1

Incident Response Manager Jobs (NOW HIRING)

Minimum ten years of recent experience in incident response, threat management, digital forensics, security operations, or related cybersecurity disciplines; seven years leading incident response ...

Incident Response SME

Arlington, VA · On-site

$112K - $257K/yr

Knowledge ofcrisis management principles, tactical and strategic preparedness frameworks, and incident response planning methodologies * Ability tocoordinate and execute high-impact readiness ...

Lead and manage a Security Incident Response Team focused on responding to security threats and maintaining HUB's critical threat detection and response suite of security applications. * Available 24 ...

About the Role This role leads proactive, intelligence-driven hunting to uncover advanced threats while managing critical Incident Response (IR) activities. The Lead will develop hypotheses based on ...

Showing results 41-60

Incident Response Manager information

See salary details

$41K

$127.2K

$199.5K

How much do incident response manager jobs pay per year?

As of Aug 23, 2026, the average yearly pay for incident response manager in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What is an incident response manager?

An incident response manager supervises a team of IT professionals who respond to cyber attacks, network intrusions, and computer crimes. Your responsibilities are to direct security personnel as they investigate security breaches and implement counter-measures. Prior to any breach or incident, your duties require you to analyze the activity on your organization’s servers and networks, locating vulnerabilities and implementing safeguards and procedural changes to prevent possible attack.

What does an incident response manager do?

An Incident Response Manager is responsible for leading an organization's efforts to detect, respond to, and recover from cybersecurity incidents such as data breaches, malware infections, or unauthorized access. They coordinate response teams, develop incident response plans, and ensure that incidents are properly documented and analyzed to prevent future occurrences. Their role also involves communicating with stakeholders, providing training, and keeping up to date with the latest cyber threats and best practices.

What are the key skills and qualifications needed to thrive as an incident response manager, and why are they important?

To thrive as an Incident Response Manager, you need expertise in cybersecurity principles, risk assessment, incident handling, and often a degree in information security or a related field. Familiarity with security information and event management (SIEM) tools, forensic analysis platforms, and certifications like CISSP, CISM, or GIAC are typically required. Strong leadership, decision-making, and communication skills are crucial for coordinating teams and managing high-pressure situations. These competencies are vital to effectively detect, contain, and mitigate security incidents while minimizing organizational impact.

What are some common challenges faced by incident response managers, and how can they effectively address them?

Incident Response Managers often encounter challenges such as rapidly evolving security threats, coordinating cross-functional teams under pressure, and ensuring clear communication during high-stress incidents. To effectively address these challenges, they focus on regular training and simulations, establish comprehensive incident response plans, and foster strong relationships with IT, legal, and executive teams. Emphasizing documentation and post-incident reviews also helps in continuously improving processes and adapting to new threats.

What is the difference between Incident Response Manager vs Security Analyst?

AspectIncident Response ManagerSecurity Analyst
CertificationsGCIH, CISSP, CISMCISSP, Security+
Work EnvironmentLeads incident response teams, manages response plansMonitors security systems, analyzes threats
Employer & Industry UsageUsed in cybersecurity teams across various industriesCommonly employed in security operations centers (SOCs)

The Incident Response Manager focuses on leading and coordinating incident response efforts, managing teams, and developing response strategies. In contrast, the Security Analyst primarily monitors security alerts, analyzes threats, and supports incident detection. Both roles require cybersecurity certifications and are integral to organizational security, but they differ in scope and responsibilities.

What cities are hiring for Incident Response Manager jobs?

Cities with the most Incident Response Manager job openings:

What are the most commonly searched types of Incident Response jobs?

The most popular types of Incident Response jobs are:

Who are the top companies hiring for Incident Response Manager jobs?

The top employers for Incident Response Manager jobs are:

What states have the most Incident Response Manager jobs?

States with the most job openings for Incident Response Manager jobs include:

Infographic showing various Incident Response Manager job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 11% Part Time, and 1% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.

Senior Incident Response Analyst

Niche Talent Finders

Chicago, IL • Hybrid

Full-time

Re-posted 29 days ago


Job description

Company Description

Downtown Chicago with ability to work a blend of in the office and remote

Sign-on for Relocation 15k

Excellent comp, bonus, training oppty, certs and career growth with stable, profitable multi-billion company in great industry. 140-150k base plus 10.5% bonus

NO VISA SPONSORSHIP

Downtown Chicago with ability to work a blend of in the office and remote

Sign-on for Relocation 15k

Excellent comp, bonus, training oppty, certs and career growth with stable, profitable multi-billion company in great industry. 130-145k base plus 10.5% bonus depending level of experience.  Open to 3-5 year canidate 

NO VISA SPONSORSHIP

Job Description

        Continue to develop companies incident response program

        Utilizes and adheres to defined workflow and processes driving Incident Response and mitigation efforts

        Provide root cause analysis, create metrics, management, dashboards, administration of monitoring tools, and communication process

        Collects supporting information and/or relevant artifacts in support of Incident Response activities

        Identify and execute on projects that improve our intrusion detection and incident response capabilities

        Conducts technical analysis on impacted systems to determine impact, scope, and recovery from active and potential cyber incidents

        Leverages Forensics tools, techniques, and capacities to support Cyber Incident Response activities

        Documents results of cyber threat analysis and subsequent remediation and recovery in an effective and consistent manner

        Executes the Incident Response lifecycle and coordinating remediation activities throughout the organization and its lines of business as a part of Cyber Incident Handling

        Applies thought leadership to enhance and advance the defensive capabilities of the Threat Management Center and its subsequent ability to defend Company

        Recommends solutions to optimize both technical and process/procedure aspects of the end to end incident lifecycle

        Provides Training and Mentoring of Junior team members

 

What qualifications make you a fit for this role:

        Previous experience with dynamic and/or malware analysis

        Experience executing various Incident Response Frameworks and Handling Procedures

        Program and Scripting Experience

        Strong understanding of Operating Systems: Windows, Unix/Linux, and OSX Operating Systems

        Strong communication and presentation skills along with the ability to work in a highly collaborative environment

        Exhibits initiative, follow-up and follow through with commitments

        Strong relationship skills and collaborative style to enable success across multiple partners.

        Manages multiple priorities in a high-pressure environment

        Demonstrates effective organizational and technical skills

        Experience with Enterprise Anti-Virus, IDS, Full Packet Capture and Host/Network Forensics Tools

        Understanding of Networking (including the OSI Model, TCP/IP, DNS, HTTP, SMTP), System Administration, and Security Architecture

        Excellent verbal and written communication skills

        Related Certification (A+, Network+, Security+, CISSP, GCIH, GCFA, GCFE, GNFA, GREM ) a plus

        Ability to comply with any regulatory requirements

Qualifications

What qualifications make you a fit for this role:

        Previous experience with dynamic and/or malware analysis

        Experience executing various Incident Response Frameworks and Handling Procedures

        Program and Scripting Experience

        Strong understanding of Operating Systems: Windows, Unix/Linux, and OSX Operating Systems

        Strong communication and presentation skills along with the ability to work in a highly collaborative environment

        Exhibits initiative, follow-up and follow through with commitments

        Strong relationship skills and collaborative style to enable success across multiple partners.

        Manages multiple priorities in a high-pressure environment

        Demonstrates effective organizational and technical skills

        Experience with Enterprise Anti-Virus, IDS, Full Packet Capture and Host/Network Forensics Tools

        Understanding of Networking (including the OSI Model, TCP/IP, DNS, HTTP, SMTP), System Administration, and Security Architecture

        Excellent verbal and written communication skills

        Related Certification (A+, Network+, Security+, CISSP, GCIH, GCFA, GCFE, GNFA, GREM ) a plus

        Ability to comply with any regulatory requirements

Additional Information

Will not sponsor visas.  Prefer someone local to NYC, Philadelphia, New Jersey or CT.  Willing to relocate professionals who have experience as a Digital Forensics and Incident Response Manager.   Excellent compensation and bonus opportunity.