1

Cybersecurity Incident Commander Jobs in Delaware

Lead, Service Management

Dover, DE · On-site

$12.75 - $16.75/hr

A distinctive part of this role is establishing and leading the cybersecurity services Pearson ... as incident commander for major incidents. Governance, risk, and compliance is a separate ...

New

Cybersecurity Incident Commander information

What is the difference between Cybersecurity Incident Commander vs Cybersecurity Analyst?

AspectCybersecurity Incident CommanderCybersecurity Analyst
CertificationsGCIH, CISSP, CISMCompTIA Security+, GIAC certifications
Work EnvironmentIncident response teams, security operations centersMonitoring networks, analyzing threats
ResponsibilitiesLead incident response, coordinate teams, communicate with stakeholdersDetect threats, analyze security data, recommend fixes

The Cybersecurity Incident Commander focuses on leading and coordinating incident response efforts during security breaches, while the Cybersecurity Analyst primarily monitors systems, analyzes threats, and supports security measures. Both roles require relevant certifications and work in security operations environments, but their responsibilities differ in scope and leadership level.

What are the key skills and qualifications needed to thrive as a Cybersecurity Incident Commander, and why are they important?

To thrive as a Cybersecurity Incident Commander, you need deep knowledge of cybersecurity principles, incident response frameworks, and risk management, often supported by a degree in computer science and certifications like CISSP or GCIH. Familiarity with Security Information and Event Management (SIEM) tools, forensic analysis platforms, and incident tracking systems is typically required. Strong leadership, decision-making, and communication skills are essential for coordinating teams and managing crises under pressure. These competencies ensure swift, effective response to cyber threats, minimizing organizational impact and ensuring regulatory compliance.

What is a Cybersecurity Incident Commander?

Cybersecurity Incident Commanders are professionals responsible for leading and coordinating an organization’s response to cybersecurity incidents, such as data breaches or cyberattacks. They develop and execute response plans, communicate with stakeholders, and ensure that containment, eradication, and recovery actions are taken efficiently. Their role is critical in minimizing damage, protecting sensitive data, and restoring normal operations. They also conduct post-incident reviews to improve future responses and security measures.

What are the main challenges a Cybersecurity Incident Commander faces during a major security incident?

A Cybersecurity Incident Commander often faces the challenge of coordinating cross-functional teams under high-pressure situations while maintaining clear communication and decision-making. They must rapidly assess evolving threats, prioritize response actions, and ensure all stakeholders are informed and aligned. Balancing timely containment of the incident with thorough evidence preservation for forensic investigation is another key challenge. This role requires staying calm, organized, and adaptable in dynamic environments where situations can change rapidly.
What are popular job titles related to Cybersecurity Incident Commander jobs in Delaware? For Cybersecurity Incident Commander jobs in Delaware, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Incident Commander jobs in Delaware look for? The top searched job categories for Cybersecurity Incident Commander jobs in Delaware are:
What cities in Delaware are hiring for Cybersecurity Incident Commander jobs? Cities in Delaware with the most Cybersecurity Incident Commander job openings:

Lead, Service Management

Pearson

Dover, DE • On-site

$12.75 - $16.75/hr

Other

Posted 3 days ago

New


Job description

Lead, Service Management

Descriptor: This role aligns to industry level titles such as Lead Service Operations & Cyber Risk or Senior Manager Service Operations & Cyber Risk

Location: US, Remote

Role Overview

Pearson Virtual Schools runs the technology platforms that thousands of schools, teachers, and students depend on every day. Keeping those platforms available, secure, and reliable is the job of this function, and this role leads it.

As Lead, Service Operations & Cyber Risk, you own service operations end-to-end (incident and problem management), you lead the rapid response team during major incidents, and you own the platforms' day-to-day security operations through a dedicated security operations lead. You are the single accountable owner for the function's service health and security outcomes. This is first and foremost a people-leadership role: you line-manage the security operations lead and the incident and service-operations team leads, and you build a strong team rather than carry the work yourself.

A distinctive part of this role is establishing and leading the cybersecurity services Pearson Virtual Schools provides to its schools, such as security-awareness training, phishing defense, and support for handling security incidents.

You also own and chair a monthly operations review for senior leadership, covering service health, cloud cost, cloud engineering, and change and release, and you act as incident commander for major incidents. Governance, risk, and compliance is a separate, independent function and a close partner of this role, particularly on audit, SOC 2, and risk. You are also the link between the technology teams and corporate functions such as Cybersecurity, Privacy, and Legal.

Key Responsibilities

Service Operations & Governance

  • Own and continuously improve service operations, including incident and problem management, plus service-health and performance reporting.

  • Lead the rapid response team for high-severity incidents, deciding when to escalate to executives and seeing issues through to resolution and clear communication.

  • Set incident-severity standards, correct misclassification, and make sure post-incident reviews produce real root-cause and preventive actions.

People & Team Leadership

  • Line-manage the security operations lead and the incident and service-operations team leads, and partner with the governance, risk, and compliance lead on audit and risk.

  • Set objectives, coach, and build capability and growth plans across the team, and make sure no critical work depends on a single person.

  • Lead through delegation. Develop owners on the team rather than carrying the work yourself.

Security & Cyber-Risk Oversight

  • Establish and lead the cybersecurity services Pearson Virtual Schools provides to its schools, such as security-awareness training, phishing defense, and incident support.

  • Own the platforms' day-to-day security posture through your security operations lead, who operates and remediates the controls. Keep vulnerability remediation, patching, and hardening on track.

  • Make risk-acceptance calls within your delegated authority, and escalate anything beyond tolerance.

  • Partner with the independent governance, risk, and compliance function so audits and SOC 2 get the operational evidence and remediation they need. That function owns audit response, SOC 2, the risk register, and business continuity; your teams deliver the underlying operational work and invoke recovery when a major incident requires it.

Executive Reporting & Partnership

  • Own and chair the monthly operations review, bringing service health, cloud cost, cloud engineering, and change and release into one executive readout.

  • Partner with Engineering, Product, Cybersecurity, and Privacy to strengthen reliability, security, and customer outcomes without direct authority.

  • Represent the function's service and security status to senior leadership.

What You Will Bring

  • 8 or more years in IT service management or technology operations, including team leadership

  • Experience managing teams and senior specialists, ideally including other team leads

  • Strong background in incident and problem management in complex SaaS or cloud environments, with ServiceNow or a similar platform

  • Enough command of cyber risk and security operations to set direction for and hold accountable a security operations specialist, and to partner effectively with an independent governance, risk, and compliance function on SOC 2 and business continuity

  • Track record running executive-level operational and risk reporting

  • Comfort leading teams that mix employees and vendors, onshore and offshore

  • Excellent written and verbal communication, including executive briefings and incident communication

  • EdTech, SaaS, or K-12 experience a plus; ITIL or SAFe certification a plus

  • Bachelor's degree in a relevant field or equivalent practical experience

Compensation at Pearson is influenced by a wide array of factors including but not limited to skill set, level of experience, and specific location. As required by the California, Colorado, Hawaii, Illinois, Maryland, Minnesota, New Jersey, New York State, New York City, Vermont, Washington State, and Washington DC laws, the pay range for this position is as follows:

The minimum full-time salary range is between $150,000 - $190,000.

This position is eligible to participate in an annual incentive program, and information on benefits offered is here.

Applications will be accepted through 12th August. This window may be extended depending on business needs.

Who we are:

At Pearson, our purpose is simple: to help people realize the life they imagine through learning. We believe that every learning opportunity is a chance for a personal breakthrough. We are the world's lifelong learning company. For us, learning isn't just what we do. It's who we are. To learn more: We are Pearson.

Pearson is an Equal Opportunity Employer and a member of E-Verify. Employment decisions are based on qualifications, merit and business need. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

If you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing TalentExperienceGlobalTeam@grp.pearson.com.

Job: Infrastructure and Cloud Operations

Job Family: TECHNOLOGY

Organization: Virtual Learning

Schedule: FULL_TIME

Workplace Type:

Req ID: 25216

#location