1

Incident Response Manager Jobs (NOW HIRING)

Status Exempt General Summary The Senior Incident Response (IR) Manager provides strategic and operational leadership for detecting, responding to, and eradicating cyber threats targeting Kia America ...

They are seeking a Manager, Incident Response to lead and manage cyber incident response activities, oversee incident investigations, and collaborate across various teams to enhance incident response ...

Showing results 21-40

Incident Response Manager information

See salary details

$41K

$127.2K

$199.5K

How much do incident response manager jobs pay per year?

As of Sep 2, 2026, the average yearly pay for incident response manager in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What is an incident response manager?

An incident response manager supervises a team of IT professionals who respond to cyber attacks, network intrusions, and computer crimes. Your responsibilities are to direct security personnel as they investigate security breaches and implement counter-measures. Prior to any breach or incident, your duties require you to analyze the activity on your organization’s servers and networks, locating vulnerabilities and implementing safeguards and procedural changes to prevent possible attack.

What does an incident response manager do?

An Incident Response Manager is responsible for leading an organization's efforts to detect, respond to, and recover from cybersecurity incidents such as data breaches, malware infections, or unauthorized access. They coordinate response teams, develop incident response plans, and ensure that incidents are properly documented and analyzed to prevent future occurrences. Their role also involves communicating with stakeholders, providing training, and keeping up to date with the latest cyber threats and best practices.

What are the key skills and qualifications needed to thrive as an incident response manager, and why are they important?

To thrive as an Incident Response Manager, you need expertise in cybersecurity principles, risk assessment, incident handling, and often a degree in information security or a related field. Familiarity with security information and event management (SIEM) tools, forensic analysis platforms, and certifications like CISSP, CISM, or GIAC are typically required. Strong leadership, decision-making, and communication skills are crucial for coordinating teams and managing high-pressure situations. These competencies are vital to effectively detect, contain, and mitigate security incidents while minimizing organizational impact.

What are some common challenges faced by incident response managers, and how can they effectively address them?

Incident Response Managers often encounter challenges such as rapidly evolving security threats, coordinating cross-functional teams under pressure, and ensuring clear communication during high-stress incidents. To effectively address these challenges, they focus on regular training and simulations, establish comprehensive incident response plans, and foster strong relationships with IT, legal, and executive teams. Emphasizing documentation and post-incident reviews also helps in continuously improving processes and adapting to new threats.

What is the difference between Incident Response Manager vs Security Analyst?

AspectIncident Response ManagerSecurity Analyst
CertificationsGCIH, CISSP, CISMCISSP, Security+
Work EnvironmentLeads incident response teams, manages response plansMonitors security systems, analyzes threats
Employer & Industry UsageUsed in cybersecurity teams across various industriesCommonly employed in security operations centers (SOCs)

The Incident Response Manager focuses on leading and coordinating incident response efforts, managing teams, and developing response strategies. In contrast, the Security Analyst primarily monitors security alerts, analyzes threats, and supports incident detection. Both roles require cybersecurity certifications and are integral to organizational security, but they differ in scope and responsibilities.

What cities are hiring for Incident Response Manager jobs?

Cities with the most Incident Response Manager job openings:

What are the most commonly searched types of Incident Response jobs?

The most popular types of Incident Response jobs are:

Who are the top companies hiring for Incident Response Manager jobs?

The top employers for Incident Response Manager jobs are:

What states have the most Incident Response Manager jobs?

States with the most job openings for Incident Response Manager jobs include:

Infographic showing various Incident Response Manager job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 12% Part Time, and 1% Contract. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.

IT SECURITY INCIDENT RESPONSE MANAGER

West Advanced Technologies (WATI)

Downey, CA • On-site

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

IT SECURITY INCIDENT RESPONSE MANAGER
Downey, CA
5+ months

Responsibilities:
1. Document incident response process and procedures.
2. Provide first responder forensics analysis and investigation
a. Triage and resolve advanced vector attacks such as botnets and advanced persistent threats (APTs)
b. Own business impacting situations, and work to restore normal service operations in cooperation with cross-functional partners.
c. Ensure timely communications and updates are provided for incident management and root-cause scenarios.
d. Work directly with data asset owners and business response plan owners during high severity events of interest.
e. Leads the effort on messaging and communication related to incident reporting for all audience.
f. Drives containment strategy during data loss or breach events.
g. Maintains chain of custody of incident evidence.
3. Drives post-containment recovery effort through to complete incident closure
a. Provides recommendations to resolve and/or reduce impact of incident and to prevent future similar incidents.
b. Develop and enrich restoration procedures to mitigate future outages and business disruptions.
c. Provide control change recommendations to administrators based on findings during investigations or threat information reviews
d. Identify and recommend opportunities for "clean-slate" process improvement with regards to incident management, fault monitoring, triage procedures and issue escalation.
4. Provides written final incident report to executive management
a. Assessing scope of incident damage and assisting in the determination of incident severity.
b. Document activities such as investigation, discovery and recovery during the incident.
5. Collaborate with departmental IT team and ISD ITS teams such as architecture, development, and engineering teams to identify the root cause of recurring incidents and create action-plans for resolution
a. Leverage and lead the root-cause/problem management process to correlate trends business impacts.
6. Maintain on-call availability for 24x7x365 coverage.
Required SKills:
1. One or more of the following professional certifications requited: Qualified Security Assessor (QSA), Certified Information Systems Auditor (CISA), Certified Information Systems Security Professionals (CISSP), Certified Information Security Manager (CISM), Certified Information Privacy Professional (CIPP), GIAC Certified Incident Handler,,(GCIH) or GIAC Network Forensic Analyst.
2. Bachelor's degree from an accredited college in Technology related discipline (e.g. Computer Science, Engineering, Information Systems, etc.) or equivalent experience/combined education.
3. Minimum of three (3) years' experience in the last five (5) years as an IT Security Incident Response Manager, supporting a complex enterprise security environment for a large public or private organization.
4. Minimum of three (3) years of experience in the past five (5) years as an IT Security Incident Response Manager, supporting Enterprise Multi-Tenant environment, include responding, containing, remediating, and reporting on the infrastructure connecting to County Departments and Public Cloud Providers, such as AWS, Azure and/or GCP.
5. Minimum of two (2) years' experience in the last three (3) years analyzing, responding, and remediating enterprise network & security architectures.
6. Minimum of two (2) years' experience in the last three (3) years leading IT Security/Information Security teams.
7. Minimum of two (2) years' experience in the last three (3) years delivering Incident Reports and Remediation Recommendations in a large enterprise organization.
8. Demonstrated ability to create clear, concise technical documentations such as procedures, Visio diagrams, and system support documents, and strong presentation skills with experience using Microsoft PowerPoint.
Regards
Naresh Damagalla
West Advanced Technologies, Inc
E: naresh.d@wati.com