1

Cybersecurity Incident Commander Jobs (NOW HIRING)

Head of Cybersecurity Defense Operations

Buffalo, NY · Hybrid

$107K - $145K/yr

The Cybersecurity Operations division serves as the focal point for M&T's 24x7x365 cyber defense ... Serve as (or designate) the Cyber Incident Commander for high-severity/major incidents, directing ...

Head of Cybersecurity Defense Operations

Buffalo, NY · On-site

$107K - $145K/yr

The Cybersecurity Operations division serves as the focal point for M&T's 24x7x365 cyber defense ... Serve as (or designate) the Cyber Incident Commander for high-severity/major incidents, directing ...

Lead the Cybersecurity Incident Response lifecycle as an Incident Commander during high-demand events/incidents. * Advise leadership and assist management of SOC personnel, personnel readiness, team ...

Sr. Cybersecurity Engineer

Atlanta, GA · On-site

$111K - $138K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear ...

Lead Analyst, Cybersecurity

North Metro, GA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents

Sr. Cybersecurity Engineer

Atlanta, GA

$111K - $138K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear ...

Sr. Cybersecurity Engineer

Atlanta, GA · On-site

$111K - $138K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear ...

Lead Analyst, Cybersecurity

North Metro, GA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents

Lead Analyst, Cybersecurity

Duluth, GA

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents

Lead Analyst, Cybersecurity

Duluth, GA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents

Showing results 21-40

Cybersecurity Incident Commander information

See salary details

$41K

$127.2K

$199.5K

How much do cybersecurity incident commander jobs pay per year?

As of Aug 16, 2026, the average yearly pay for cybersecurity incident commander in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What is a Cybersecurity Incident Commander?

Cybersecurity Incident Commanders are professionals responsible for leading and coordinating an organization’s response to cybersecurity incidents, such as data breaches or cyberattacks. They develop and execute response plans, communicate with stakeholders, and ensure that containment, eradication, and recovery actions are taken efficiently. Their role is critical in minimizing damage, protecting sensitive data, and restoring normal operations. They also conduct post-incident reviews to improve future responses and security measures.

What are the main challenges a Cybersecurity Incident Commander faces during a major security incident?

A Cybersecurity Incident Commander often faces the challenge of coordinating cross-functional teams under high-pressure situations while maintaining clear communication and decision-making. They must rapidly assess evolving threats, prioritize response actions, and ensure all stakeholders are informed and aligned. Balancing timely containment of the incident with thorough evidence preservation for forensic investigation is another key challenge. This role requires staying calm, organized, and adaptable in dynamic environments where situations can change rapidly.

What are the key skills and qualifications needed to thrive as a Cybersecurity Incident Commander, and why are they important?

To thrive as a Cybersecurity Incident Commander, you need deep knowledge of cybersecurity principles, incident response frameworks, and risk management, often supported by a degree in computer science and certifications like CISSP or GCIH. Familiarity with Security Information and Event Management (SIEM) tools, forensic analysis platforms, and incident tracking systems is typically required. Strong leadership, decision-making, and communication skills are essential for coordinating teams and managing crises under pressure. These competencies ensure swift, effective response to cyber threats, minimizing organizational impact and ensuring regulatory compliance.

What is the difference between Cybersecurity Incident Commander vs Cybersecurity Analyst?

AspectCybersecurity Incident CommanderCybersecurity Analyst
CertificationsGCIH, CISSP, CISMCompTIA Security+, GIAC certifications
Work EnvironmentIncident response teams, security operations centersMonitoring networks, analyzing threats
ResponsibilitiesLead incident response, coordinate teams, communicate with stakeholdersDetect threats, analyze security data, recommend fixes

The Cybersecurity Incident Commander focuses on leading and coordinating incident response efforts during security breaches, while the Cybersecurity Analyst primarily monitors systems, analyzes threats, and supports security measures. Both roles require relevant certifications and work in security operations environments, but their responsibilities differ in scope and leadership level.

More about Cybersecurity Incident Commander jobs

What cities are hiring for Cybersecurity Incident Commander jobs?

Cities with the most Cybersecurity Incident Commander job openings:

What states have the most Cybersecurity Incident Commander jobs?

States with the most job openings for Cybersecurity Incident Commander jobs include:

What job categories do people searching Cybersecurity Incident Commander jobs look for?

The top searched job categories for Cybersecurity Incident Commander jobs are:

Infographic showing various Cybersecurity Incident Commander job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $127,177 per year, or $61.1 per hour.

Technology Support Lead - Incident Management & Response (IMR)

JPMorganChase

Seattle, WA • On-site

Full-time

Re-posted 29 days ago


Job description

Job Summary:
JPMorganChase is one of the oldest financial institutions, providing innovative financial solutions globally. The Technology Support Lead will be a key member of the Cybersecurity & Technology Controls Incident Management & Response team, responsible for 24/7 incident management and response support to safeguard the firm's infrastructure against cybersecurity threats.
Responsibilities:
• Serve as a key member of the Cybersecurity & Technology Controls (CTC) Incident Management & Response (IMR) team within the Global Incident Command Center (GICC) and Security Operations Center (SOC), providing 24/7 support for incident management and response.
• Execute the Firm-wide Cybersecurity Incident Management Playbook to orchestrate actions during the lifecycle of cybersecurity events, aiming to prevent or mitigate impacts.
• Act as the frontline defense for cybersecurity incidents, ensuring effective and timely resolution of security issues against the firm's infrastructure.
• Collaborate with internal and external partners, including regulatory, compliance, privacy, and media communications teams, to manage incidents.
• Utilize command and control, communication, and documentation skills to ensure the stability, capacity, and resiliency of products.
• Work closely with Cybersecurity Operations Incident Response teams and Enterprise Technology Product and Engineering teams to mitigate and remediate events and incidents.
• Analyze operational metrics to identify process improvements and deliver constructive feedback to the team.
• Engage in continuous improvement of practices and processes, and participate in research, internal procedure uplift, and internal tools development.
Qualifications:
Required:
• Formal training or certification on technology support concepts and 5+ years applied experience
• Minimum of five years of experience in an Incident Management or Incident Response function in an enterprise environment.
• Demonstrated command and control, documentation, and communication skills in previous roles.
• Experience communicating technical topics both in writing and verbally to senior management from technical and non-technical backgrounds.
• Ability to work closely with business, technology, and project management partners to execute projects and improvements for the CTC IMR team.
• Strong understanding of the ITIL framework and experience with incident management tools.
• Basic understanding of various operating systems, network fundamentals, cyber tools, and cloud architecture.
• High-level understanding of cybersecurity attack frameworks, such as MITRE ATT&CK and Cyber Kill Chain.
• Ability to exercise excellent judgment and decision-making skills under pressure and know when to escalate issues.
• Ability to influence senior technology managers across organizational boundaries through formal and informal channels.
• Proactive with a strong bias for action, naturally inquisitive, and committed to continuous improvement.
Preferred:
• Demonstrated ability to multitask and prioritize in a stressful environment; results-oriented.
• Ability to use available mainstream AI tools to increase productivity and innovate existing processes.
• ITIL Certification.
• Baseline cybersecurity certifications, such as Security+ or Google Cybersecurity Certificate.
• Awareness of the wider roles of interconnecting cybersecurity teams and collaboration with teams like Forensics, Threat Intelligence, Penetration Testing, and Vulnerability Management.
• Experience with delivering constructive feedback to a team on a continuous basis.
Company:
With a history tracing its roots to 1799 in New York City, JPMorganChase is one of the world's oldest, largest, and best-known financial institutions—carrying forth the innovative spirit of our heritage firms in global operations across 100 markets. Founded in 2000, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.