Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Incident Command & Coordination Acts as Incident Commander during major incidents, coordinating ... Collaboration Partners with infrastructure, application, cybersecurity, and business teams to drive ...
Serve as Incident Commander, when assigned, to run the bridge, track actions/owners, and drive ... Escalate incidents to Cybersecurity Operations Management and Incident Response Team members as ...
Serve as Incident Commander, when assigned, to run the bridge, track actions/owners, and drive ... Escalate incidents to Cybersecurity Operations Management and Incident Response Team members as ...
Lead - Incident Responder Cybersecurity
$110K - $146K/hr
Serve as Incident Commander, when assigned, to run the bridge, track actions/owners, and drive ... Escalate incidents to Cybersecurity Operations Management and Incident Response Team members as ...
Lead - Incident Responder Cybersecurity
$110K - $146K/hr
Serve as Incident Commander, when assigned, to run the bridge, track actions/owners, and drive ... Escalate incidents to Cybersecurity Operations Management and Incident Response Team members as ...
Lead - Incident Responder Cybersecurity
Denver, CO · On-site
$110K - $146K/yr
Serve as Incident Commander, when assigned, to run the bridge, track actions/owners, and drive ... Escalate incidents to Cybersecurity Operations Management and Incident Response Team members as ...
Lead - Incident Responder Cybersecurity
Denver, CO · On-site
$110K - $146K/yr
Serve as Incident Commander, when assigned, to run the bridge, track actions/owners, and drive ... Escalate incidents to Cybersecurity Operations Management and Incident Response Team members as ...
... incident response actions, including malware analysis and forensic artifact handling ... Commander • Develop and coordinate courses of action with various Government and contract ...
... incident response actions, including malware analysis and forensic artifact handling ... Commander • Develop and coordinate courses of action with various Government and contract ...
Cyber Command, DISA, and Zero Trust cybersecurity requirements. The Team Lead provides daily ... Incident Response & Reporting * Act as the central POC for Computer Emergency Response. * Lead ...
Cyber Command, DISA, and Zero Trust cybersecurity requirements. The Team Lead provides daily ... Incident Response & Reporting * Act as the central POC for Computer Emergency Response. * Lead ...
GRC & Incident Manager
Los Angeles, CA · On-site
In addition to incident command duties, this role leads the organization's GRC program, including ... Ensure physical security controls align with cybersecurity, business continuity, and compliance ...
GRC & Incident Manager
Los Angeles, CA · On-site
In addition to incident command duties, this role leads the organization's GRC program, including ... Ensure physical security controls align with cybersecurity, business continuity, and compliance ...
Cybersecurity Service Provider (CSSP) Operations Team Lead
Indianapolis, IN · On-site
$106K - $143K/yr
Cyber Command, DISA, and Zero Trust cybersecurity requirements. The Team Lead provides daily ... Incident Response & Reporting * Act as the central POC for Computer Emergency Response. * Lead ...
Cybersecurity Service Provider (CSSP) Operations Team Lead
Indianapolis, IN · On-site
$106K - $143K/yr
Cyber Command, DISA, and Zero Trust cybersecurity requirements. The Team Lead provides daily ... Incident Response & Reporting * Act as the central POC for Computer Emergency Response. * Lead ...
SENIOR CYBERSECURITY ANALYST
Colorado Springs, CO · On-site
$100K - $140K/yr
Army Space and Missile Defense Command (USASMDC) is responsible for delivering global missile ... efforts • Lead cybersecurity incident response and corrective action planning • Advise ...
SENIOR CYBERSECURITY ANALYST
Colorado Springs, CO · On-site
$100K - $140K/yr
Army Space and Missile Defense Command (USASMDC) is responsible for delivering global missile ... efforts • Lead cybersecurity incident response and corrective action planning • Advise ...
Act as incident commander or technical lead, coordinate response actions with leadership across cybersecurity security teams while collaborating with legal, enterprise technology, engineering, and ...
Act as incident commander or technical lead, coordinate response actions with leadership across cybersecurity security teams while collaborating with legal, enterprise technology, engineering, and ...
Act as incident commander or technical lead, coordinate response actions with leadership across cybersecurity security teams while collaborating with legal, enterprise technology, engineering, and ...
Act as incident commander or technical lead, coordinate response actions with leadership across cybersecurity security teams while collaborating with legal, enterprise technology, engineering, and ...
Cyber Command, DISA, and Zero Trust cybersecurity requirements. The Team Lead provides daily ... Incident Response & Reporting * Act as the central POC for Computer Emergency Response. * Lead ...
Cyber Command, DISA, and Zero Trust cybersecurity requirements. The Team Lead provides daily ... Incident Response & Reporting * Act as the central POC for Computer Emergency Response. * Lead ...
Act as incident commander or technical lead, coordinate response actions with leadership across cybersecurity security teams while collaborating with legal, enterprise technology, engineering, and ...
Act as incident commander or technical lead, coordinate response actions with leadership across cybersecurity security teams while collaborating with legal, enterprise technology, engineering, and ...
Consulting Associate/Cybersecurity & Incident Response (Forensic Services practice)
Boston, MA · On-site
Identify and track malware beaconing outbound to its command and control (C2) channel via memory ... Understanding incident handling procedures: preparation, identification, containment, eradication ...
Consulting Associate/Cybersecurity & Incident Response (Forensic Services practice)
Boston, MA · On-site
Identify and track malware beaconing outbound to its command and control (C2) channel via memory ... Understanding incident handling procedures: preparation, identification, containment, eradication ...
Sr. Incident Responder
Spartanburg, SC · On-site
Description Are you the kind of cybersecurity expert who runs toward the fire? Do you thrive in ... Serve as the Incident Commander for high-severity cyber events, orchestrating containment ...
Sr. Incident Responder
Spartanburg, SC · On-site
Description Are you the kind of cybersecurity expert who runs toward the fire? Do you thrive in ... Serve as the Incident Commander for high-severity cyber events, orchestrating containment ...
Cybersecurity Incident Commander information
See salary details
$41K - $55.4K
6% of jobs
$55.4K - $69.8K
7% of jobs
$69.8K - $84.2K
6% of jobs
$87.6K is the 25th percentile. Wages below this are outliers.
$84.2K - $98.6K
21% of jobs
$98.6K - $113K
7% of jobs
The median wage is $118.4K / yr.
$113K - $127.5K
4% of jobs
$127.5K - $141.9K
3% of jobs
$141.9K - $156.3K
7% of jobs
$167.9K is the 75th percentile. Wages above this are outliers.
$156.3K - $170.7K
15% of jobs
$170.7K - $185.1K
19% of jobs
$185.1K - $199.5K
3% of jobs
$41K
$127.2K
$199.5K
How much do cybersecurity incident commander jobs pay per year?
What is the difference between Cybersecurity Incident Commander vs Cybersecurity Analyst?
| Aspect | Cybersecurity Incident Commander | Cybersecurity Analyst |
|---|---|---|
| Certifications | GCIH, CISSP, CISM | CompTIA Security+, GIAC certifications |
| Work Environment | Incident response teams, security operations centers | Monitoring networks, analyzing threats |
| Responsibilities | Lead incident response, coordinate teams, communicate with stakeholders | Detect threats, analyze security data, recommend fixes |
The Cybersecurity Incident Commander focuses on leading and coordinating incident response efforts during security breaches, while the Cybersecurity Analyst primarily monitors systems, analyzes threats, and supports security measures. Both roles require relevant certifications and work in security operations environments, but their responsibilities differ in scope and leadership level.
What are the key skills and qualifications needed to thrive as a Cybersecurity Incident Commander, and why are they important?
What are Cybersecurity Incident Commanders?
What are the main challenges a Cybersecurity Incident Commander faces during a major security incident?

First Citizens Bank rating
7.6
Based on 103 frontline employees who took The Breakroom Quiz
79th of 141 rated banks
Job description
This is a remote role that may only be hired in the following location(s): AZ, FL, GA, NC and TX.
This position enhances the operational reliability, resilience, and stability of enterprise IT services through effective Major Incident Management practices. The role is responsible for leading the response to high-impact incidents, minimizing business disruption, and restoring service as quickly as possible. Facilitates the development and maturity of IT service management capabilities by driving continuous improvement across incident, problem, and change processes. Serves as a key technical and process leader during critical events and ensures compliance with all applicable IT or Enterprise Service Management (ITSM or ESM) standards and regulations. Ensure that incident response procedures, post-incident reviews, and process improvements are properly documented, implemented, and managed throughout their lifecycle.
Responsibilities
- Responsibilities:
- Major Incident Management & Process Improvement
Leads the end-to-end lifecycle of major incidents, including detection, prioritization, escalation, coordination, and resolution. Drives continuous improvement of incident management processes, runbooks, and response frameworks to enhance operational effectiveness. Conducts post-incident reviews (PIRs) to identify root causes and preventative measures. Ensures incidents, problems, and associated changes are managed efficiently while maintaining service levels across platforms. - Incident Command & Coordination
Acts as Incident Commander during major incidents, coordinating cross-functional technical teams, vendors, and stakeholders to rapidly restore service. Establishes clear roles, timelines, and action plans during incident bridges. Removes blockers and ensures timely decision-making under pressure. - Reporting & Analytics
Responsible for documenting incidents, producing executive-level reports, and tracking key performance metrics such as MTTR (Mean Time to Restore), MTTD (Mean Time to Detect), incident volume, and SLA adherence. Monitors trends and provides data-driven insights to improve service reliability and reduce recurring issues. - Collaboration
Partners with infrastructure, application, cybersecurity, and business teams to drive swift resolution of major incidents and improve long-term service resilience. Collaborates with Problem Management to ensure root cause analysis is completed and corrective actions are tracked. Supports Change Management to reduce incident risk from changes. - Communication
Provides clear, concise, and timely communication to stakeholders at all levels during major incidents, including executive leadership. Publishes incident summaries, status updates, and post-incident reports. Ensures communication standards are met during high-pressure scenarios with a focus on transparency and business impact. - Governance & Compliance
Ensures adherence to ITIL and organizational ITSM standards. Supports audit and compliance requirements related to incident and change management processes. Maintains documentation, playbooks, and escalation procedures. - Training & Enablement
Leads or supports training for IT teams on incident response procedures, tools, and best practices. Promotes a culture of operational excellence and continuous improvement.
- Major Incident Management & Process Improvement
Qualifications
Qualifications:
Bachelor's Degree and 6 years of experience in Operational Information Technology services and support including processes, programs, and procedures
OR
High School Diploma or GED and 10 years of experience in Operational Information Technology services and support including processes, programs, and procedures
Preferred Area of Experience:
ITSM Process Management (Incident, Major Incident, Problem, Change, or other relevant ITSM/ESM processes)
Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at ;br>
License or Certification Type:
- ITIL Certification (v3 or v4) - Preferred
- Six Sigma (Green Belt or higher) - Preferred
Preferred Experience:
- 5+ years of hands-on experience in Major Incident Management or Incident Command roles in a large enterprise environment
- Proven ability to lead severity 1 / critical outages affecting customer-facing or mission-critical systems
- Strong experience with ITSM tools (e.g., ServiceNow, BMC Remedy, or similar)
- Demonstrated success in reducing MTTR and improving incident response maturity
- Experience facilitating post-incident reviews (PIRs) and driving root cause resolution through Problem Management
- Ability to manage high-pressure situations, make rapid decisions, and coordinate distributed teams
- Strong understanding of infrastructure, applications, cloud platforms and networking concepts
- Excellent executive communication and stakeholder management skills
- Familiarity with SRE principles, observability tools, and event management frameworks is a plus
$descr2
$descr3
What First Citizens Bank employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom