1

Incident Response Manager Jobs in Decatur, GA (NOW HIRING)

They are seeking a Manager, Incident Response to lead and manage cyber incident response activities, oversee incident investigations, and collaborate across various teams to enhance incident response ...

Manager, Incident Response

Atlanta, GA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Lead and manage cyber incident response activities, including triage, containment, eradication, and recovery efforts for client incidents * Oversee and coordinate incident investigations across cyber ...

Cybersecurity Incident Response Specialist

Atlanta, GA · On-site

  • Medical

  • Dental

  • Retirement

... manage their fleets. Geotab's open platform and Geotab Marketplace ® , offering hundreds of third ... Geotab is seeking a Cybersecurity Incident Response Specialist who will be responsible for ...

Security Incident Response Engineer

Atlanta, GA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Security Incident Response Engineer is responsible for detecting, investigating, containing ... Support major incident management activities and provide technical leadership during active ...

Security Incident Response Engineer

Atlanta, GA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Security Incident Response Engineer is responsible for detecting, investigating, containing ... Support major incident management activities and provide technical leadership during active ...

Security Incident Response Engineer

Atlanta, GA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Security Incident Response Engineer is responsible for detecting, investigating, containing ... Support major incident management activities and provide technical leadership during active ...

Incident Response Analyst

Atlanta, GA · On-site

$104K - $138K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Success looks like faster incident response, less noise, and a SOC that gets sharper every sprint ... Familiarity with cloud, container, Kubernetes, CI/CD runner, artifact registry, package management ...

Security Incident Response Engineer

Atlanta, GA · On-site

$110 - $160/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

## Security Incident Response EngineerApplylocations: 1170 Peachtree St Ste 1200 - ATLANTA, GA: 100 ... Support major incident management activities and provide technical leadership during active ...

Security Incident Response Engineer

Atlanta, GA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Security Incident Response Engineer is responsible for detecting, investigating, containing ... Support major incident management activities and provide technical leadership during active ...

Security Incident Response Engineer

Atlanta, GA

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Security Incident Response Engineer is responsible for detecting, investigating, containing ... Support major incident management activities and provide technical leadership during active ...

This role leads enterprise incident governance, including Major Incident (MI) response, escalation management, root cause analysis, and incident trend remediation across all IT service domains. This ...

next page

Showing results 1-20

Incident Response Manager information

See Decatur, GA salary details

$40K

$124.2K

$194.8K

How much do incident response manager jobs pay per year?

As of Aug 18, 2026, the average yearly pay for incident response manager in Decatur, GA is $124,167.00, according to ZipRecruiter salary data. Most workers in this role earn between $86,900.00 and $167,900.00 per year, depending on experience, location, and employer.

What is an incident response manager?

An incident response manager supervises a team of IT professionals who respond to cyber attacks, network intrusions, and computer crimes. Your responsibilities are to direct security personnel as they investigate security breaches and implement counter-measures. Prior to any breach or incident, your duties require you to analyze the activity on your organization’s servers and networks, locating vulnerabilities and implementing safeguards and procedural changes to prevent possible attack.

What does an incident response manager do?

An Incident Response Manager is responsible for leading an organization's efforts to detect, respond to, and recover from cybersecurity incidents such as data breaches, malware infections, or unauthorized access. They coordinate response teams, develop incident response plans, and ensure that incidents are properly documented and analyzed to prevent future occurrences. Their role also involves communicating with stakeholders, providing training, and keeping up to date with the latest cyber threats and best practices.

What are the key skills and qualifications needed to thrive as an incident response manager, and why are they important?

To thrive as an Incident Response Manager, you need expertise in cybersecurity principles, risk assessment, incident handling, and often a degree in information security or a related field. Familiarity with security information and event management (SIEM) tools, forensic analysis platforms, and certifications like CISSP, CISM, or GIAC are typically required. Strong leadership, decision-making, and communication skills are crucial for coordinating teams and managing high-pressure situations. These competencies are vital to effectively detect, contain, and mitigate security incidents while minimizing organizational impact.

What are some common challenges faced by incident response managers, and how can they effectively address them?

Incident Response Managers often encounter challenges such as rapidly evolving security threats, coordinating cross-functional teams under pressure, and ensuring clear communication during high-stress incidents. To effectively address these challenges, they focus on regular training and simulations, establish comprehensive incident response plans, and foster strong relationships with IT, legal, and executive teams. Emphasizing documentation and post-incident reviews also helps in continuously improving processes and adapting to new threats.

What is the difference between Incident Response Manager vs Security Analyst?

AspectIncident Response ManagerSecurity Analyst
CertificationsGCIH, CISSP, CISMCISSP, Security+
Work EnvironmentLeads incident response teams, manages response plansMonitors security systems, analyzes threats
Employer & Industry UsageUsed in cybersecurity teams across various industriesCommonly employed in security operations centers (SOCs)

The Incident Response Manager focuses on leading and coordinating incident response efforts, managing teams, and developing response strategies. In contrast, the Security Analyst primarily monitors security alerts, analyzes threats, and supports incident detection. Both roles require cybersecurity certifications and are integral to organizational security, but they differ in scope and responsibilities.

What are the most commonly searched types of Incident Response jobs in Decatur, GA?

The most popular types of Incident Response jobs in Decatur, GA are:

What job categories do people searching Incident Response Manager jobs in Decatur, GA look for?

The top searched job categories for Incident Response Manager jobs in Decatur, GA are:

What cities near Decatur, GA are hiring for Incident Response Manager jobs?

Cities near Decatur, GA with the most Incident Response Manager job openings:

Infographic showing various Incident Response Manager job openings in Decatur, GA as of August 2026, with employment types broken down into 86% Full Time, 11% Part Time, 2% Temporary, and 1% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $124,167 per year, or $59.7 per hour.

Incident Response Manager

Fortuna Cysec Inc

Atlanta, GA • On-site

Full-time

Re-posted 17 days ago


Job description

Description:

Company Overview


Fortuna Cysec delivers unified cybersecurity operations through TheFense platform—our integrated MDR, SIEM, EDR, and response ecosystem designed for regulated industries, nonprofits, healthcare, education, and mission-driven organizations. Our global SOC/NOC operates 24×7×365, providing real-time visibility, rapid containment, and deep technical expertise across diverse customer environments.

We are expanding our Incident Response leadership team with a hands-on technical manager who thrives in fast-moving investigations and can guide customers through their most critical security events.


Role Summary

The Cybersecurity Incident Response Manager leads and directly participates in high-severity investigations across Fortuna Cysec’s customer base. This role blends technical depth, operational leadership, and customer-facing communication. You will serve as the senior escalation point for complex incidents, drive containment and remediation, and strengthen TheFense platform’s detection and response capabilities.


Requirements:

Lead and Execute Incident Response

· Command all phases of incident response—triage, investigation, containment, eradication, and recovery—while performing hands-on technical analysis.

· Analyze EDR telemetry, SIEM alerts, network logs, cloud audit logs, and identity events across Microsoft, AWS, and hybrid environments.

· Execute containment actions including endpoint isolation, identity disablement, MFA resets, OAuth token revocation, and firewall/network segmentation changes.

· Conduct forensic acquisition and analysis using Velociraptor, KAPE, FTK, EnCase, and Volatility.

· Reverse-engineer or sandbox suspicious binaries/scripts to determine behavior and impact.

· Lead hypothesis-driven threat hunts mapped to MITRE ATT&CK using TheFense’s unified telemetry.

Strengthen IR Operations

· Oversee daily IR operations across global SOC/NOC teams, ensuring SLA adherence and seamless follow-the-sun handoffs.

· Review and enhance IR playbooks, runbooks, and automated response actions within TheFense.

· Ensure high-quality incident documentation, evidence handling, and customer-ready reporting.

· Conduct root-cause analysis and deliver technically detailed post-incident reviews.

· Partner with engineering to refine detection logic, reduce false positives, and improve automation.

Engage Directly with Customers

· Serve as the technical authority during active breaches, guiding CISOs, IT directors, and executive stakeholders.

· Deliver clear, concise briefings that include attack path analysis, forensic findings, and prioritized remediation steps.

· Support customer teams with hands-on remediation across identity, cloud, endpoint, and email ecosystems.

· Provide strategic recommendations aligned with NIST, CIS Controls, and Fortuna Cysec best practices.

Advance Threat Intelligence and Detection

· Translate emerging threat intelligence into new detection rules, response playbooks, and threat-hunting queries.

· Validate detection logic through lab testing, simulated attacks, and historical telemetry review.

· Identify detection gaps and collaborate with TI teams to enrich investigations with IOCs and adversary behavior patterns.

Build Team and Platform Maturity

· Mentor analysts across global SOC/NOC teams in IR, forensics, cloud investigations, and threat hunting.

· Develop internal tooling and automation using Python or PowerShell.

· Participate in tabletop exercises, purple-team engagements, and breach simulations.

· Contribute to the evolution of TheFense platform by evaluating new telemetry sources and response capabilities.

Required Qualifications

  • 5–10+ years of hands-on experience in incident response, threat hunting, SOC operations, or digital forensics.
  • Deep technical expertise with EDR platforms (Microsoft Defender, SentinelOne, CrowdStrike, Carbon Black).
  • Strong SIEM experience with log parsing, correlation, and custom detection creation (Wazuh, Microsoft Sentinel, Elastic, Splunk).
  • Strong Windows Servers, Office 365 & Azure EntraID / Intune Experience
  • Hands-on experience with cloud IR in Azure, AWS, and hybrid environments.
  • Proficiency with forensic tools (Velociraptor, KAPE, FTK, EnCase) and memory analysis frameworks (Volatility).
  • Strong understanding of identity security (Entra ID, Okta), email security (M365, Proofpoint), and SaaS compromise patterns.
  • Familiarity with MITRE ATT&CK, NIST 800-61, CIS Controls, ISO 27035.
  • Ability to communicate complex technical findings to both technical and executive audiences.
  • Relevant certifications: GCIA, GCFA, GCIH, GNFA, CISSP, or equivalent experience.

Preferred Qualifications

  • Experience in an MDR, MSSP, or IR consulting environment.
  • Scripting/automation skills in Python or PowerShell.
  • Experience with malware analysis, cloud forensics, or identity compromise investigations.
  • Experience supporting regulated industries (HIPAA, FERPA, PCI-DSS, SOX, CJIS) and mission-driven organizations.


Fortuna Cysec is an equal opportunity employer. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, pregnancy, age, sexual orientation, transgender status, gender identity, disability, alienage or citizenship status, marital status or partnership status, genetic information, veteran status or any other characteristic protected under applicable law.