1

Incident Response Lead Jobs (NOW HIRING)

Job Summary Serves as the dedicated lead responder for Transocean's Cyber Security Incident Response Team (CSIRT), responsible for leading major investigation, coordination, containment, eradication ...

$150K - $185K/yr

The Cybersecurity Incident Response Lead will oversee the incident response and threat intelligence programs to safeguard critical assets and data. The ideal candidate will combine technical ...

Incident Response Team Lead

Reston, VA · On-site

$155K - $180K/yr

Incident Response Team Lead Location: Reston, VA Clearance Level: TS (SCI Eligible) Active Certified Information System Security Professional (CISSP) SUMMARY Agile Defense is seeking experienced ...

Incident Response Team Lead Location: Reston, VA Clearance Level: TS (SCI Eligible) Active Certified Information System Security Professional (CISSP) SUMMARY Agile Defense is seeking experienced ...

Lead and conduct comprehensive host forensics, network forensics, log analysis, and malware triage to support incident response investigations. * Tool Development: Create and enhance scripts, tools ...

Lead Incident Responder

Washington, DC · On-site

$160K - $185K/yr

Lead end-to-end incident response activities, including detection, triage, containment, eradication, and recovery. Direct investigations of advanced threats, including APTs, ransomware, and insider ...

Showing results 21-40

Incident Response Lead information

See salary details

$17

$41

$66

How much do incident response lead jobs pay per hour?

As of Aug 8, 2026, the average hourly pay for incident response lead in the United States is $41.73, according to ZipRecruiter salary data. Most workers in this role earn between $29.33 and $47.60 per hour, depending on experience, location, and employer.

What are the primary challenges an Incident Response Lead faces during a major security incident?

An Incident Response Lead often encounters the challenge of quickly coordinating cross-functional teams under pressure while maintaining clear communication with stakeholders. They must rapidly analyze incomplete or evolving information to make critical decisions, all while ensuring containment and minimizing business impact. Balancing technical remediation with regulatory and reporting requirements can also be demanding. Adaptability and the ability to remain calm and organized are key to effectively managing these high-stress situations.

What does an Incident Response Lead do?

An Incident Response Lead is responsible for managing and coordinating an organization's response to cybersecurity incidents. They lead a team of specialists to detect, analyze, and mitigate threats, ensuring that security breaches are contained and investigated thoroughly. The Incident Response Lead also develops response plans, conducts training, and communicates with stakeholders to minimize the impact of incidents. Their role is critical in protecting sensitive data and maintaining business continuity.

What are the key skills and qualifications needed to thrive as an Incident Response Lead?

To thrive as an Incident Response Lead, you need a strong background in cybersecurity, experience in threat analysis, and often a degree in computer science or a related field. Expertise with security information and event management (SIEM) tools, forensic analysis software, and relevant certifications like CISSP, CISM, or GIAC are typically required. Exceptional problem-solving abilities, leadership, and clear communication are vital soft skills for coordinating teams and managing high-pressure situations. These skills ensure rapid, effective responses to security threats, minimizing business impact and maintaining organizational resilience.

What is the difference between Incident Response Lead vs Security Analyst?

AspectIncident Response LeadSecurity Analyst
CertificationsGCIH, CISSP, CISACISSP, Security+
Work EnvironmentLeads incident response teams, manages response strategiesMonitors security systems, analyzes threats
Employer & Industry UsageUsed in cybersecurity teams across various industriesCommon in security operations centers (SOCs)

The Incident Response Lead focuses on managing and leading incident response efforts, coordinating teams during security breaches. In contrast, a Security Analyst primarily monitors systems, detects threats, and analyzes security data. While both roles require cybersecurity certifications and work within similar environments, the Lead has a leadership and strategic focus, whereas the Analyst is more operational and technical.

More about Incident Response Lead jobs
What cities are hiring for Incident Response Lead jobs? Cities with the most Incident Response Lead job openings:
Who are the top companies hiring for Incident Response Lead jobs? The top employers for Incident Response Lead jobs are:
What states have the most Incident Response Lead jobs? States with the most job openings for Incident Response Lead jobs include:
What are popular job titles related to Incident Response Lead jobs? For Incident Response Lead jobs, the most frequently searched job titles are:
Infographic showing various Incident Response Lead job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 10% Part Time, and 3% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $86,808 per year, or $41.7 per hour.

IT Security Specialist (Pre-Incident Consulting & Incident Response Lead)

Mirazon

Louisville, KY

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 20 days ago


Job description

Mirazon is a scaling, people-centered IT company that believes strong security starts long before an incident occurs, and that calm, capable leadership matters most when it does. We're looking for aSecurity Specialistwho thrives at the intersection of strategy and execution: someone who enjoys strengthening security postures proactively and who can step confidently into high-pressure situations to guide clients through complex cybersecurity events.


Mission of the Position

This role is designed for an experienced individual contributor with deep technical expertise, sound judgment, and executive presence. You value preparation, documentation, and disciplined processes, and you're equally comfortable designing preventative controls as you are leading incident response efforts in real time. You bring clarity to chaos, translate technical risk into business impact, and act as a trusted advisor to clients when the stakes are highest.


Key Criteria/Requirements

  • 5+ years in cybersecurity or infrastructure security roles
  • 3+ years leading security incidents
  • Strong experience with:
    • Firewalls (FortiGate, Cisco, SonicWall, Palo Alto, etc.)
    • Endpoint detection and response (EDR/XDR)
    • Microsoft 365 security stack
    • Identity and access management
    • Backup and disaster recovery systems
  • Experience with ransomware containment and recovery
  • Deep understanding of networking and Active Directory environments
  • Strong written and verbal communication skills
  • Ability to lead under pressure


Preferred Certifications

  • CISSP
  • CISM
  • CEH
  • GIAC (GCIA, GCIH, etc.)
  • Security+
  • Microsoft Security certifications
  • Vendor firewall certifications


Key Accountabilities

1. Pre-Incident Security Consulting (Strategic & Preventative)

  • Conduct comprehensive security risk assessments and gap analyses
  • Lead cybersecurity maturity assessments aligned to NIST, CIS, or industry frameworks
  • Perform vulnerability assessments and coordinate remediation planning
  • Design and review:
    • Network security architecture
    • Firewall and segmentation strategies
    • Endpoint security strategies
    • MFA and identity security implementation
  • Develop incident response plans and business continuity playbooks
  • Conduct tabletop exercises with client executive teams
  • Provide executive-level reporting with risk prioritization and budget guidance
  • Assist sales/engineering with scoping security engagements and SOW development


2. Incident Response Leadership

  • Serve as Incident Response Lead during cybersecurity events
  • Direct containment, eradication, and recovery efforts
  • Coordinate with:
    • Internal engineering teams
    • Client leadership
    • Insurance carriers
    • Legal counsel
    • Forensics vendors
  • Perform initial triage and determine scope of compromise
  • Oversee forensic evidence preservation
  • Guide ransomware response and recovery strategy
  • Lead root-cause analysis and post-incident reporting
  • Develop corrective action plans


3. Client & Executive Communication

  • Act as trusted advisor to C-suite and ownership groups
  • Translate technical findings into business risk language
  • Present findings and remediation plans in board-level settings
  • Provide calm, decisive leadership during crisis situations
  • Maintain strict confidentiality and professionalism


4. Documentation & Process Development

  • Maintain standardized security assessment templates
  • Develop and refine internal IR procedures
  • Create security standards and best practices
  • Ensure all engagements are properly documented in PSA systems
  • Contribute to continuous improvement of security offerings


Insurance Benefits

Eligibility begins the first day of full-time employment (date of hire).

  • Life Insurance
  • Short-term Disability
  • Long-term Disability
  • Cafeteria Plan - Premium, Medical, & Child Care Reimbursement
  • Health Insurance
  • Dental Plan
  • Vision Plan

Other Benefits

  • 401K Matching
  • Referral Bonuses
  • Tuition Reimbursement
  • Performance Incentives
  • Time Off- benefitsaccrueon a pro-rated basis each pay period over a 12-month period with the following maximums:
    • Vacation Time -10 daysper calendar year
    • Sick Leave- 5 days per calendar year
  • Paid Company Holidays (7)
  • Paid Floating Holidays (2)
  • Volunteer 1
  • Cell Phone & Internet Reimbursement