1

Cybersecurity Incident Commander Jobs (NOW HIRING)

We are seeking a Cybersecurity Incident Commander to join SoFi's Cyber Defense program and lead incident command efforts across the organization. This role will serve as a central driver for security ...

We are seeking a Cybersecurity Incident Commander to join SoFi's Cyber Defense program and lead incident command efforts across the organization. This role will serve as a central driver for security ...

Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear ...

next page

Showing results 1-20

Cybersecurity Incident Commander information

See salary details

$41K

$127.2K

$199.5K

How much do cybersecurity incident commander jobs pay per year?

As of Jun 8, 2026, the average yearly pay for cybersecurity incident commander in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What is the difference between Cybersecurity Incident Commander vs Cybersecurity Analyst?

AspectCybersecurity Incident CommanderCybersecurity Analyst
CertificationsGCIH, CISSP, CISMCompTIA Security+, GIAC certifications
Work EnvironmentIncident response teams, security operations centersMonitoring networks, analyzing threats
ResponsibilitiesLead incident response, coordinate teams, communicate with stakeholdersDetect threats, analyze security data, recommend fixes

The Cybersecurity Incident Commander focuses on leading and coordinating incident response efforts during security breaches, while the Cybersecurity Analyst primarily monitors systems, analyzes threats, and supports security measures. Both roles require relevant certifications and work in security operations environments, but their responsibilities differ in scope and leadership level.

What are the key skills and qualifications needed to thrive as a Cybersecurity Incident Commander, and why are they important?

To thrive as a Cybersecurity Incident Commander, you need deep knowledge of cybersecurity principles, incident response frameworks, and risk management, often supported by a degree in computer science and certifications like CISSP or GCIH. Familiarity with Security Information and Event Management (SIEM) tools, forensic analysis platforms, and incident tracking systems is typically required. Strong leadership, decision-making, and communication skills are essential for coordinating teams and managing crises under pressure. These competencies ensure swift, effective response to cyber threats, minimizing organizational impact and ensuring regulatory compliance.

What are Cybersecurity Incident Commanders?

Cybersecurity Incident Commanders are professionals responsible for leading and coordinating an organization’s response to cybersecurity incidents, such as data breaches or cyberattacks. They develop and execute response plans, communicate with stakeholders, and ensure that containment, eradication, and recovery actions are taken efficiently. Their role is critical in minimizing damage, protecting sensitive data, and restoring normal operations. They also conduct post-incident reviews to improve future responses and security measures.

What are the main challenges a Cybersecurity Incident Commander faces during a major security incident?

A Cybersecurity Incident Commander often faces the challenge of coordinating cross-functional teams under high-pressure situations while maintaining clear communication and decision-making. They must rapidly assess evolving threats, prioritize response actions, and ensure all stakeholders are informed and aligned. Balancing timely containment of the incident with thorough evidence preservation for forensic investigation is another key challenge. This role requires staying calm, organized, and adaptable in dynamic environments where situations can change rapidly.
More about Cybersecurity Incident Commander jobs
What cities are hiring for Cybersecurity Incident Commander jobs? Cities with the most Cybersecurity Incident Commander job openings:
What states have the most Cybersecurity Incident Commander jobs? States with the most job openings for Cybersecurity Incident Commander jobs include:
What job categories do people searching Cybersecurity Incident Commander jobs look for? The top searched job categories for Cybersecurity Incident Commander jobs are:
Infographic showing various Cybersecurity Incident Commander job openings in the United States as of May 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.
Cybersecurity Incident Commander

Cybersecurity Incident Commander

SoFi

Seattle, WA • On-site

Other

Posted 10 days ago


Job description

The Role:

We are seeking a Cybersecurity Incident Commander to join SoFi's Cyber Defense program and lead incident command efforts across the organization. This role will serve as a central driver for security incident response, ensuring effective management of day-to-day incidents as well as large-scale, high-impact cybersecurity events.

The SOC team is responsible for monitoring, analyzing, and responding to security events across SoFi's infrastructure and applications. As a dedicated incident response resource within Cyber Defense, you will coordinate cross-functional response efforts, maintain incident command structure during active events, and ensure consistent communication, documentation, and resolution tracking.

This is a highly visible role that partners closely with SOC Analysts, Threat Research, Offensive Security, Tools Automation & Operations (TAO), Engineering, IT, Legal, Risk, Executive team, and other stakeholders to drive timely containment, eradication, and recovery. The ideal candidate thrives in fast-paced environments, brings structure to ambiguity, has exceptional communication skills, and can effectively drive complex incidents from detection through post-incident review.

What You'll Do:
  •  Serve as the primary Security Incident Commander for security incidents identified by the SOC.

  • Lead and manage the end-to-end lifecycle of security incidents, including triage validation, containment, eradication, recovery, and closure.

  • Establish and maintain incident command during high-severity or large-scale incidents.

  • Drive cross-functional collaboration and decision making across technical and business teams to ensure timely and effective response.

  • Facilitate incident communication, coordinate response resources, and maintain clear situational awareness for all engaged.

  • Ensure consistent documentation of incident timelines, impact assessments, decisions, evidence chain of custody, and actions taken.

  • Develop and maintain incident severity classifications and escalation criteria that are aligned with organizational and business needs and expectations.

  • Provide executive-ready status updates and summaries during major incidents. 

  • Coordinate post-incident reviews, including root cause analysis, lessons learned, and tracking of remediation actions.

  • Identify and facilitate opportunities to improve incident response processes, playbooks, and communication workflows.

  • Partner with SOC leadership to enhance incident metrics, reporting, and operational maturity.

  • Organize and participate in tabletop exercises, simulations, and readiness activities to improve Cyber Defense and SOC response capabilities. 

What You'll Need:
  • 3-7+ years of experience in cybersecurity operations, incident response, or SOC environments.

  • Direct experience coordinating or leading security incident response efforts in enterprise environments.

  • Strong understanding of the incident response lifecycle and frameworks (e.g., NIST 800-61).

  • Experience handling high-severity incidents such as ransomware, business email compromise, insider threats, cloud compromise, or data exfiltration events.

  • Ability to interpret technical findings and translate them into clear, actionable updates for both technical and non-technical stakeholders.

  • Excellent written and verbal communication skills, especially in high-pressure situations.

  • Strong organizational skills with the ability to manage multiple concurrent incidents.

  • Experience facilitating cross-functional communication across various media channels and driving accountability during live incidents.

  • Ability to operate independently while collaborating effectively across distributed teams.

Nice to Have:
  • Experience in a formal CSIRT or Incident Commander role.

  • Working knowledge of security technologies such as SIEM, EDR, email security, IAM, cloud security controls, and network monitoring tools.

  • Knowledge of regulatory and compliance considerations (e.g., financial services, PCI, SOX, GLBA).

  • Experience directing or conducting digital forensics or deep technical investigations.

  • Familiarity with cloud-native security incident response (AWS, GCP, or Azure).

  • Exposure to MITRE ATT&CK framework and threat intelligence integration.

  • Relevant certifications such as GCIA, GCIH, GCED, CISSP, CISM, or similar.

  • Experience developing or maintaining incident response playbooks and runbooks.