1

Incident Commander Jobs in Minnesota (NOW HIRING)

Serve as the Incident Commander and Prescribed Fire Burn Boss on assigned prescribed fire operations. * Direct and coordinate assigned personnel and resources throughout prescribed fire operations.

Fire Chief - Owatonna

Owatonna, MN · On-site

$123K - $159K/yr

The Director serves as the City's Emergency Manager and Incident Commander, oversees fire code enforcement and inspection programs, provides guidance to the Building Inspections and Community ...

Engine Boss (ENGB)

Otsego, MN · On-site

$33 - $40/hr

Coordinate with Incident Command personnel, agency partners, and other responding resources * Inspect and maintain assigned engines, pumps, hoses, radios, tools, and other equipment to ensure ...

next page

Showing results 1-20

Incident Commander information

See Minnesota salary details

$30.4K

$52.4K

$59.7K

How much do incident commander jobs pay per year?

As of Sep 8, 2026, the average yearly pay for incident commander in Minnesota is $52,355.00, according to ZipRecruiter salary data. Most workers in this role earn between $57,800.00 and $58,300.00 per year, depending on experience, location, and employer.

What does an incident commander do?

Incident commander (IC) jobs are positions of responsibility and authority to carry out emergency response plans. Incident commanders play a vital role in emergency response for natural disasters, acts of violence, and other emergencies, such as fires and bomb threats. More recently, the information technology (IT) sector adopted the IC role to manage disaster recovery and business continuity in the event of a computer systems failure or data breach. Whether in IT or other emergency response situations, as IC your duties include allocating resources, minimizing fallout, and supervising operations.

What are the key skills and qualifications needed to thrive as an incident commander, and why are they important?

An Incident Commander is the individual responsible for managing and directing response efforts during an emergency or critical incident, such as a natural disaster, cybersecurity breach, or other crisis. They oversee the incident response team, make key decisions, and coordinate communications between agencies or departments to ensure a swift and effective resolution. The Incident Commander is typically designated at the start of an incident and remains in charge until the situation is resolved or command is transferred. Their leadership is crucial for maintaining order, safety, and clear lines of authority during high-stress situations.

How does an incident commander typically interact with other teams during a major incident?

During a major incident, the Incident Commander serves as the central point of communication, coordinating efforts between technical teams, management, and stakeholders. They facilitate regular updates, assign clear responsibilities, and ensure that everyone is aligned on priorities and next steps. This role often requires quick decision-making, clear documentation, and the ability to manage high-pressure situations while fostering collaboration across departments to resolve issues efficiently.

What is the difference between Incident Commander vs Emergency Response Coordinator?

AspectIncident CommanderEmergency Response Coordinator
CertificationsICS certifications, First Aid/CPREmergency management certifications, First Aid/CPR
Work EnvironmentEmergency scenes, incident sitesEmergency planning offices, coordination centers
Employer & IndustryPublic safety, fire departments, disaster responseGovernment agencies, NGOs, corporate safety teams
Primary RoleLead incident response, make tactical decisionsCoordinate response efforts, plan emergency procedures

While both roles focus on emergency situations, the Incident Commander is responsible for leading on-site incident response and making tactical decisions. The Emergency Response Coordinator typically oversees planning and coordination efforts, ensuring effective response strategies are in place. Both roles require similar certifications and are vital in emergency management, but their day-to-day responsibilities and work environments differ.

What are popular job titles related to Incident Commander jobs in Minnesota?

For Incident Commander jobs in Minnesota, the most frequently searched job titles are:

What job categories do people searching Incident Commander jobs in Minnesota look for?

The top searched job categories for Incident Commander jobs in Minnesota are:

What are popular job titles related to Incident Commander jobs in MN?

For Incident Commander jobs in MN, the most frequently searched job titles are:

Infographic showing various Incident Commander job openings in Minnesota as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $52,355 per year, or $25.2 per hour.

Principal Engineer - Cybersecurity Incident Response

Target

Minneapolis, MN • On-site

$168K - $303K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 13 days ago


Key responsibilities

  • Set and communicate the technical vision, architecture, and roadmap for incident response engineering.

  • Architect and lead the development of secure, reliable services, integrations, and automations to support incident response activities.

  • Provide hands-on incident commander support during complex or high-severity cyber investigations.


Target rating

6.6

Company rating: 6.6 out of 10

Based on 7,054 frontline employees who took The Breakroom Quiz

14th of 39 rated national retailers


Job description

The pay range is $168,000.00 - $303,000.00

Pay is based on several factors which vary based on position.These include labor markets and in some instancesmay include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves.Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation.Find competitive benefits from financial and education to well-being and beyond at https://corporate.target.com/careers/benefits.

Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here.

As a Principal Engineer supporting Cybersecurity Incident Response, you set the technical strategy for the engineering platforms, services, integrations, and automations that enable Target to investigate and respond to cyber threats. You set direction for how these capabilities are designed, developed, tested, deployed, and operationalized across multiple portfolios and drive adoption across TTS. You lead and approve engineering efforts to meet functional and non-functional requirements, including security, reliability, scalability, availability, performance, and maintainability.

This role combines principal-level engineering leadership with deep incident response expertise. You are expected to contribute directly during active investigations with the judgment and hands-on capability of a principal incident response analyst, while translating investigative needs and lessons learned into durable technology and process improvements. You are a thought leader and mentor for engineers and incident responders and actively contribute to the broader cybersecurity and technical community.

Use your skills, experience and talents to be a part of groundbreaking thinking and visionary goals. As a Principal Engineer, Cybersecurity Incident Response, you will take the lead as you...

  • Set and communicate the technical vision, architecture, and roadmap for incident response engineering, aligning security operations needs with Target's business and technical environments.
  • Architect and lead the development of secure, reliable services, integrations, and automations using Python, APIs, event-driven patterns, and cloud-native technologies to accelerate triage, enrichment, evidence collection, analysis, containment, and recovery.
  • Establish and drive engineering standards for source control, peer review, automated testing, CI/CD, release management, observability, documentation, secrets management, access controls, and resilient operations.
  • Lead the design, development, and lifecycle management of security operations (SecOps) and security orchestration, automation, and response (SOAR) capabilities, including production-grade playbooks, integrations, case-management workflows, data enrichment, and analyst-facing tools.
  • Provide hands-on, principal analyst-level incident commander support by leading complex or high-severity cyber investigations. Guide triage, hypothesis development, data collection, scoping, evidence analysis, timeline reconstruction, containment decisions, eradication, recovery, and clear documentation of findings and risk.
  • Partner with incident responders, threat hunters, detection engineers, digital forensics, threat intelligence, Enterprise Architecture, and technology teams to convert investigative requirements and post-incident findings into scalable capabilities.
  • Assess the viability, applicability, security, maintainability, and cost implications of technical solutions through proofs of concept, prototypes, architecture reviews, vendor evaluations, and build-versus-buy decisions.
  • Define metrics and feedback loops that measure automation quality, platform reliability, investigative cycle time, analyst experience, and operational outcomes; use the results to drive continuous improvement.
  • Work with engineering and cybersecurity leaders to build a high-performing team, provide technical leadership and coaching, mentor engineers and analysts, and participate in the selection and development of technical talent.
  • Architect, engineer, and operationalize scalable live-response and forensic artifact collection solutions that enable secure, reliable acquisition of volatile and persistent evidence across endpoint, cloud, identity, network, and container environments, with built-in automation, evidence-integrity controls, observability, and integrations with investigative and SOAR workflows.
  • Design, develop, and operationalize agentic AI-powered analysis tooling that integrates with SecOps, SIEM, SOAR, and case-management platforms to correlate telemetry and forensic evidence, automate repetitive investigative tasks, generate defensible findings, and recommend next investigative actions with appropriate human oversight and security controls.

Core responsibilities of this job are described within this job description. Job duties may change at any time due to business needs.

About you:

  • 4-year degree or equivalent experience. Continuing education to maintain thorough knowledge of technical and cybersecurity domains while staying current with relevant technologies and threats.
  • 10+ years of experience in technology development, cybersecurity engineering, security operations, or related services.
  • 10+ years of hands-on cybersecurity incident response experience, including demonstrated ability to independently lead and support active enterprise investigations.
  • Advanced Python programming and software engineering skills, including APIs, data structures, testing, code review, source control, packaging, error handling, and maintainable documentation.
  • Demonstrated experience designing and operating automation through modern CI/CD and DevSecOps practices, including automated testing, secure deployment, monitoring, rollback, and change governance.
  • Strong hands-on experience with SOAR platforms (SecOps preferred) and the development of production-grade playbooks, integrations, and workflows. Familiarity with adjacent technologies such as SIEM, EDR, case management, threat intelligence, identity, cloud security, and malware triage.
  • Deep knowledge of the incident response lifecycle and the ability to analyze endpoint, network, identity, cloud, and file based evidence; scope impact; build defensible timelines; and advise on containment, eradication, and recovery.
  • Strong understanding of secure systems design and operations, including authentication and authorization, secrets management, logging and telemetry, data handling, evidence integrity, resilience, and failure recovery.
  • Demonstrated success solving complex technical problems across more than one technical or functional area. Experience with REST APIs, SQL/NoSQL data stores, Git, PowerShell or Bash, containers/Kubernetes, and cloud technologies.
  • Understands business fundamentals and how technology can support business goals, translate business and cyber risk into technical strategy, and evaluate financial and operational implications.
  • Proven leadership capabilities, influence, interpersonal skills, sound judgment, and calm decision-making in time-sensitive situations. Excellent verbal, written, and presentation skills to communicate complex technical and investigative findings clearly to technical teams, cybersecurity leaders, and business stakeholders.
  • Strong team player with excellent planning and organizational skills and a demonstrated commitment to teamwork and team effectiveness.

This position will operate as a Hybrid/Flex for Your Day work arrangement based on Target's needs. A Hybrid/Flex for Your Day work arrangement means the team member's core role will need to be performed both onsite at the Target HQ MN location the role is assigned to and virtually, depending upon what your role, team and tasks require for that day. Work duties cannot be performed outside of the country of the primary work location, unless otherwise prescribed by Target. Click here if you are curious to learn more about Minnesota.

Benefits Eligibility

Please paste this url into your preferred browser to learn about benefits eligibility for this role: https://tgt.biz/BenefitsForYou_F

Americans with Disabilities Act (ADA)

In compliance with state and federal laws, Target will make reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please reach out to candidate.accommodations@HRHelp.Target.com. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed through this channel.


What Target employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Target logo

About Target

Sourced by ZipRecruiter

We're here to help all families discover the joy of everyday life. Target is a general merchandise retailer with stores in all 50 U.S. states and the District of Columbia. 75% of the U.S. population lives within 10 miles of a Target store. We employ 400,000+ Our tagline is "Expect More. Pay Less." We've been using it since 1994! The Target Corporation also owns Shipt and Roundel. More to love! Target is headquartered in Minneapolis, Minnesota, its hometown since the first Target store opened in 1962 under The Dayton Company.

Industry

Retail and scientific research and development services

Company size

10,000+ Employees

Headquarters location

Minneapolis, MN, US