Incident Response Manager
Leading cybersecurity incident response and digital forensics investigations.

Role Overview
As an Incident Response Manager, you will lead our organization’s response to cybersecurity incidents, coordinating cross-functional teams and ensuring rapid containment and recovery from security breaches. This role requires strong leadership skills, technical expertise, and the ability to make critical decisions under pressure.
You will be responsible for developing and maintaining incident response procedures, training response teams, and continuously improving our incident response capabilities based on lessons learned from real-world incidents.
Key Responsibilities
Lead incident response activities during major security incidents, coordinating response efforts across technical, legal, and business teams.
Develop and maintain incident response plans, procedures, and playbooks to ensure consistent and effective response to various types of security incidents.
Conduct digital forensics investigations to determine the scope, impact, and root cause of security incidents.
Manage relationships with external partners including law enforcement, legal counsel, and forensics vendors during incident response activities.
Train and mentor junior incident response team members and conduct tabletop exercises to test and improve response capabilities.
Prepare detailed incident reports and present findings to senior leadership and regulatory bodies as required.
Required Qualifications
Bachelor’s degree in Cybersecurity, Computer Science, or related field, plus 6+ years of experience in incident response or digital forensics.
Strong leadership and project management skills with experience managing cross-functional teams during high-stress situations.
Expert knowledge of digital forensics tools and techniques for Windows, Linux, and macOS environments.
Experience with network forensics, malware analysis, and memory forensics using industry-standard tools.
Professional certifications such as GCIH, GCFA, EnCE, or similar incident response and forensics credentials.
Strong written and verbal communication skills with the ability to explain technical concepts to non-technical stakeholders.
