1

Cybersecurity Incident Commander Jobs (NOW HIRING)

Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear ...

Sr. Cybersecurity Engineer

Atlanta, GA · On-site

$111K - $138K/yr

Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear ...

Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents

Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents

Experienced in cybersecurity incident response, endpoint security, SOC management, and Linux ... Experience acting as an escalation lead or incident commander for high severity incidents

Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...

next page

Showing results 1-20

Cybersecurity Incident Commander information

See salary details

$41K

$127.2K

$199.5K

How much do cybersecurity incident commander jobs pay per year?

As of Jun 9, 2026, the average yearly pay for cybersecurity incident commander in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What is the difference between Cybersecurity Incident Commander vs Cybersecurity Analyst?

AspectCybersecurity Incident CommanderCybersecurity Analyst
CertificationsGCIH, CISSP, CISMCompTIA Security+, GIAC certifications
Work EnvironmentIncident response teams, security operations centersMonitoring networks, analyzing threats
ResponsibilitiesLead incident response, coordinate teams, communicate with stakeholdersDetect threats, analyze security data, recommend fixes

The Cybersecurity Incident Commander focuses on leading and coordinating incident response efforts during security breaches, while the Cybersecurity Analyst primarily monitors systems, analyzes threats, and supports security measures. Both roles require relevant certifications and work in security operations environments, but their responsibilities differ in scope and leadership level.

What are the key skills and qualifications needed to thrive as a Cybersecurity Incident Commander, and why are they important?

To thrive as a Cybersecurity Incident Commander, you need deep knowledge of cybersecurity principles, incident response frameworks, and risk management, often supported by a degree in computer science and certifications like CISSP or GCIH. Familiarity with Security Information and Event Management (SIEM) tools, forensic analysis platforms, and incident tracking systems is typically required. Strong leadership, decision-making, and communication skills are essential for coordinating teams and managing crises under pressure. These competencies ensure swift, effective response to cyber threats, minimizing organizational impact and ensuring regulatory compliance.

What are Cybersecurity Incident Commanders?

Cybersecurity Incident Commanders are professionals responsible for leading and coordinating an organization’s response to cybersecurity incidents, such as data breaches or cyberattacks. They develop and execute response plans, communicate with stakeholders, and ensure that containment, eradication, and recovery actions are taken efficiently. Their role is critical in minimizing damage, protecting sensitive data, and restoring normal operations. They also conduct post-incident reviews to improve future responses and security measures.

What are the main challenges a Cybersecurity Incident Commander faces during a major security incident?

A Cybersecurity Incident Commander often faces the challenge of coordinating cross-functional teams under high-pressure situations while maintaining clear communication and decision-making. They must rapidly assess evolving threats, prioritize response actions, and ensure all stakeholders are informed and aligned. Balancing timely containment of the incident with thorough evidence preservation for forensic investigation is another key challenge. This role requires staying calm, organized, and adaptable in dynamic environments where situations can change rapidly.
More about Cybersecurity Incident Commander jobs
What cities are hiring for Cybersecurity Incident Commander jobs? Cities with the most Cybersecurity Incident Commander job openings:
What states have the most Cybersecurity Incident Commander jobs? States with the most job openings for Cybersecurity Incident Commander jobs include:
What job categories do people searching Cybersecurity Incident Commander jobs look for? The top searched job categories for Cybersecurity Incident Commander jobs are:
Infographic showing various Cybersecurity Incident Commander job openings in the United States as of May 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.
Sr. Cybersecurity Engineer

Sr. Cybersecurity Engineer

Rivian

Atlanta, GA

$111K - $138K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 19 days ago


Rivian rating

7.4

Company rating: 7.4 out of 10

Based on 154 frontline employees who took The Breakroom Quiz

17th of 44 rated automakers


Job description

About Rivian

Rivian is on a mission to keep the world adventurous forever. This goes for the emissions-free Electric Adventure Vehicles we build, and the curious, courageous souls we seek to attract. 

As a company, we constantly challenge what’s possible, never simply accepting what has always been done. We reframe old problems, seek new solutions and operate comfortably in areas that are unknown. Our backgrounds are diverse, but our team shares a love of the outdoors and a desire to protect it for future generations. 


Role Summary

We are seeking an Incident Commander to lead our response capabilities through a code-first lens. You are dedicated to minimizing impact and downtime by deploying automation and ensuring total observability across our environment. You will serve as an Incident Commander during critical Cybersecurity incidents, simultaneously building the integrations and tools that scale our ability to detect, respond, and recover. This role will be a hybrid opportunity in Atlanta, GA and will report to our Sr. Manager Cybersecurity. 


Responsibilities
  • Incident Command & Crisis Management: Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear communication streams to minimize business downtime.

  • Engineering Resilience: Pivot from reactive "fire-fighting" to proactive "fire-proofing." operationalize "Security as Code" by developing automation scripts and SOAR workflows to handle repetitive threats.

  • Observability & Detection: Enhance our threat detection capabilities by treating logs as data pipelines. Work with engineering teams to ensure our monitoring tools provide high-fidelity signals, not just noise.

  • Blameless Post-Mortems: Lead comprehensive After-Action Reviews (AARs) with a focus on root cause analysis. Translate findings into architectural improvements rather than policy patches.

  • Tooling & Integration: Bridge the gap between Security and DevOps. Build and refine integrations between our security stack (SIEM, EDR) and infrastructure tools (CI/CD, Cloud providers) to streamline response capabilities.

  • On-Call Rotation: Participate in a structured on-call rotation to provide critical command coverage outside of standard business hours, ensuring 24/7 operational continuity and rapid remediation.


Qualifications
  • 5+ years of experience in product security, application security, or security architecture.
  • Command Presence: Proven ability to manage complex, high-stress incidents with clarity and authority. You can translate technical crises into business language for executive stakeholders.

  • Hybrid Background: Experience in Incident Response is critical, but we highly value candidates coming from DevOps, SRE, or Infrastructure Engineering backgrounds who want to apply their skills to Security.

  • Automation First Mindset: Proficiency in scripting (Python, Go, or PowerShell) and familiarity with automation platforms.

  • Cloud Fluency: Deep understanding of cloud-native infrastructure (AWS/GCP/Azure) and how to respond to incidents within containerized (Kubernetes/Docker) environments.

  • Frameworks: Deep understanding of incident handling lifecycles (NIST 800-61) and attacker TTPs (MITRE ATT&CK).

Pay Disclosure

Salary Range for this role is $111,000 - $138,700 for Georgia based applicants. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee’s position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, geographic location, shift, and organizational needs.

The successful candidate may be eligible for annual performance bonus and equity awards. 

We offer a comprehensive package of benefits for full-time and part-time employees, their spouse or domestic partner, and children up to age 26, including but not limited to paid vacation, paid sick leave, and a competitive portfolio of insurance benefits including life, medical, dental, vision, short-term disability insurance, and long-term disability insurance to eligible employees. You may also have the opportunity to participate in Rivian’s 401(k) Plan and Employee Stock Purchase Program if you meet certain eligibility requirements. Full-time employee coverage is effective on their first day of employment. Part-time employee coverage is effective the first of the month following 90 days of employment. More information about benefits is available at rivianbenefits.com. 

You can apply for this role through careers.rivian.com (or through internal-careers-rivian.icims.com if you are a current employee). This job is not expected to be closed any sooner than February 6, 2026.



Equal Opportunity

Rivian is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law.

Rivian is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at candidateaccommodations@rivian.com.

Candidate Data Privacy

Rivian may collect, use and disclose your personal information or personal data (within the meaning of the applicable data protection laws) when you apply for employment and/or participate in our recruitment processes (“Candidate Personal Data”). This data includes contact, demographic, communications, educational, professional, employment, social media/website, network/device, recruiting system usage/interaction, security and preference information. Rivian may use your Candidate Personal Data for the purposes of (i) tracking interactions with our recruiting system; (ii) carrying out, analyzing and improving our application and recruitment process, including assessing you and your application and conducting employment, background and reference checks; (iii) establishing an employment relationship or entering into an employment contract with you; (iv) complying with our legal, regulatory and corporate governance obligations; (v) recordkeeping; (vi) ensuring network and information security and preventing fraud; and (vii) as otherwise required or permitted by applicable law. 

Rivian may share your Candidate Personal Data with (i) internal personnel who have a need to know such information in order to perform their duties, including individuals on our People Team, Finance, Legal, and the team(s) with the position(s) for which you are applying; (ii) Rivian affiliates; and (iii) Rivian’s service providers, including providers of background checks, staffing services, and cloud services. 

Rivian may transfer or store internationally your Candidate Personal Data, including to or in the United States, Canada, the United Kingdom, and the European Union and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions.  

Please note that we are currently not accepting applications from third party application services.

Qualifications:
  • 5+ years of experience in product security, application security, or security architecture.
  • Command Presence: Proven ability to manage complex, high-stress incidents with clarity and authority. You can translate technical crises into business language for executive stakeholders.

  • Hybrid Background: Experience in Incident Response is critical, but we highly value candidates coming from DevOps, SRE, or Infrastructure Engineering backgrounds who want to apply their skills to Security.

  • Automation First Mindset: Proficiency in scripting (Python, Go, or PowerShell) and familiarity with automation platforms.

  • Cloud Fluency: Deep understanding of cloud-native infrastructure (AWS/GCP/Azure) and how to respond to incidents within containerized (Kubernetes/Docker) environments.

  • Frameworks: Deep understanding of incident handling lifecycles (NIST 800-61) and attacker TTPs (MITRE ATT&CK).
Education:UNAVAILABLEEmployment Type: FULL_TIME

What Rivian employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Rivian logo

About Rivian

Sourced by ZipRecruiter

Rivian is a pioneering automotive industry player headquartered in Irvine, California. Established in 2009, the company has made notable advancements in developing sustainable transportation solutions. It is widely recognized for its electric adventure vehicles: the R1T pickup and the R1S SUV. Rivian is dedicated to creating a positive shift in societal mobility and emphasizes sustainability, innovation, and adventure as part of its core values. Their mission is to keep the world adventurous forever - a testament to their commitment in transitioning the world to sustainable transportation. Rivian's achievements are numerous, with one of the most notable being securing a significant multi-billion dollar investment from Amazon for the production of electric delivery vans.

Industry

Automobile dealers

Company size

10,000+ Employees

Headquarters location

Irvine, CA, US

Year founded

2009