Incident Response Manager
Atlanta, GA · On-site
We are expanding our Incident Response leadership team with a hands-on technical manager who thrives in fast-moving investigations and can guide customers through their most critical security events.
Atlanta, GA · On-site
We are expanding our Incident Response leadership team with a hands-on technical manager who thrives in fast-moving investigations and can guide customers through their most critical security events.
Atlanta, GA · On-site
We are expanding our Incident Response leadership team with a hands-on technical manager who thrives in fast-moving investigations and can guide customers through their most critical security events.
$107K - $195K/yr
Leidos is seeking an Incident Response Lead to join our team on a highly visible cyber security single-award IDIQ vehicle that provides security operations center (SOC) support, cyber analysis ...
$107K - $195K/yr
Leidos is seeking an Incident Response Lead to join our team on a highly visible cyber security single-award IDIQ vehicle that provides security operations center (SOC) support, cyber analysis ...
The Incident Response Coordinator is a role for those experienced with leading, managing and coordinating cybersecurity incident response activities. This role serves as a single point of contact for ...
The Incident Response Coordinator is a role for those experienced with leading, managing and coordinating cybersecurity incident response activities. This role serves as a single point of contact for ...
Sarasota, FL · On-site
The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders ...
Sarasota, FL · On-site
The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders ...
The Incident Response Coordinator supports the end-to-end response to IT incidents and service disruptions, helping restore normal operations quickly and reduce impact on mission-critical systems.
The Incident Response Coordinator supports the end-to-end response to IT incidents and service disruptions, helping restore normal operations quickly and reduce impact on mission-critical systems.
Boise, ID · On-site
The Incident Response Coordinator supports the end-to-end response to IT incidents and service disruptions, helping restore normal operations quickly and reduce impact on mission-critical systems.
Boise, ID · On-site
The Incident Response Coordinator supports the end-to-end response to IT incidents and service disruptions, helping restore normal operations quickly and reduce impact on mission-critical systems.
The Incident Response Analyst is a experienced position that supports TrendAI efforts to provide incident response for TrendAI and its customers. This role blends technical knowledge and experience ...
The Incident Response Analyst is a experienced position that supports TrendAI efforts to provide incident response for TrendAI and its customers. This role blends technical knowledge and experience ...
Manhattan, NY · On-site
Conduct and participate in incident response training and exercises * Upkeep and development of IR documentation * Support the overall B&H IR program. * Provide monthly reporting for the IR function.
Manhattan, NY · On-site
Conduct and participate in incident response training and exercises * Upkeep and development of IR documentation * Support the overall B&H IR program. * Provide monthly reporting for the IR function.
The Incident Response Coordinator supports the end‐to‐end response to IT incidents and service disruptions, helping restore normal operations quickly and reduce impact on mission‐critical ...
The Incident Response Coordinator supports the end‐to‐end response to IT incidents and service disruptions, helping restore normal operations quickly and reduce impact on mission‐critical ...
The SOC / Incident Response Engineer supports enterprise security monitoring, incident response, and threat detection across a hybrid IT environment, including on-premises infrastructure and cloud ...
The SOC / Incident Response Engineer supports enterprise security monitoring, incident response, and threat detection across a hybrid IT environment, including on-premises infrastructure and cloud ...
The Incident Response Analyst is a experienced position that supports TrendAI efforts to provide incident response for TrendAI and its customers. This role blends technical knowledge and experience ...
The Incident Response Analyst is a experienced position that supports TrendAI efforts to provide incident response for TrendAI and its customers. This role blends technical knowledge and experience ...
Sarasota, FL · On-site
The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders ...
Sarasota, FL · On-site
The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders ...
DESCRIPTION The Senior Incident Response Engineer is a senior technical expert responsible for leading and executing the most complex and high-impact incident response activities within the ...
DESCRIPTION The Senior Incident Response Engineer is a senior technical expert responsible for leading and executing the most complex and high-impact incident response activities within the ...
Oak Brook, IL · On-site
Incident Response Manager MUST HAVE: * 5+ years' hands-on experience in Incident Response management * Experience with legal operations * Experience working with a SOC/NOC * Hands-on experience with ...
Oak Brook, IL · On-site
Incident Response Manager MUST HAVE: * 5+ years' hands-on experience in Incident Response management * Experience with legal operations * Experience working with a SOC/NOC * Hands-on experience with ...
Arlington, VA · On-site
$160K/yr
The Incident Response engineer will manage security incident response processes, investigate threats, and implement corrective actions to contain and remediate incidents. Analyze security alerts ...
Arlington, VA · On-site
$160K/yr
The Incident Response engineer will manage security incident response processes, investigate threats, and implement corrective actions to contain and remediate incidents. Analyze security alerts ...
Manhattan, NY · On-site +1
The Role We are seeking a highly skilled and motivated Incident Response Expert to join our elite global team. In this role, you will lead and participate in complex forensic investigations and ...
Manhattan, NY · On-site +1
The Role We are seeking a highly skilled and motivated Incident Response Expert to join our elite global team. In this role, you will lead and participate in complex forensic investigations and ...
We are seeking a battle-tested, highly self-driven Manager, Incident Response to lead, inspire, and continuously mature our Incident Response Team. In this role, you will not just help to manage ...
We are seeking a battle-tested, highly self-driven Manager, Incident Response to lead, inspire, and continuously mature our Incident Response Team. In this role, you will not just help to manage ...
Bethesda, MD · On-site +1
$60K - $85K/yr
Overview Edgewater is seeking an Incident Response Analyst to provide support to an Edgewater Federal government contract. ** Due to the nature of the contract and work, US Citizenship is required
Bethesda, MD · On-site +1
$60K - $85K/yr
Overview Edgewater is seeking an Incident Response Analyst to provide support to an Edgewater Federal government contract. ** Due to the nature of the contract and work, US Citizenship is required
$150K - $175K/yr
About the Role As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver ...
$150K - $175K/yr
About the Role As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver ...
Mclean, VA · Remote
About the Role As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver ...
Quick apply
Mclean, VA · Remote
About the Role As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver ...
$41K - $55.4K
6% of jobs
$55.4K - $69.8K
7% of jobs
$69.8K - $84.2K
6% of jobs
$87.6K is the 25th percentile. Wages below this are outliers.
$84.2K - $98.6K
21% of jobs
$98.6K - $113K
7% of jobs
The median wage is $118.4K / yr.
$113K - $127.5K
4% of jobs
$127.5K - $141.9K
3% of jobs
$141.9K - $156.3K
7% of jobs
$167.9K is the 75th percentile. Wages above this are outliers.
$156.3K - $170.7K
15% of jobs
$170.7K - $185.1K
19% of jobs
$185.1K - $199.5K
3% of jobs
$41K
$127.2K
$199.5K
| Aspect | Incident Response | Security Analyst |
|---|---|---|
| Certifications | GCIH, CISSP, CEH | CISSP, Security+ |
| Work Environment | Responding to security incidents, investigating breaches | Monitoring networks, analyzing security data |
| Employer & Industry Usage | Cybersecurity firms, large organizations | IT departments, security teams |
Incident Response specialists focus on managing and mitigating security incidents and breaches, often working in response teams. Security Analysts monitor systems proactively, analyze security data, and identify vulnerabilities. While both roles require similar certifications and work within cybersecurity, Incident Response is more reactive, whereas Security Analysts are more proactive in security monitoring.
Cities with the most Incident Response job openings:
The most popular types of Incident Response jobs are:
States with the most job openings for Incident Response jobs include:
The top searched job categories for Incident Response jobs are:

Full-time
Re-posted 3 days ago
Company Overview
Fortuna Cysec delivers unified cybersecurity operations through TheFense platform—our integrated MDR, SIEM, EDR, and response ecosystem designed for regulated industries, nonprofits, healthcare, education, and mission-driven organizations. Our global SOC/NOC operates 24×7×365, providing real-time visibility, rapid containment, and deep technical expertise across diverse customer environments.
We are expanding our Incident Response leadership team with a hands-on technical manager who thrives in fast-moving investigations and can guide customers through their most critical security events.
Role Summary
The Cybersecurity Incident Response Manager leads and directly participates in high-severity investigations across Fortuna Cysec’s customer base. This role blends technical depth, operational leadership, and customer-facing communication. You will serve as the senior escalation point for complex incidents, drive containment and remediation, and strengthen TheFense platform’s detection and response capabilities.
Lead and Execute Incident Response
· Command all phases of incident response—triage, investigation, containment, eradication, and recovery—while performing hands-on technical analysis.
· Analyze EDR telemetry, SIEM alerts, network logs, cloud audit logs, and identity events across Microsoft, AWS, and hybrid environments.
· Execute containment actions including endpoint isolation, identity disablement, MFA resets, OAuth token revocation, and firewall/network segmentation changes.
· Conduct forensic acquisition and analysis using Velociraptor, KAPE, FTK, EnCase, and Volatility.
· Reverse-engineer or sandbox suspicious binaries/scripts to determine behavior and impact.
· Lead hypothesis-driven threat hunts mapped to MITRE ATT&CK using TheFense’s unified telemetry.
Strengthen IR Operations
· Oversee daily IR operations across global SOC/NOC teams, ensuring SLA adherence and seamless follow-the-sun handoffs.
· Review and enhance IR playbooks, runbooks, and automated response actions within TheFense.
· Ensure high-quality incident documentation, evidence handling, and customer-ready reporting.
· Conduct root-cause analysis and deliver technically detailed post-incident reviews.
· Partner with engineering to refine detection logic, reduce false positives, and improve automation.
Engage Directly with Customers
· Serve as the technical authority during active breaches, guiding CISOs, IT directors, and executive stakeholders.
· Deliver clear, concise briefings that include attack path analysis, forensic findings, and prioritized remediation steps.
· Support customer teams with hands-on remediation across identity, cloud, endpoint, and email ecosystems.
· Provide strategic recommendations aligned with NIST, CIS Controls, and Fortuna Cysec best practices.
Advance Threat Intelligence and Detection
· Translate emerging threat intelligence into new detection rules, response playbooks, and threat-hunting queries.
· Validate detection logic through lab testing, simulated attacks, and historical telemetry review.
· Identify detection gaps and collaborate with TI teams to enrich investigations with IOCs and adversary behavior patterns.
Build Team and Platform Maturity
· Mentor analysts across global SOC/NOC teams in IR, forensics, cloud investigations, and threat hunting.
· Develop internal tooling and automation using Python or PowerShell.
· Participate in tabletop exercises, purple-team engagements, and breach simulations.
· Contribute to the evolution of TheFense platform by evaluating new telemetry sources and response capabilities.
Required Qualifications
Preferred Qualifications
Fortuna Cysec is an equal opportunity employer. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, pregnancy, age, sexual orientation, transgender status, gender identity, disability, alienage or citizenship status, marital status or partnership status, genetic information, veteran status or any other characteristic protected under applicable law.