teamsExcellent verbal and written communication skills, including executive-level reporting and stakeholder engagementCertifications such as CISM, CISSP, GCFA, or C-CISO are highly desirable