Sr. Cybersecurity Engineer
$111K - $138K/yr
Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear ...
$111K - $138K/yr
Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear ...
$111K - $138K/yr
Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear ...
Atlanta, GA · On-site
$111K - $138K/yr
Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear ...
Atlanta, GA · On-site
$111K - $138K/yr
Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear ...
... cybersecurity incident response. The role sits at the intersection of real-time incident command and intelligent automation, combining hands-on leadership during the enterprise's most critical ...
... cybersecurity incident response. The role sits at the intersection of real-time incident command and intelligent automation, combining hands-on leadership during the enterprise's most critical ...
Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents
Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents
You will command enterprise response to material cyber incidents across cloud,onpremises, and OT ... Lead execution of the Incident Response (IR) plan to rapidly scope,contain, eradicate, and ...
You will command enterprise response to material cyber incidents across cloud,onpremises, and OT ... Lead execution of the Incident Response (IR) plan to rapidly scope,contain, eradicate, and ...
You will command enterprise response to material cyber incidents across cloud,onpremises, and OT ... Lead execution of the Incident Response (IR) plan to rapidly scope,contain, eradicate, and ...
You will command enterprise response to material cyber incidents across cloud,onpremises, and OT ... Lead execution of the Incident Response (IR) plan to rapidly scope,contain, eradicate, and ...
... cybersecurity incident response. The role sits at the intersection of real-time incident command and intelligent automation, combining hands-on leadership during the enterprise's most critical ...
... cybersecurity incident response. The role sits at the intersection of real-time incident command and intelligent automation, combining hands-on leadership during the enterprise's most critical ...
Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents
Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents
... cybersecurity incident response. The role sits at the intersection of real-time incident command and intelligent automation, combining hands-on leadership during the enterprise's most critical ...
... cybersecurity incident response. The role sits at the intersection of real-time incident command and intelligent automation, combining hands-on leadership during the enterprise's most critical ...
Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents
Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents
$80 - $130/hr
Army Space and Missile Defense Command (USASMDC) is responsible for delivering global missile ... incident response and remediation activities Coordinate with system owners, ISSOs, and network ...
$80 - $130/hr
Army Space and Missile Defense Command (USASMDC) is responsible for delivering global missile ... incident response and remediation activities Coordinate with system owners, ISSOs, and network ...
New York, NY · On-site
$121K - $164K/yr
... Incident Commander (CIC) during major security events. This person will operate as part of a global cybersecurity defense organization, provide operational leadership, while also leading the ...
New York, NY · On-site
$121K - $164K/yr
... Incident Commander (CIC) during major security events. This person will operate as part of a global cybersecurity defense organization, provide operational leadership, while also leading the ...
... Cybersecurity Operations Center (GSOC) , based in Gaithersburg, Maryland, reporting to the Head of ... Incident Command: Lead execution of the Incident Response (IR) plan to rapidly scope, contain ...
... Cybersecurity Operations Center (GSOC) , based in Gaithersburg, Maryland, reporting to the Head of ... Incident Command: Lead execution of the Incident Response (IR) plan to rapidly scope, contain ...
... Cybersecurity Operations Center (GSOC) , based in Gaithersburg, Maryland, reporting to the Head of ... Incident Command: Lead execution of the Incident Response (IR) plan to rapidly scope, contain ...
... Cybersecurity Operations Center (GSOC) , based in Gaithersburg, Maryland, reporting to the Head of ... Incident Command: Lead execution of the Incident Response (IR) plan to rapidly scope, contain ...
Incident Command: Lead execution of the Incident Response (IR) plan to rapidly scope, contain ... Over five (5) years managing Cyber Security Operations Centre Incident Response in enterprise-sized ...
Incident Command: Lead execution of the Incident Response (IR) plan to rapidly scope, contain ... Over five (5) years managing Cyber Security Operations Centre Incident Response in enterprise-sized ...
Jersey City, NJ · Hybrid
$115K - $156K/yr
Being a member of IT Cybersecurity & Platform Strategy team, reporting to the Cyber Monitoring and ... Act as Incident Commander on major (P1) incidents and as an escalation point for your team for ...
Jersey City, NJ · Hybrid
$115K - $156K/yr
Being a member of IT Cybersecurity & Platform Strategy team, reporting to the Cyber Monitoring and ... Act as Incident Commander on major (P1) incidents and as an escalation point for your team for ...
Tampa, FL · Hybrid
$101K - $136K/yr
Being a member of IT Cybersecurity & Platform Strategy team, reporting to the Cyber Monitoring and ... Act as Incident Commander on major (P1) incidents and as an escalation point for your team for ...
Tampa, FL · Hybrid
$101K - $136K/yr
Being a member of IT Cybersecurity & Platform Strategy team, reporting to the Cyber Monitoring and ... Act as Incident Commander on major (P1) incidents and as an escalation point for your team for ...
Tampa, FL · On-site
$104K - $141K/yr
Being a member of IT Cybersecurity & Platform Strategy team, reporting to the Cyber Monitoring and ... Act as Incident Commander on major (P1) incidents and as an escalation point for your team for ...
Tampa, FL · On-site
$104K - $141K/yr
Being a member of IT Cybersecurity & Platform Strategy team, reporting to the Cyber Monitoring and ... Act as Incident Commander on major (P1) incidents and as an escalation point for your team for ...
Tampa, FL · Hybrid
$104K - $141K/yr
Being a member of IT Cybersecurity & Platform Strategy team, reporting to the Cyber Monitoring and ... Act as Incident Commander on major (P1) incidents and as an escalation point for your team for ...
Tampa, FL · Hybrid
$104K - $141K/yr
Being a member of IT Cybersecurity & Platform Strategy team, reporting to the Cyber Monitoring and ... Act as Incident Commander on major (P1) incidents and as an escalation point for your team for ...
Raleigh, NC · On-site
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Raleigh, NC · On-site
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
$41K - $55.4K
6% of jobs
$55.4K - $69.8K
7% of jobs
$69.8K - $84.2K
6% of jobs
$87.6K is the 25th percentile. Wages below this are outliers.
$84.2K - $98.6K
21% of jobs
$98.6K - $113K
7% of jobs
The median wage is $118.4K / yr.
$113K - $127.5K
4% of jobs
$127.5K - $141.9K
3% of jobs
$141.9K - $156.3K
7% of jobs
$167.9K is the 75th percentile. Wages above this are outliers.
$156.3K - $170.7K
15% of jobs
$170.7K - $185.1K
19% of jobs
$185.1K - $199.5K
3% of jobs
$41K
$127.2K
$199.5K
| Aspect | Cybersecurity Incident Commander | Cybersecurity Analyst |
|---|---|---|
| Certifications | GCIH, CISSP, CISM | CompTIA Security+, GIAC certifications |
| Work Environment | Incident response teams, security operations centers | Monitoring networks, analyzing threats |
| Responsibilities | Lead incident response, coordinate teams, communicate with stakeholders | Detect threats, analyze security data, recommend fixes |
The Cybersecurity Incident Commander focuses on leading and coordinating incident response efforts during security breaches, while the Cybersecurity Analyst primarily monitors systems, analyzes threats, and supports security measures. Both roles require relevant certifications and work in security operations environments, but their responsibilities differ in scope and leadership level.

$111K - $138K/yr
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 19 days ago
7.4
Based on 154 frontline employees who took The Breakroom Quiz
17th of 44 rated automakers
Rivian is on a mission to keep the world adventurous forever. This goes for the emissions-free Electric Adventure Vehicles we build, and the curious, courageous souls we seek to attract.
As a company, we constantly challenge what’s possible, never simply accepting what has always been done. We reframe old problems, seek new solutions and operate comfortably in areas that are unknown. Our backgrounds are diverse, but our team shares a love of the outdoors and a desire to protect it for future generations.
We are seeking an Incident Commander to lead our response capabilities through a code-first lens. You are dedicated to minimizing impact and downtime by deploying automation and ensuring total observability across our environment. You will serve as an Incident Commander during critical Cybersecurity incidents, simultaneously building the integrations and tools that scale our ability to detect, respond, and recover. This role will be a hybrid opportunity in Atlanta, GA and will report to our Sr. Manager Cybersecurity.
Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear communication streams to minimize business downtime.
Engineering Resilience: Pivot from reactive "fire-fighting" to proactive "fire-proofing." operationalize "Security as Code" by developing automation scripts and SOAR workflows to handle repetitive threats.
Observability & Detection: Enhance our threat detection capabilities by treating logs as data pipelines. Work with engineering teams to ensure our monitoring tools provide high-fidelity signals, not just noise.
Blameless Post-Mortems: Lead comprehensive After-Action Reviews (AARs) with a focus on root cause analysis. Translate findings into architectural improvements rather than policy patches.
Tooling & Integration: Bridge the gap between Security and DevOps. Build and refine integrations between our security stack (SIEM, EDR) and infrastructure tools (CI/CD, Cloud providers) to streamline response capabilities.
On-Call Rotation: Participate in a structured on-call rotation to provide critical command coverage outside of standard business hours, ensuring 24/7 operational continuity and rapid remediation.
Command Presence: Proven ability to manage complex, high-stress incidents with clarity and authority. You can translate technical crises into business language for executive stakeholders.
Hybrid Background: Experience in Incident Response is critical, but we highly value candidates coming from DevOps, SRE, or Infrastructure Engineering backgrounds who want to apply their skills to Security.
Automation First Mindset: Proficiency in scripting (Python, Go, or PowerShell) and familiarity with automation platforms.
Cloud Fluency: Deep understanding of cloud-native infrastructure (AWS/GCP/Azure) and how to respond to incidents within containerized (Kubernetes/Docker) environments.
Salary Range for this role is $111,000 - $138,700 for Georgia based applicants. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee’s position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, geographic location, shift, and organizational needs.
The successful candidate may be eligible for annual performance bonus and equity awards.
We offer a comprehensive package of benefits for full-time and part-time employees, their spouse or domestic partner, and children up to age 26, including but not limited to paid vacation, paid sick leave, and a competitive portfolio of insurance benefits including life, medical, dental, vision, short-term disability insurance, and long-term disability insurance to eligible employees. You may also have the opportunity to participate in Rivian’s 401(k) Plan and Employee Stock Purchase Program if you meet certain eligibility requirements. Full-time employee coverage is effective on their first day of employment. Part-time employee coverage is effective the first of the month following 90 days of employment. More information about benefits is available at rivianbenefits.com.
You can apply for this role through careers.rivian.com (or through internal-careers-rivian.icims.com if you are a current employee). This job is not expected to be closed any sooner than February 6, 2026.
Rivian is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law.
Rivian is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at candidateaccommodations@rivian.com.
Candidate Data PrivacyRivian may collect, use and disclose your personal information or personal data (within the meaning of the applicable data protection laws) when you apply for employment and/or participate in our recruitment processes (“Candidate Personal Data”). This data includes contact, demographic, communications, educational, professional, employment, social media/website, network/device, recruiting system usage/interaction, security and preference information. Rivian may use your Candidate Personal Data for the purposes of (i) tracking interactions with our recruiting system; (ii) carrying out, analyzing and improving our application and recruitment process, including assessing you and your application and conducting employment, background and reference checks; (iii) establishing an employment relationship or entering into an employment contract with you; (iv) complying with our legal, regulatory and corporate governance obligations; (v) recordkeeping; (vi) ensuring network and information security and preventing fraud; and (vii) as otherwise required or permitted by applicable law.
Rivian may share your Candidate Personal Data with (i) internal personnel who have a need to know such information in order to perform their duties, including individuals on our People Team, Finance, Legal, and the team(s) with the position(s) for which you are applying; (ii) Rivian affiliates; and (iii) Rivian’s service providers, including providers of background checks, staffing services, and cloud services.
Rivian may transfer or store internationally your Candidate Personal Data, including to or in the United States, Canada, the United Kingdom, and the European Union and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions.
Please note that we are currently not accepting applications from third party application services.
Qualifications:Command Presence: Proven ability to manage complex, high-stress incidents with clarity and authority. You can translate technical crises into business language for executive stakeholders.
Hybrid Background: Experience in Incident Response is critical, but we highly value candidates coming from DevOps, SRE, or Infrastructure Engineering backgrounds who want to apply their skills to Security.
Automation First Mindset: Proficiency in scripting (Python, Go, or PowerShell) and familiarity with automation platforms.
Cloud Fluency: Deep understanding of cloud-native infrastructure (AWS/GCP/Azure) and how to respond to incidents within containerized (Kubernetes/Docker) environments.
Sourced by ZipRecruiter
Rivian is a pioneering automotive industry player headquartered in Irvine, California. Established in 2009, the company has made notable advancements in developing sustainable transportation solutions. It is widely recognized for its electric adventure vehicles: the R1T pickup and the R1S SUV. Rivian is dedicated to creating a positive shift in societal mobility and emphasizes sustainability, innovation, and adventure as part of its core values. Their mission is to keep the world adventurous forever - a testament to their commitment in transitioning the world to sustainable transportation. Rivian's achievements are numerous, with one of the most notable being securing a significant multi-billion dollar investment from Amazon for the production of electric delivery vans.
Automobile dealers
10,000+ Employees
Irvine, CA, US
2009