1

Cybersecurity Incident Commander Jobs in Texas (NOW HIRING)

Cybersecurity Manager

Dallas, TX

$109K - $148K/yr

Manage the incident response process serving as Incident Commander for declared cybersecurity incidents * Manage an insider threat program, including data loss prevention * Oversee SOC analysts ...

Cybersecurity Manager

Dallas, TX · On-site

$125 - $150/hr

... Incident Commander for declared cybersecurity incidentsManage an insider threat program, including data loss preventionOversee SOC analysts' response to DLP alerts and escalationsServe as security ...

This position offers direct exposure to modern security tools, incident response procedures, and ... Strong working knowledge of Windows and Linux/Unix operating systems and command-line interfaces

This position offers direct exposure to modern security tools, incident response procedures, and ... Strong working knowledge of Windows and Linux/Unix operating systems and command-line interfaces

... Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams ... Experience with alternate management methods using SSH, serial connections, and the command-line ...

Cybersecurity Team Lead

Irving, TX · Hybrid

$106K - $144K/yr

... Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams ... Experience with alternate management methods using SSH, serial connections and the command-line ...

Engages in incident reporting and response support. * Conducts ongoing monitoring of computer ... Maintain operational oversight and manage Command-level and privileged user accounts for the ...

... Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams ... Experience with alternate management methods using SSH, serial connections and the command-line ...

Lead Security Engineer

Austin, TX · On-site

$180K - $235K/yr

Build, maintain, and test the incident response runbook; serve as the primary incident commander ... Qualifications * 8+ years in security engineering, infrastructure security, or cybersecurity ...

next page

Showing results 1-20

Cybersecurity Incident Commander information

What is a Cybersecurity Incident Commander?

Cybersecurity Incident Commanders are professionals responsible for leading and coordinating an organization’s response to cybersecurity incidents, such as data breaches or cyberattacks. They develop and execute response plans, communicate with stakeholders, and ensure that containment, eradication, and recovery actions are taken efficiently. Their role is critical in minimizing damage, protecting sensitive data, and restoring normal operations. They also conduct post-incident reviews to improve future responses and security measures.

What are the main challenges a Cybersecurity Incident Commander faces during a major security incident?

A Cybersecurity Incident Commander often faces the challenge of coordinating cross-functional teams under high-pressure situations while maintaining clear communication and decision-making. They must rapidly assess evolving threats, prioritize response actions, and ensure all stakeholders are informed and aligned. Balancing timely containment of the incident with thorough evidence preservation for forensic investigation is another key challenge. This role requires staying calm, organized, and adaptable in dynamic environments where situations can change rapidly.

What are the key skills and qualifications needed to thrive as a Cybersecurity Incident Commander, and why are they important?

To thrive as a Cybersecurity Incident Commander, you need deep knowledge of cybersecurity principles, incident response frameworks, and risk management, often supported by a degree in computer science and certifications like CISSP or GCIH. Familiarity with Security Information and Event Management (SIEM) tools, forensic analysis platforms, and incident tracking systems is typically required. Strong leadership, decision-making, and communication skills are essential for coordinating teams and managing crises under pressure. These competencies ensure swift, effective response to cyber threats, minimizing organizational impact and ensuring regulatory compliance.

What is the difference between Cybersecurity Incident Commander vs Cybersecurity Analyst?

AspectCybersecurity Incident CommanderCybersecurity Analyst
CertificationsGCIH, CISSP, CISMCompTIA Security+, GIAC certifications
Work EnvironmentIncident response teams, security operations centersMonitoring networks, analyzing threats
ResponsibilitiesLead incident response, coordinate teams, communicate with stakeholdersDetect threats, analyze security data, recommend fixes

The Cybersecurity Incident Commander focuses on leading and coordinating incident response efforts during security breaches, while the Cybersecurity Analyst primarily monitors systems, analyzes threats, and supports security measures. Both roles require relevant certifications and work in security operations environments, but their responsibilities differ in scope and leadership level.

What are popular job titles related to Cybersecurity Incident Commander jobs in Texas?

For Cybersecurity Incident Commander jobs in Texas, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Incident Commander jobs in Texas look for?

The top searched job categories for Cybersecurity Incident Commander jobs in Texas are:

What cities in Texas are hiring for Cybersecurity Incident Commander jobs?

Cities in Texas with the most Cybersecurity Incident Commander job openings:

$109K - $148K/yr

Full-time

Re-posted 2 days ago


Simmons Bank rating

8.0

Company rating: 8.0 out of 10

Based on 22 frontline employees who took The Breakroom Quiz

72nd of 175 rated banks


Job description

It's fun to work in a company where people truly BELIEVE in what they're doing!

We're committed to bringing passion and customer focus to the business.

Summary

At Simmons Bank, the Cybersecurity Manager is an essential leader within the Information Security team. The SOC provides continuous security monitoring and incident response; conducts security awareness and training; and manages security threats and vulnerabilities.

The Cybersecurity Manager oversees the activity of the SOC team, including hiring, training, and performance management. The Cybersecurity Manager also maintains strong operational programs; assesses escalated security events and threats; and develops, implements and tests incident response plans and playbooks.

Additional responsibilities include supporting the Bank's audits and examinations; supporting risk assessments related to the SOC; reporting the SOC's operational metrics, and reporting on SOC activities to IT and business leaders.

Essential Duties and Responsibilities

Security Operations

  • Develop and maintain the Security Operations Center (SOC) Program

  • Direct a team of SOC analysts, delegating tasks as required to support daily cyber security detection and response activities

  • Develop and maintain processes to enhance detection and response capabilities

  • Develop use-cases and content for security event monitoring and automated workflows

  • Monitor SOC analyst performance against defined SLAs and metrics

  • Coordinate with Red Team and external service providers to scope and execute security assessments

Incident Response

  • Develop, implement, and test incident response plans with SOC, IT and business units

  • Oversee the development of written SOC response playbooks

  • Manage the incident response process serving as Incident Commander for declared cybersecurity incidents

  • Manage an insider threat program, including data loss prevention

  • Oversee SOC analysts' response to DLP alerts and escalations

  • Serve as security liaison for Fraud and Compliance investigations

  • Serve as quality control and security liaison for legal collections

Security Education

  • Oversee security awareness and training program, including content selection and development

  • Oversee security awareness phishing simulations and tabletop exercises

  • Provide guidance, education, and content to other departments and business units on cyber related matters as well as communicating capabilities of the SOC team

Threat and Vulnerability Management

  • Lead and manage the vulnerability management process

  • Support application security scanning and vulnerability risk analysis

  • Manage threat hunting and threat intelligence programs

  • Manage program to protect digital assets from abuse and takedown process

  • Oversee the analysis of vendor vulnerability releases (e.g. Patch Tuesday)

  • Research new trends and advances in cybersecurity to stay updated on potential threats and best practices

  • Advise business and technology leadership for potential changes in security posture

  • Recommend and direct changes in automated tools supporting the monitoring and threat landscape

Administrative

  • Develop written standards for respective areas and contributes to the overall Information Security Policy and Program

  • Responds to audit, compliance, and regulatory requests, as needed (e.g. SOX audit)

  • Participate in periodic business reviews with vendors and internal customers

  • Manage staffing, including supervision, scheduling, development, evaluation, and disciplinary actions

  • Develop and maintain an environment of growth where knowledge and performance are consistently advancing

  • Develop and mentor staff through open communication and training opportunities; build and maintain employee morale and motivation

Qualifications

Work Experience

  • Five (5) years of experience in information security or cybersecurity

  • Three (3) years of experience supervising and leading security operations personnel

  • Banking or Financial Services experienced (preferred)

  • Experience within Security Operations Center, Fusion Center, or MSP/MSSP (preferred)

  • Experience with vulnerability management process, scanning tools, risk analysis and metrics reporting

  • Experience investigating intrusions in a cloud/hybrid environment

  • Experience with SIEM and/or log aggregation technologies, writing queries to support investigations and threat hunts

  • Experience with security tool integrations (APIs) and automating processes with scripting and SOAR (preferred)

  • Experience leading incident response activities at an appropriate level in prior roles

Education and Certifications

  • CISSP, CISM, GCIH, GSOC or other security related certifications (required)

  • Multiple certifications across security disciplines (preferred)

  • Bachelor's or Master's degree in a related field (preferred)

Other Qualifications (including physical requirements)

  • Ability to balance multiple responsibilities and prioritize effectively

  • Strong sense of urgency and focus on timely execution of deliverables

  • Strong operational mindset and high degree of accountability

  • Strong situational awareness and proactive, concise communicator

  • Proficient with the MITRE attack framework and common threat vectors

  • Proficient with security of Windows operating systems

  • Strong oral and written communication skills

  • Strong organizational, problem solving, and planning skills

  • Must possess excellent telephone and customer service skills

  • Must be willing to periodically work non-standard hours and be on call

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Activities, duties and responsibilities may change at any time with or without notice.

Equal Employment Opportunity Information: Simmons First National Corporation and its subsidiaries are committed to a policy of equal employment with respect to a person's race, color, religion, sex, ancestry, sexual orientation, gender identity, national origin, covered veterans, military status, physical or mental disability or any other legally protected classifications.


What Simmons Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom