1

Cybersecurity Incident Commander Jobs (NOW HIRING)

From delivering affordable broadband to protecting against cybersecurity threats and building ... The Incident Commander (IC) is responsible for the management, supervision, and coordination of ...

From delivering affordable broadband to protecting against cybersecurity threats and building ... The Incident Commander (IC) is responsible for the management, supervision, and coordination of ...

From delivering affordable broadband to protecting against cybersecurity threats and building ... The Incident Commander (IC) is responsible for the management, supervision, and coordination of ...

Lead enterprise-wide response to high-risk cybersecurity incidents as Cyber Incident Commander, validating and escalating incidents, directing cross-functional response efforts, and driving ...

This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP) - owning end-to-end response coordination for high-severity and critical security incidents across ...

This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP) -- owning end-to-end response coordination for high‑severity and critical security incidents across ...

$150 - $175/hr

Senior Manager, Cybersecurity Incident Response and Business Continuity | United States | Remote ... You'll unite incident command with Business Continuity and Disaster Recovery, lead a talented team ...

next page

Showing results 1-20

Cybersecurity Incident Commander information

See salary details

$41K

$127.2K

$199.5K

How much do cybersecurity incident commander jobs pay per year?

As of Sep 6, 2026, the average yearly pay for cybersecurity incident commander in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What is a Cybersecurity Incident Commander?

Cybersecurity Incident Commanders are professionals responsible for leading and coordinating an organization’s response to cybersecurity incidents, such as data breaches or cyberattacks. They develop and execute response plans, communicate with stakeholders, and ensure that containment, eradication, and recovery actions are taken efficiently. Their role is critical in minimizing damage, protecting sensitive data, and restoring normal operations. They also conduct post-incident reviews to improve future responses and security measures.

What are the main challenges a Cybersecurity Incident Commander faces during a major security incident?

A Cybersecurity Incident Commander often faces the challenge of coordinating cross-functional teams under high-pressure situations while maintaining clear communication and decision-making. They must rapidly assess evolving threats, prioritize response actions, and ensure all stakeholders are informed and aligned. Balancing timely containment of the incident with thorough evidence preservation for forensic investigation is another key challenge. This role requires staying calm, organized, and adaptable in dynamic environments where situations can change rapidly.

What are the key skills and qualifications needed to thrive as a Cybersecurity Incident Commander, and why are they important?

To thrive as a Cybersecurity Incident Commander, you need deep knowledge of cybersecurity principles, incident response frameworks, and risk management, often supported by a degree in computer science and certifications like CISSP or GCIH. Familiarity with Security Information and Event Management (SIEM) tools, forensic analysis platforms, and incident tracking systems is typically required. Strong leadership, decision-making, and communication skills are essential for coordinating teams and managing crises under pressure. These competencies ensure swift, effective response to cyber threats, minimizing organizational impact and ensuring regulatory compliance.

What is the difference between Cybersecurity Incident Commander vs Cybersecurity Analyst?

AspectCybersecurity Incident CommanderCybersecurity Analyst
CertificationsGCIH, CISSP, CISMCompTIA Security+, GIAC certifications
Work EnvironmentIncident response teams, security operations centersMonitoring networks, analyzing threats
ResponsibilitiesLead incident response, coordinate teams, communicate with stakeholdersDetect threats, analyze security data, recommend fixes

The Cybersecurity Incident Commander focuses on leading and coordinating incident response efforts during security breaches, while the Cybersecurity Analyst primarily monitors systems, analyzes threats, and supports security measures. Both roles require relevant certifications and work in security operations environments, but their responsibilities differ in scope and leadership level.

More about Cybersecurity Incident Commander jobs

What cities are hiring for Cybersecurity Incident Commander jobs?

Cities with the most Cybersecurity Incident Commander job openings:

What states have the most Cybersecurity Incident Commander jobs?

States with the most job openings for Cybersecurity Incident Commander jobs include:

What job categories do people searching Cybersecurity Incident Commander jobs look for?

The top searched job categories for Cybersecurity Incident Commander jobs are:

Infographic showing various Cybersecurity Incident Commander job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.

Incident Commander

City of New York

Brooklyn, NY • On-site

$150K/yr

Full-time

Posted 23 days ago


Key responsibilities

  • Lead significant, high-impact, or high-visibility cyber security incidents, including validation, prioritization, escalation, and coordination of response activities across multiple City agencies.

  • Serve in an on-call capacity to provide leadership, decision-making, and communication during active cyber incidents outside of regular hours.

  • Coordinate and direct efforts among SOC analysts, incident responders, and external partners, and deliver briefings to executive leadership and stakeholders.


City Of New York rating

7.2

Company rating: 7.2 out of 10

Based on 81 frontline employees who took The Breakroom Quiz

626th of 856 rated public administrative organizations


Job description

Company Description
Job Description
The Office of Technology and Innovation (OTI) leverages technology to drive opportunity, improve public safety, and help government run better across New York City. From delivering affordable broadband to protecting against cybersecurity threats and building digital government services, OTI is at the forefront of how the city delivers for New Yorkers in the 21st century. Follow us on social media @NYCOfficeofTech, and visit nyc.gov/oti to learn more.
At OTI, we offer great benefits, and the chance to work on projects that have a meaningful impact on millions of people. You'll have the opportunity to work with cutting-edge technology and collaborate with other passionate professionals who share your drive and commitment to making a difference through technology.
About Cyber Command
Cyber Command is charged with protecting all City systems against cyber threats, including systems that deliver vital services to New Yorkers. Headed by the Chief Information Security Officer of the City of New York, we provide in-depth support to over 100 agencies and offices to protect, detect, identify, respond to, and recover from cyber threats.
The Incident Commander (IC) is responsible for the management, supervision, and coordination of cyber security incidents as part of a 24x7, 365 Security Operations environment, including nights, weekends, and holiday coverage through an on-call rotation or designated duty schedule. Serving as the critical bridge between executive leadership and technical response teams, the IC provides authoritative command and control during incidents, ensures rapid and informed decision-making, and drives continuous improvement of the City's cyber incident response capabilities. As an experienced leader with deep technical fluency, the IC maintains and evolves incident response playbooks aligned with industry standards (e.g., NIST SP 800-61, NIST CSF) conducts cyber tabletop exercises, acts as a primary liaison for third-party and cross-agency incidents and communicates clearly and confidently with Agency leadership and City Hall stakeholders. The IC identifies operational gaps and maturity improvements to ensure the Security Operations Center (SOC) is staffed and led 24x7 with the authority to take immediate, decisive action upon notification of a cyber security incident.
Responsibilities include, but are not limited to, the following:
-Lead significant, high-impact, or high-visibility cyber security incidents, including validation, prioritization, escalation, and coordination of response activities across multiple City agencies in a 24x7 operational tempo, including nights and weekends as required;
-Serve in an on-call Incident Commander capacity, providing off-hours leadership, decision-making, and executive communication during active incidents;
-Exercise rapid, independent decision-making in high-stress, fluid environments, including incidents affecting critical infrastructure, life-safety systems, and essential City services;
-Provide strategic guidance on, and tracking of, tools, visibility, staffing, and capability gaps impacting the Citys overall cyber security posture and response readiness;
-Act as the primary liaison between the SOC and impacted agency business, technical, legal, and executive teams throughout the incident lifecycle;
-Coordinate and direct efforts among SOC analysts, incident responders, threat intelligence, forensics, legal, communications, and external partners using clearly defined command-and-control structures;
-Deliver timely, accurate, and actionable briefings to executive leadership, Agency heads, and other stakeholders during and following incidents;
-Lead and oversee After-Action Reports (AARs) and lessons-learned activities, translating findings into concrete improvements to people, process, and technology;
-Test, maintain, and continuously improve incident response plans, playbooks, and escalation procedures to address emerging threats and evolving attack techniques;
-Build and maintain strong working relationships across City technology, security, legal, privacy, communications, and operational teams;
-Participate in and lead special initiatives, exercises, and strategic projects related to cyber resilience, operational readiness, and incident response maturity.
-Handle special projects and initiatives as assigned.
HOURS/SHIFT
Day - Due to the necessary management duties of this position in a 24/7 operation, the candidate may be required to be on call and work various shifts such as weekends and/or nights/evenings.
WORK LOCATION
Brooklyn, NY
TO APPLY
* Special Note: Taking and passing civil service exams are necessary to maintain employment with the City of New York. Please check the Department of Citywide Administrative Services (DCAS) website: (Open Competitive Exams for Anyone - Department of Citywide Administrative Services) for important exam filing information. Please ensure that you are either a permanent employee in the civil service title listed on this posting, or, that you file for the examination when there is an open filing period. For more information regarding the civil service process, please visit the DCAS website at: How You Can Apply for a Civil Service Exam - Department of Citywide Administrative Services
* Interested applicants with other civil service titles who meet the preferred requirements should also submit a resume for consideration
Please go to www.cityjobs.nyc.gov and search for Job ID #791541
SUBMISSION OF A RESUME IS NOT A GUARANTEE THAT YOU WILL RECEIVE AN INTERVIEW
APPOINTMENTS ARE SUBJECT TO OVERSIGHT APPROVAL
This position is open to qualified persons with a disability who are eligible for the 55-a Program.
Please indicate in your cover letter that you would like to be considered for the position under the 55-a program
OTI participates in E-Verify
TELECOMMUNICATION MANAGER - 82984
Qualifications
1. A baccalaureate degree from an accredited college including or supplemented by 24 credits in the field of voice and/or data telecommunications or in a pertinent scientific, technical, electronic or related area, and four years of satisfactory fulltime experience in the performance of analytical, planning, operational, technical, or administrative duties in a voice and/or data telecommunications or closely related electronics planning, management, and/or service organization, one year of which must have been in a highly specialized capacity and 18 months must have been in an executive, managerial, or administrative capacity or in the supervision of staff performing work in the voice and/or data telecommunications field; or
2. An associate degree from an accredited college including or supplemented by 12 credits in the field of voice and/or data telecommunications or in a pertinent, scientific, technical, electronic or related area and five years of experience as described in "1" above; or
3. Education and/or experience equivalent to "1" above. However, all candidates must have at least a four-year high school diploma or its educational equivalent and one year of the specialized experience as described in "1" above and must possess the 18 months of executive, managerial, administrative or supervisory experience as described in "1" above.
Additional Information
The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.

What City Of New York employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom