1

Incident Response Jobs (NOW HIRING)

The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders ...

The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders ...

Description About Sygnia Sygnia is a leading global cyber readiness and incident response firm. Our teams operate on the digital frontlines of today's most sophisticated cyber battles, helping the ...

The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders ...

The Incident Response Coordinator is a role for those experienced with leading, managing and coordinating cybersecurity incident response activities. This role serves as a single point of contact for ...

The Role We are seeking a highly skilled and motivated Incident Response Expert to join our elite global team. In this role, you will lead and participate in complex forensic investigations and ...

We are expanding our Incident Response leadership team with a hands-on technical manager who thrives in fast-moving investigations and can guide customers through their most critical security events.

Incident Response Manager MUST HAVE: * 5+ years' hands-on experience in Incident Response management * Experience with legal operations * Experience working with a SOC/NOC * Hands-on experience with ...

Manager, Incident Response

Mclean, VA ยท Remote

$150K - $175K/yr

About the Role As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver ...

Success looks like faster incident response, less noise, and a SOC that gets sharper every sprint! * Triage, investigate, and respond to security alerts across Splunk's enterprise and product ...

New

Manager, Incident Response

Mclean, VA ยท On-site +1

$150K - $175K/yr

About the Role As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver ...

Job Summary Serves as the dedicated lead responder for Transocean's Cyber Security Incident Response Team (CSIRT), responsible for leading major investigation, coordination, containment, eradication ...

About the Role We're looking for an Incident Response Consultant to join our team and help clients navigate cybersecurity incidents with confidence. In this role, you'll serve as a trusted technical ...

Showing results 21-40

Incident Response information

See salary details

$41K

$127.2K

$199.5K

How much do incident response jobs pay per year?

As of Aug 14, 2026, the average yearly pay for incident response in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in incident response roles and how can they be managed?

Incident Response professionals often face challenges such as rapidly evolving cyber threats, handling high-pressure situations, and coordinating effectively with cross-functional teams during security incidents. Managing these challenges requires staying updated with the latest threat intelligence, practicing incident simulations, and maintaining clear communication protocols. Building strong relationships with IT, legal, and management teams can also help ensure a swift and coordinated response to incidents, making the role both demanding and highly collaborative.

How to get a job in incident response?

To get a job in incident response, candidates should develop skills in cybersecurity, network analysis, and digital forensics, often through relevant certifications like CISSP, GIAC, or CEH. Gaining experience through internships or entry-level security roles and familiarizing oneself with security tools such as SIEM systems and intrusion detection is also beneficial.

How much do incident responders make?

Incident responders typically earn a median annual salary between $70,000 and $110,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced professionals with certifications like CISSP or GIAC can earn higher salaries, especially in high-demand industries or regions with a strong cybersecurity focus.

What is incident response?

Incident response refers to the organized approach that organizations use to address and manage the aftermath of a security breach or cyberattack. The goal is to handle the situation in a way that limits damage, reduces recovery time and costs, and mitigates the risks associated with the incident. Incident response typically involves preparation, detection, containment, eradication, recovery, and lessons learned. A well-developed incident response plan helps organizations quickly identify threats, minimize impact, and restore normal operations.

What is the difference between Incident Response vs Security Analyst?

AspectIncident ResponseSecurity Analyst
CertificationsGCIH, CISSP, CEHCISSP, Security+
Work EnvironmentResponding to security incidents, investigating breachesMonitoring networks, analyzing security data
Employer & Industry UsageCybersecurity firms, large organizationsIT departments, security teams

Incident Response specialists focus on managing and mitigating security incidents and breaches, often working in response teams. Security Analysts monitor systems proactively, analyze security data, and identify vulnerabilities. While both roles require similar certifications and work within cybersecurity, Incident Response is more reactive, whereas Security Analysts are more proactive in security monitoring.

What are the key skills and qualifications needed to thrive as an incident response professional?

To thrive as an Incident Response professional, you need strong analytical skills, a deep understanding of cybersecurity principles, and usually a degree in computer science or a related field. Familiarity with tools like SIEM platforms (e.g., Splunk), forensic analysis software, and certifications such as CISSP or GIAC is highly beneficial. Attention to detail, calmness under pressure, and effective communication are crucial soft skills for responding to security incidents and working with cross-functional teams. These skills and qualities enable quick detection, containment, and resolution of security threats, minimizing organizational risk and damage.

What are the career paths for incident response?

Incident response professionals can advance to roles such as senior analyst, incident response manager, cybersecurity director, or chief information security officer. Career progression often involves gaining experience, obtaining certifications like CISSP or GIAC, and developing skills in threat analysis, forensics, and security management.

What cities are hiring for Incident Response jobs?

Cities with the most Incident Response job openings:

What are the most commonly searched types of Incident Response jobs?

The most popular types of Incident Response jobs are:

What states have the most Incident Response jobs?

States with the most job openings for Incident Response jobs include:

Infographic showing various Incident Response job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 50% In-person, and 50% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.

Incident Response Manager

Crowe LLP

Denver, CO โ€ข On-site

Full-time

Re-posted 18 days ago


Job description

Your Journey at Crowe Starts Here:

At Crowe, you can build a meaningful and rewarding career. With real flexibility to balance work with life moments, you're trusted to deliver results and make an impact. We embrace you for who you are, care for your well-being, and nurture your career. Everyone has equitable access to opportunities for career growth and leadership. Over our 80-year history, delivering excellent service through innovation has been a core part of our DNA across our audit, tax, and consulting groups. That's why we continuously invest in innovative ideas, such as AI-enabled insights and technology-powered solutions, to enhance our services. Join us at Crowe and embark on a career where you can help shape the future of our industry.

Job Description:

What It Means to Be a Consultant at Crowe
Consulting is a dynamic business focused on solving problems for our clients and serving our core markets through innovative solutions. As technology and AI continue to reshape the consulting landscape, we are looking for individuals who are curious, adaptable, and eager to learn. At Crowe, consultants are expected to build both technical and transferable skills, think critically, and use technology to solve real business problems. In this role, you will continuously learn, collaborate across teams, and explore how tools, including emerging AI capabilities, can improve efficiency, insights, and client outcomes.

In management at Crowe, you play a pivotal role in leading teams, guiding project execution, and deepening client relationships. You are expected to contribute to account planning, identify opportunities to add value, and ensure high-quality delivery. As your responsibilities expand, you take on broader account ownership, balancing project leadership with growing involvement in client strategy and solution development.

Success in this role comes from a growth mindset, strong communication skills, advanced critical thinking, and the ability to navigate new challenges with confidence.


The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders, overseeing engagement delivery, and acting as a trusted advisor to clients during cybersecurity crises. This role combines deep technical expertise with leadership, business development, client relationship management, and operational oversight responsibilities.

Responsibilities

  • Serve as the primary client-facing leader during major cybersecurity incidents.
  • Lead multiple concurrent incident response engagements involving ransomware, data breaches, insider threats, cloud compromises, and advanced threat actor activity.
  • Provide executive-level briefings to CISOs, CIOs, legal counsel, executive leadership, boards of directors, and other stakeholders.
  • Direct forensic investigations, threat hunting activities, containment efforts, eradication plans, and recovery operations.
  • Review and approve technical findings, investigation reports, executive summaries, and client deliverables.
  • Coordinate internal and external resources to ensure successful engagement execution and client outcomes.
  • Ensure investigations meet legal, regulatory, and evidentiary requirements.
  • Develop and maintain incident response methodologies, playbooks, procedures, and service offerings.
  • Lead and mentor Incident Response consultants and senior staff through coaching, technical guidance, and performance feedback.
  • Assist with recruiting, onboarding, and professional development of team members.
  • Support business development efforts through proposal development, scoping, client presentations, and strategic discussions.
  • Identify opportunities to expand client relationships and deliver additional cybersecurity services.
  • Contribute to thought leadership through whitepapers, webinars, conference presentations, and market-facing content.

Requirements

  • 7+ years of cybersecurity experience with at least 3 years focused on incident response, digital forensics, threat hunting, or cyber defense operations.
  • Demonstrated experience leading complex incident response engagements from initial detection through recovery.
  • Experience managing project teams, mentoring technical staff, and coordinating cross-functional stakeholders.
  • Strong leadership, decision-making, and risk management capabilities.
  • Excellent communication skills with the ability to present technical findings to executive and non-technical audiences.
  • Ability to manage competing priorities and multiple concurrent engagements.
  • Strong understanding of networking, operating systems, identity systems, cloud technologies, and cybersecurity principles.
  • Experience utilizing SIEM platforms such as Splunk, Elastic, Microsoft Sentinel, or FortiSIEM.
  • Experience utilizing EDR platforms such as CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, or Carbon Black.
  • Proficiency with scripting and automation using PowerShell, Python, Bash, or similar technologies.
  • Strong documentation and report-writing capabilities.
  • Willingness to travel approximately 15% or more as required.

Preferred Qualifications

  • Expert knowledge of Windows, Linux, Active Directory, Microsoft Entra ID, Microsoft 365, AWS, Azure, and Google Cloud environments.
  • Advanced understanding of attacker tactics, techniques, and procedures (MITRE ATT&CK).
  • Experience leading enterprise-scale ransomware investigations and recovery efforts.
  • Experience coordinating legal counsel, cyber insurance carriers, law enforcement, and third-party stakeholders during incidents.
  • Experience developing incident response programs, tabletop exercises, and cyber resilience strategies.
  • Experience managing consulting engagements and project financials.
  • Experience building and managing cybersecurity teams.
  • Relevant certifications such as GCFA, GCIH, GCED, GREM, GCTD, CISSP, CCSP, CISM, AWS Security Specialty, or Azure Security Engineer Associate.

We expect the candidate to uphold Crowe's values of Care, Trust, Courage, and Stewardship. These values define who we are. We expect all of our people to act ethically and with integrity at all times.

The application deadline for this role is 11/30/2026.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. Crowe is not sponsoring for work authorization at this time.

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Crowe, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $110,800.00 - $226,400.00 per year.

Our Benefits:
Your exceptional people experience starts here. At Crowe, we know that great peopleare what makes a great firm. We care about our people and offer employees a comprehensive total rewards package. Learn more about what working at Crowe can mean for you!
How You Can Grow:
We will nurture your talent in an inclusive culture that values diversity. You will have the chance to meet on a consistent basis with your Career Coach that will guide you in your career goals and aspirations. Learn more about where talent can prosper!
More about Crowe:
Crowe (www.crowe.com) is one of the largest public accounting, consulting and technology firms in the United States. Crowe uses its deep industry expertise to provide audit services to public and private entities while also helping clients reach their goals with tax, advisory, risk and performance services. Crowe is recognized by many organizations as one of the country's best places to work. Crowe serves clients worldwide as an independent member of Crowe Global, one of the largest global accounting networks in the world. The network consists of more than 200 independent accounting and advisory services firms in more than 130 countries around the world.
Crowe LLP and Crowe Advisory LLC (and their respective subsidiary entities) provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, sexual orientation, gender identity or expression, genetics, national origin, disability or protected veteran status, or any other characteristic protected by federal, state or local laws.


Crowe LLP and Crowe Advisory LLC (and their respective subsidiary entities) does not accept unsolicited candidates, referrals or resumes from any staffing agency, recruiting service, sourcing entity or any other third-party paid service at any time. Any referrals, resumes or candidates submitted to Crowe, or any employee or owner of Crowe without a pre-existing agreement signed by both parties covering the submission will be considered the property of Crowe, and free of charge.


Crowe will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws.

Please visit our webpage to see notices of the various state and local Ban-the-Box laws and Fair Chance Ordinances, where applicable.

We are committed to a merit-based hiring process, evaluating all candidates consistently using objective, job-related criteria such as relevant experience, demonstrated skills, measurable impact, and alignment with the role's responsibilities, and making employment decisions in a fair and inclusive manner free from discrimination.

If you are interested in applying for employment with Crowe and are in need of an accommodation or require special assistance to navigate our website or to complete your application, please visit our Applicant Assistance and Accommodations page for more information: https://careers.crowe.com/crowe-applicant-assistance-and-accommodation


Crowe logo

About Crowe

Sourced by ZipRecruiter

Crowe (www.crowe.com) is one of the largest public accounting, consulting and technology firms in the United States. Crowe uses its deep industry expertise to provide audit services to public and private entities while also helping clients reach their goals with tax, advisory, risk and performance services. Crowe is recognized by many organizations as one of the country's best places to work. Crowe serves clients worldwide as an independent member of Crowe Global, one of the largest global accounting networks in the world. The network consists of more than 200 independent accounting and advisory services firms in more than 130 countries around the world.

Industry

Accounting services

Company size

1,001 - 5,000 Employees

Headquarters location

Chicago, IL, US

Social media