Serve as Incident Commander during high-severity cybersecurity events. * Lead response activities for ransomware, malware outbreaks, business email compromise, credential theft, cloud compromise ...
Serve as Incident Commander during high-severity cybersecurity events. * Lead response activities for ransomware, malware outbreaks, business email compromise, credential theft, cloud compromise ...
Serve as Incident Commander during high-severity cybersecurity events. * Lead response activities for ransomware, malware outbreaks, business email compromise, credential theft, cloud compromise ...
Serve as Incident Commander during high-severity cybersecurity events. * Lead response activities for ransomware, malware outbreaks, business email compromise, credential theft, cloud compromise ...
Serve as Incident Commander during high-severity cybersecurity events. * Lead response activities for ransomware, malware outbreaks, business email compromise, credential theft, cloud compromise ...
Serve as Incident Commander during high-severity cybersecurity events. * Lead response activities for ransomware, malware outbreaks, business email compromise, credential theft, cloud compromise ...
Senior SOC Engineer - Remote / Telecommute
Cary, NC · Remote
$47 - $52/hr
Bachelor's degree in Computer Science, Information Security, Cybersecurity, Engineering, or ... Act as incident commander for high-severity events, coordinating containment, eradication, and ...
Quick apply
Senior SOC Engineer - Remote / Telecommute
Cary, NC · Remote
$47 - $52/hr
Bachelor's degree in Computer Science, Information Security, Cybersecurity, Engineering, or ... Act as incident commander for high-severity events, coordinating containment, eradication, and ...
Manager IT
Raleigh, NC · On-site
Overview First Citizens is seeking an experienced IT Manager - Global Command Center to lead a team ... The manager will oversee daily operations, workforce management, incident response, batch ...
Manager IT
Raleigh, NC · On-site
Overview First Citizens is seeking an experienced IT Manager - Global Command Center to lead a team ... The manager will oversee daily operations, workforce management, incident response, batch ...
Electronics Technician 3 - Security Systems (Raleigh, NC)
Raleigh, NC · On-site
$23.75 - $32.75/hr
... cybersecurity industries. We are seeking an Electronics Technician 3 to join our Security and ... and command and control systems for federal, local and commercial customers across high-growth ...
Electronics Technician 3 - Security Systems (Raleigh, NC)
Raleigh, NC · On-site
$23.75 - $32.75/hr
... cybersecurity industries. We are seeking an Electronics Technician 3 to join our Security and ... and command and control systems for federal, local and commercial customers across high-growth ...
Cybersecurity Incident Commander information
See Raleigh, NC salary details
$39.9K - $53.9K
6% of jobs
$53.9K - $67.9K
7% of jobs
$67.9K - $81.9K
6% of jobs
$85.2K is the 25th percentile. Wages below this are outliers.
$81.9K - $95.9K
21% of jobs
$95.9K - $109.9K
7% of jobs
The median wage is $115.1K / yr.
$109.9K - $123.9K
4% of jobs
$123.9K - $137.9K
3% of jobs
$137.9K - $151.9K
7% of jobs
$163.2K is the 75th percentile. Wages above this are outliers.
$151.9K - $165.9K
15% of jobs
$165.9K - $179.9K
19% of jobs
$179.9K - $193.9K
3% of jobs
$39.9K
$123.6K
$193.9K
How much do cybersecurity incident commander jobs pay per year?
What is a Cybersecurity Incident Commander?
What are the main challenges a Cybersecurity Incident Commander faces during a major security incident?
What are the key skills and qualifications needed to thrive as a Cybersecurity Incident Commander, and why are they important?
What is the difference between Cybersecurity Incident Commander vs Cybersecurity Analyst?
| Aspect | Cybersecurity Incident Commander | Cybersecurity Analyst |
|---|---|---|
| Certifications | GCIH, CISSP, CISM | CompTIA Security+, GIAC certifications |
| Work Environment | Incident response teams, security operations centers | Monitoring networks, analyzing threats |
| Responsibilities | Lead incident response, coordinate teams, communicate with stakeholders | Detect threats, analyze security data, recommend fixes |
The Cybersecurity Incident Commander focuses on leading and coordinating incident response efforts during security breaches, while the Cybersecurity Analyst primarily monitors systems, analyzes threats, and supports security measures. Both roles require relevant certifications and work in security operations environments, but their responsibilities differ in scope and leadership level.
What are popular job titles related to Cybersecurity Incident Commander jobs in Raleigh, NC?
For Cybersecurity Incident Commander jobs in Raleigh, NC, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Incident Commander jobs in Raleigh, NC look for?
The top searched job categories for Cybersecurity Incident Commander jobs in Raleigh, NC are:
What cities near Raleigh, NC are hiring for Cybersecurity Incident Commander jobs?
Cities near Raleigh, NC with the most Cybersecurity Incident Commander job openings:

Full-time
Posted 5 days ago
Job description
The Sr. Manager, Security Operations is a senior cybersecurity leadership role responsible for leading Advance Auto Parts' enterprise security monitoring, detection, incident response, cyber crisis management, threat hunting, and operational resilience capabilities.
This leader is accountable for the strategic direction, operational effectiveness, and continuous improvement of the Security Operations Center (SOC) and Incident Response (IR) program. The role is responsible for ensuring threats are rapidly detected, investigated, contained, eradicated, and remediated while minimizing risk to business operations, customers, team members, and company reputation.
The Sr. Manager will partner across Cybersecurity, Technology, Legal, Privacy, Corporate Communications, Risk Management, Store Operations, Supply Chain Operations, and Business Leadership to advance the company's cyber defense capabilities and strengthen enterprise resilience against modern threats, including ransomware, identity-based attacks, cloud compromises, insider threats, and third-party breaches.
This role is based out of our corporate headquarters in Raleigh, NC. This is a hybrid work model (4 days in office, 1 day work from home)
Security Operations Leadership
- Lead and mature Advance Auto Parts' Security Operations Center (SOC) capabilities.
- Oversee 24x7 security monitoring, triage, escalation, analysis, and response activities.
- Develop and execute the roadmap for security operations, detection engineering, threat hunting, and operational maturity.
- Establish and track service-level objectives, KPIs, and operational metrics.
- Drive continuous improvement of security operations processes, procedures, workflows, and automation.
Incident Response & Cyber Crisis Management
- Own and manage the enterprise Cybersecurity Incident Response Program.
- Serve as Incident Commander during high-severity cybersecurity events.
- Lead response activities for ransomware, malware outbreaks, business email compromise, credential theft, cloud compromise, insider threats, and major security incidents.
- Coordinate containment, eradication, recovery, and business restoration efforts.
- Lead executive communications during significant cyber events.
- Ensure alignment with legal, regulatory, compliance, privacy, and cyber insurance requirements.
Threat Intelligence
- Drive improvements in enterprise detection capabilities across cloud, endpoint, network, identity, applications, and third-party environments.
- Partner with Engineering and Architecture teams to improve detection coverage and response automation.
- Lead use case development aligned to MITRE ATT&CK and emerging threat intelligence.
- Establish detection effectiveness metrics and continuously improve signal-to-noise ratios.
- Oversee tuning and optimization of monitoring technologies.
- Lead proactive threat hunting operations to identify advanced attacker activity.
- Leverage threat intelligence to improve security monitoring, investigations, and response readiness.
- Maintain visibility into threat actor activity, TTPs, emerging campaigns, and vulnerabilities impacting the retail industry.
- Collaborate with external intelligence providers, ISACs, law enforcement, and industry partners.
Cyber Preparedness & Resilience
- Lead tabletop exercises and cyber crisis simulations.
- Conduct ransomware preparedness exercises and executive-level response testing.
- Ensure incident response playbooks remain current and actionable.
- Perform post-incident reviews and drive corrective actions.
- Maintain enterprise readiness for significant cyber events.
Metrics, Reporting & Governance
- Develop operational dashboards and executive reporting.
- Present security operations metrics, incident trends, threat intelligence insights, and program maturity updates to executive leadership.
- Report on:
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Incident Severity Trends
- Detection Effectiveness
- Threat Hunting Outcomes
- SOC Performance Metrics
- Automation Effectiveness
- Support Board, Audit Committee, and executive cybersecurity reporting.
Leadership & Talent Development
- Lead, mentor, and develop security analysts, incident responders, threat hunters, and detection engineers.
- Build a high-performing cybersecurity operations culture focused on accountability, resilience, and continuous improvement.
- Establish workforce development plans and professional growth opportunities.
- Support recruiting and retention of cybersecurity talent.
Qualifications:
- 10+ years of experience in cybersecurity, incident response and threat intelligence with a strong focus on operational excellence.
- Proven leadership experience in security architectures, security tools and controls, cloud, operations, governance, or risk management.
- Strong background in process improvement methodologies (Lean, Six Sigma, ITIL, Agile).
- Experience with cybersecurity frameworks (NIST, ISO 27001, MITRE ATT&CK).
- Familiarity with security technologies (SIEM, SOAR, EDR, cloud security tools, vulnerability management).
- Excellent communication and leadership skills to drive alignment across security, IT, and business teams.
Preferred Qualifications:
- Certifications: CISSP, CISM, CISA, ITIL,
- Experience in large-scale, complex organizations or highly regulated industries.
- Expertise in cybersecurity automation and analytics.
California Residents click below for Privacy Notice:
https://jobs.advanceautoparts.com/us/en/disclosures
About Advance Auto Parts
Sourced by ZipRecruiter
At Advance Auto Parts we have a passion for YES. Each day we are motivated by a passion to help our Customers. We have a commitment to advance the lives of our fellow Team Members, Customers, and the Communities where we live and work.
Industry
Motor vehicle and motor vehicle parts wholesalers, retail, internet and it and elementary and secondary schools
Company size
10,000+ Employees
Headquarters location
Raleigh, NC, US