1

Cybersecurity Incident Response Manager Jobs (NOW HIRING)

$260K - $365K/yr

Overview Orrick is seeking a highly motivated Managing Associate to join our fast-growing and internationally recognized Cybersecurity & Incident Response practice. This is an opportunity to develop ...

$260K - $365K/yr

Overview Orrick is seeking a highly motivated Managing Associate to join our fast-growing and internationally recognized Cybersecurity & Incident Response practice. This is an opportunity to develop ...

Investigate cybersecurity incidents affecting NIPRNet and SIPRNet environments * Perform proactive ... Firewall Management * Endpoint Security * Security Telemetry Monitoring * Evidence Collection

Incident Response Manager

Austin, TX · Remote

$120K - $140K/yr

As an Incident Response Manager working remote in the United States, you'll be a part of bringing ... What you Bring to the Role: 5 years in CyberSecurity including experience with security tools ...

Incident Response Manager

Austin, TX · Remote

$120K - $140K/yr

Incident Response Manager Apply now Save jobSaved job Your potential has a place here with TTECs ... What you Bring to the Role: 5+ years in CyberSecurity including experience with security tools ...

Incident Response Manager

Austin, TX · On-site

$120K - $140K/yr

As an Incident Response Manager working remote in the United States, you'll be a part of bringing ... What you Bring to the Role: • 5+ years in CyberSecurity including experience with security tools ...

Showing results 21-40

Cybersecurity Incident Response Manager information

See salary details

$41K

$127.2K

$199.5K

How much do cybersecurity incident response manager jobs pay per year?

As of Sep 11, 2026, the average yearly pay for cybersecurity incident response manager in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What does a Cybersecurity Incident Response Manager do?

A Cybersecurity Incident Response Manager is responsible for leading and coordinating the response to cyber threats and security incidents within an organization. They develop and implement incident response plans, oversee investigations into security breaches, and ensure that incidents are contained, eradicated, and properly documented. Additionally, they work closely with IT teams and stakeholders to strengthen security measures, conduct post-incident analysis, and provide training to improve organizational resilience against future attacks.

What are the key skills and qualifications needed to thrive as a cybersecurity incident response manager?

To thrive as a Cybersecurity Incident Response Manager, you need comprehensive knowledge of IT security principles, threat detection, and incident management, typically supported by a degree in computer science or cybersecurity and relevant experience. Familiarity with SIEM platforms, forensic analysis tools, and certifications such as CISSP, CISM, or GIAC are commonly required. Strong leadership, problem-solving, and communication skills help coordinate rapid responses and lead cross-functional teams under pressure. These skills and qualifications are crucial for minimizing organizational risk and ensuring swift, effective responses to security incidents.

How does a cybersecurity incident response manager typically collaborate with other departments during a security incident?

A Cybersecurity Incident Response Manager works closely with IT, legal, communications, and executive leadership teams during a security incident. Their role involves coordinating information sharing, ensuring incident response procedures are followed, and facilitating timely decision-making to minimize risks. Effective collaboration helps streamline investigation, containment, and recovery efforts while ensuring compliance with regulatory requirements and internal policies. Regular cross-departmental drills and clear communication channels are essential for smooth incident handling.

What is the difference between Cybersecurity Incident Response Manager vs Cybersecurity Analyst?

AspectCybersecurity Incident Response ManagerCybersecurity Analyst
CertificationsGCIH, CISSP, CISACompTIA Security+, GIAC Security Essentials
Work EnvironmentLeads incident response teams, manages response strategiesMonitors security systems, analyzes threats
Employer & Industry UsageUsed in organizations with dedicated incident response teamsCommon in security operations centers (SOCs)

The Cybersecurity Incident Response Manager focuses on leading and coordinating incident response efforts, managing teams, and developing response plans. In contrast, the Cybersecurity Analyst primarily monitors security alerts, analyzes threats, and supports incident detection. Both roles require relevant certifications and work within security teams, but the Incident Response Manager has a broader leadership responsibility during security incidents.

What cities are hiring for Cybersecurity Incident Response Manager jobs?

Cities with the most Cybersecurity Incident Response Manager job openings:

What are popular job titles related to Cybersecurity Incident Response Manager jobs?

For Cybersecurity Incident Response Manager jobs, the most frequently searched job titles are:

Cybersecurity Incident Response Analyst II

Bethesda, MD • On-site

Merit321, Launching Careers
Recruiting and Staffing Services • 11 - 50 employees

Full-time

Re-posted 22 days ago


Job description

Job Summary:
Merit321 is a company focused on launching careers, and they are seeking a Tier 2 Cybersecurity Incident Response Analyst. This role provides advanced incident response support for NIH enterprise and cloud environments, responding to incidents, conducting investigations, and coordinating response activities according to established policies and standards.
Responsibilities:
• Respond to and manage incidents reported through the NIH cybersecurity hotline
• Log, categorize, investigate, and escalate incidents per NIH procedures
• Perform Tier 2/3 incident response across on-premises and cloud environments (Azure, AWS, GCP)
• Conduct forensic analysis, threat hunting, and log correlation
• Coordinate response activities with NIH stakeholders and service providers
• Develop executive summaries for significant incidents and third-party events
• Develop and maintain incident response playbooks, SOPs, and KB documentation
• Support annual updates to the NIH Incident Response Plan
• Contribute to incident response maturity assessments and improvement roadmaps
Qualifications:
Required:
• At least 3 years of cybersecurity incident response experience
• Bachelor' degree in related field
• Experience supporting federal, NIH, HHS, or healthcare environments
• Working knowledge of: NIST Cybersecurity Framework (CSF)
• Working knowledge of: NIST SP 800-61 Rev. 2
• Working knowledge of: NIST SP 800-53 Rev. 5 (IR, AU, SI, CA families)
• Working knowledge of: Client CISA guidance
• Hands-on experience responding to incidents in cloud environments
• Strong written communication skills, including executive-level reporting
Preferred:
• Experience developing or maintaining incident response playbooks
• Incident response or security certifications (GCIH, GCIA, CISSP, etc.)
Company:
What do you get when you bring together the most qualified, motivated, and talented individuals and place them into exciting and fast-paced environments that challenge them to be their best? You get a fast-growing company that has your best interest in mind and that supports your career growth. Founded in 2014, the company is headquartered in Rockville, USA, with a team of 11-50 employees. The company is currently Early Stage.