1

Incident Response Manager Jobs (NOW HIRING)

We are seeking a battle-tested, highly self-driven Manager, Incident Response to lead, inspire, and continuously mature our Incident Response Team. In this role, you will not just help to manage ...

Manager, Incident Response

Mclean, VA · Remote

$150K - $175K/yr

About the Role As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver ...

We are seeking a battle-tested, highly self-driven Manager, Incident Response to lead, inspire, and continuously mature our Incident Response Team. In this role, you will not just help to manage ...

Manager, Incident Response

Mclean, VA · On-site +1

$150K - $175K/yr

About the Role As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver ...

The Major Incident Manager will have global accountability for providing governance and oversight of the Major Incident functions within Enterprise Technology. This role will own the global Major ...

Lead and manage a Security Incident Response Team focused on responding to security threats and maintaining HUB's critical threat detection and response suite of security applications. * Available 24 ...

Incident Response SME

Arlington, VA · On-site

$112K - $257K/yr

Knowledge ofcrisis management principles, tactical and strategic preparedness frameworks, and incident response planning methodologies * Ability tocoordinate and execute high-impact readiness ...

Showing results 41-60

Incident Response Manager information

See salary details

$41K

$127.2K

$199.5K

How much do incident response manager jobs pay per year?

As of Aug 12, 2026, the average yearly pay for incident response manager in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an incident response manager, and why are they important?

To thrive as an Incident Response Manager, you need expertise in cybersecurity principles, risk assessment, incident handling, and often a degree in information security or a related field. Familiarity with security information and event management (SIEM) tools, forensic analysis platforms, and certifications like CISSP, CISM, or GIAC are typically required. Strong leadership, decision-making, and communication skills are crucial for coordinating teams and managing high-pressure situations. These competencies are vital to effectively detect, contain, and mitigate security incidents while minimizing organizational impact.

What is an incident response manager?

An incident response manager supervises a team of IT professionals who respond to cyber attacks, network intrusions, and computer crimes. Your responsibilities are to direct security personnel as they investigate security breaches and implement counter-measures. Prior to any breach or incident, your duties require you to analyze the activity on your organization’s servers and networks, locating vulnerabilities and implementing safeguards and procedural changes to prevent possible attack.

What are some common challenges faced by incident response managers, and how can they effectively address them?

Incident Response Managers often encounter challenges such as rapidly evolving security threats, coordinating cross-functional teams under pressure, and ensuring clear communication during high-stress incidents. To effectively address these challenges, they focus on regular training and simulations, establish comprehensive incident response plans, and foster strong relationships with IT, legal, and executive teams. Emphasizing documentation and post-incident reviews also helps in continuously improving processes and adapting to new threats.

What does an incident response manager do?

An Incident Response Manager is responsible for leading an organization's efforts to detect, respond to, and recover from cybersecurity incidents such as data breaches, malware infections, or unauthorized access. They coordinate response teams, develop incident response plans, and ensure that incidents are properly documented and analyzed to prevent future occurrences. Their role also involves communicating with stakeholders, providing training, and keeping up to date with the latest cyber threats and best practices.

What is the difference between Incident Response Manager vs Security Analyst?

AspectIncident Response ManagerSecurity Analyst
CertificationsGCIH, CISSP, CISMCISSP, Security+
Work EnvironmentLeads incident response teams, manages response plansMonitors security systems, analyzes threats
Employer & Industry UsageUsed in cybersecurity teams across various industriesCommonly employed in security operations centers (SOCs)

The Incident Response Manager focuses on leading and coordinating incident response efforts, managing teams, and developing response strategies. In contrast, the Security Analyst primarily monitors security alerts, analyzes threats, and supports incident detection. Both roles require cybersecurity certifications and are integral to organizational security, but they differ in scope and responsibilities.

What cities are hiring for Incident Response Manager jobs? Cities with the most Incident Response Manager job openings:
What are the most commonly searched types of Incident Response jobs? The most popular types of Incident Response jobs are:
Who are the top companies hiring for Incident Response Manager jobs? The top employers for Incident Response Manager jobs are:
What states have the most Incident Response Manager jobs? States with the most job openings for Incident Response Manager jobs include:
Infographic showing various Incident Response Manager job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 12% Part Time, and 1% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.

Incident Response Analyst

Cyber Synergy Consulting Group

Washington, DC • On-site

$100K - $125K/yr

Full-time

Re-posted yesterday


Job description

Incident Response Analyst (Task 4 - Federal Cybersecurity Contract)
Location: Remote with occasional on-site (Washington, D.C. Metro Area)
Employment Type: Full-Time
Clearance: Public Trust (or eligibility to obtain)
We are seeking an experienced Incident Response Analyst to support Task 4 - Incident Response Management on a federal cybersecurity services contract. This role provides front-line security event triage, investigation, reporting, and coordination across multiple federal cybersecurity teams.
The ideal candidate has hands-on experience with enterprise IR tooling-CrowdStrike, FireEye (Trellix), Splunk, NetWitness, and Magnet AXIOM-and is comfortable working in a high-tempo operational environment aligned with federal cybersecurity frameworks (NIST, FISMA, OMB).
Key Responsibilities
  • Perform initial triage of security events from SIEM, EDR, NDR, and log sources, including CrowdStrike, FireEye/Trellix, Splunk, NetWitness, and related platforms.
  • Conduct incident investigations, including host and network forensics, log analysis, and evidence review using tools such as NetWitness and AXIOM.
  • Coordinate closely with HHS CSIRC, OpDiv incident response teams, system owners, and security engineering staff to validate findings and recommend containment actions.
  • Provide daily updates, SITREPs, and written documentation of incident status, investigative steps, and remediation recommendations.
  • Develop incident dashboards and knowledge base documentation within Splunk and other IR platforms.
  • Support containment, eradication, and recovery efforts aligned to federal IR procedures.
  • Participate in tabletop exercises, readiness assessments, and operational continuity testing.
  • Monitor and manage the Incident Response Team (IRT) mailbox; escalate urgent items within required SLAs.
  • Assist with audit support, evidence gathering, and post-incident reviews.
  • Contribute to continuous improvement of incident response processes and playbooks.
Required Qualifications
  • 2-5+ years of experience in cybersecurity operations, SOC analysis, or incident response.
  • Direct hands-on experience with IR tools, including:
    • CrowdStrike Falcon (EDR)
    • FireEye/Trellix (HX, Helix, or equivalent)
    • Splunk (SIEM, dashboards, search queries)
    • NetWitness (network forensics, packet analysis)
    • Magnet AXIOM (host forensics)
  • Strong understanding of adversary techniques, malware behavior, incident timelines, and forensic artifacts.
  • Familiarity with NIST 800-61, NIST 800-53, FISMA, OMB guidance.
  • Ability to clearly document investigations and communicate findings to technical and non-technical audiences.
  • Eligibility to obtain and maintain a Public Trust clearance.
Preferred Qualifications
  • Experience supporting federal agencies (HHS, DHS, DoD, DOJ, etc.).
  • Certifications such as Security+, CySA+, CEH, GCIH, GCIA, CHFI, or related.
  • Experience performing threat hunting across EDR, SIEM, and NDR tools.
  • Familiarity with packet analysis tools (Wireshark) and scripting languages (Python, PowerShell).
  • Experience with ServiceNow or similar ticketing platforms
Work Schedule & Expectations
  • Core hours: 7:00 AM - 5:00 PM EST, Monday through Friday, with the flexibility to support after-hours incidents as needed.
  • Participation in on-call rotations may be required.
  • Remote work permitted with reliable connectivity and camera-enabled participation.