1

Incident Command Jobs (NOW HIRING)

Establish and maintain incident command during high-severity or large-scale incidents. * Drive cross-functional collaboration and decision making across technical and business teams to ensure timely ...

Establish and maintain incident command during high-severity or large-scale incidents. * Drive cross-functional collaboration and decision making across technical and business teams to ensure timely ...

... incident command efforts, manage security incidents, and ensure effective response to cybersecurity events across the organization. Responsibilities : • Serve as the primary Security Incident ...

... incident command efforts, manage security incidents, and ensure effective response to cybersecurity events across the organization. Responsibilities : • Serve as the primary Security Incident ...

Incident Commander

Miami, FL · On-site

$30/hr

In your day to day role as an Incident Commander, you will be acting as a liaison between Surefox and its clients while providing emergency response. You will perform all duties in accordance with ...

Incident Commander

Miami, FL · On-site

$30/hr

In your day to day role as an Incident Commander, you will be acting as a liaison between Surefox and its clients while providing emergency response. You will perform all duties in accordance with ...

Incident Commander

Miami, FL · On-site

$30/hr

In your day to day role as an Incident Commander, you will be acting as a liaison between Surefox and its clients while providing emergency response. You will perform all duties in accordance with ...

Incident Commander

Draper, UT · On-site

$25/hr

We are currently seeking an experienced Incident Commander with high integrity and professionalism who can join our team here in the Draper, UT. You will be working on uniquely assigned projects ...

Incident Commander

Draper, UT · On-site

$25/hr

We are currently seeking an experienced Incident Commander with high integrity and professionalism who can join our team here in the Bay Area. You will be working on uniquely assigned projects under ...

Incident Commander

Draper, UT · On-site

$25/hr

We are currently seeking an experienced Incident Commander with high integrity and professionalism who can join our team here in the Bay Area. You will be working on uniquely assigned projects under ...

next page

Showing results 1-20

Incident Command information

See salary details

$36.5K

$163.4K

$193.5K

How much do incident command jobs pay per year?

As of Jun 5, 2026, the average yearly pay for incident command in the United States is $163,404.00, according to ZipRecruiter salary data. Most workers in this role earn between $129,000.00 and $193,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an Incident Commander, and why are they important?

To thrive as an Incident Commander, you need strong leadership, decision-making skills, and thorough knowledge of emergency response protocols, typically supported by relevant certifications such as ICS (Incident Command System) training. Familiarity with emergency management tools, communication systems, and resource-tracking software is crucial. Exceptional communication, composure under pressure, and the ability to coordinate diverse teams are vital soft skills. These competencies ensure effective crisis management, minimize risks, and facilitate swift, organized responses to emergencies.

What are some common challenges faced by professionals in Incident Command roles, and how can they be managed effectively?

Professionals in Incident Command often encounter challenges such as rapidly changing situations, coordinating multiple teams, and maintaining clear communication under pressure. Effectively managing these issues requires strong leadership, adaptability, and a solid grasp of established incident command protocols. Regular training, clear delegation of tasks, and the use of real-time communication tools can significantly improve team coordination and response effectiveness during emergencies.

What is Incident Command?

Incident Command refers to a standardized, on-scene management system used to coordinate emergency response operations. It is designed to enable effective and efficient incident management by integrating facilities, equipment, personnel, procedures, and communications within a common organizational structure. The Incident Command System (ICS) is widely used by fire, police, emergency medical services, and other agencies during emergencies such as natural disasters, accidents, or terrorist events. ICS helps ensure a coordinated response, clear leadership, and safety for responders and the public.

What is the difference between Incident Command vs Firefighter?

AspectIncident CommandFirefighter
Required credentialsEmergency management training, certifications like ICS, NIMSFirefighter certification, EMT/paramedic licenses
Work environmentCommand centers, incident sites, coordination rolesFire scenes, rescue operations, emergency response
Employer & industry usageEmergency management agencies, fire departments, disaster response teamsFire departments, rescue services, emergency response units

Incident Command and Firefighter roles often overlap during emergencies, but Incident Command focuses on managing and coordinating the response, while Firefighters are directly involved in suppression and rescue efforts. Both roles require specialized training and are essential in emergency situations, but their responsibilities and work environments differ significantly.

More about Incident Command jobs
What cities are hiring for Incident Command jobs? Cities with the most Incident Command job openings:
What states have the most Incident Command jobs? States with the most job openings for Incident Command jobs include:
Infographic showing various Incident Command job openings in the United States as of May 2026, with employment types broken down into 1% As Needed, 86% Full Time, 12% Part Time, and 1% Contract. Highlights an 93% Physical, 1% Hybrid, and 6% Remote job distribution, with an average salary of $163,404 per year, or $78.6 per hour.
Cybersecurity Incident Commander

Cybersecurity Incident Commander

SoFi

Seattle, WA

Other

Posted 7 days ago


Job description

The Role:

We are seeking a Cybersecurity Incident Commander to join SoFi's Cyber Defense program and lead incident command efforts across the organization. This role will serve as a central driver for security incident response, ensuring effective management of day-to-day incidents as well as large-scale, high-impact cybersecurity events.

The SOC team is responsible for monitoring, analyzing, and responding to security events across SoFi's infrastructure and applications. As a dedicated incident response resource within Cyber Defense, you will coordinate cross-functional response efforts, maintain incident command structure during active events, and ensure consistent communication, documentation, and resolution tracking.

This is a highly visible role that partners closely with SOC Analysts, Threat Research, Offensive Security, Tools Automation & Operations (TAO), Engineering, IT, Legal, Risk, Executive team, and other stakeholders to drive timely containment, eradication, and recovery. The ideal candidate thrives in fast-paced environments, brings structure to ambiguity, has exceptional communication skills, and can effectively drive complex incidents from detection through post-incident review.

What You'll Do:
  •  Serve as the primary Security Incident Commander for security incidents identified by the SOC.

  • Lead and manage the end-to-end lifecycle of security incidents, including triage validation, containment, eradication, recovery, and closure.

  • Establish and maintain incident command during high-severity or large-scale incidents.

  • Drive cross-functional collaboration and decision making across technical and business teams to ensure timely and effective response.

  • Facilitate incident communication, coordinate response resources, and maintain clear situational awareness for all engaged.

  • Ensure consistent documentation of incident timelines, impact assessments, decisions, evidence chain of custody, and actions taken.

  • Develop and maintain incident severity classifications and escalation criteria that are aligned with organizational and business needs and expectations.

  • Provide executive-ready status updates and summaries during major incidents. 

  • Coordinate post-incident reviews, including root cause analysis, lessons learned, and tracking of remediation actions.

  • Identify and facilitate opportunities to improve incident response processes, playbooks, and communication workflows.

  • Partner with SOC leadership to enhance incident metrics, reporting, and operational maturity.

  • Organize and participate in tabletop exercises, simulations, and readiness activities to improve Cyber Defense and SOC response capabilities. 

What You'll Need:
  • 3-7+ years of experience in cybersecurity operations, incident response, or SOC environments.

  • Direct experience coordinating or leading security incident response efforts in enterprise environments.

  • Strong understanding of the incident response lifecycle and frameworks (e.g., NIST 800-61).

  • Experience handling high-severity incidents such as ransomware, business email compromise, insider threats, cloud compromise, or data exfiltration events.

  • Ability to interpret technical findings and translate them into clear, actionable updates for both technical and non-technical stakeholders.

  • Excellent written and verbal communication skills, especially in high-pressure situations.

  • Strong organizational skills with the ability to manage multiple concurrent incidents.

  • Experience facilitating cross-functional communication across various media channels and driving accountability during live incidents.

  • Ability to operate independently while collaborating effectively across distributed teams.

Nice to Have:
  • Experience in a formal CSIRT or Incident Commander role.

  • Working knowledge of security technologies such as SIEM, EDR, email security, IAM, cloud security controls, and network monitoring tools.

  • Knowledge of regulatory and compliance considerations (e.g., financial services, PCI, SOX, GLBA).

  • Experience directing or conducting digital forensics or deep technical investigations.

  • Familiarity with cloud-native security incident response (AWS, GCP, or Azure).

  • Exposure to MITRE ATT&CK framework and threat intelligence integration.

  • Relevant certifications such as GCIA, GCIH, GCED, CISSP, CISM, or similar.

  • Experience developing or maintaining incident response playbooks and runbooks.