This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP ... Collaborate with IT and infrastructure teams to validate that security controls are implemented ...
This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP ... Collaborate with IT and infrastructure teams to validate that security controls are implemented ...
Incident and Escalation Manager
San Francisco, CA · On-site
$180K - $220K/yr
Write it down so anyone on rotation runs it the same way. * Build and train the incident commander rotation. Build a realistic balance of hiring and utilizing existing resources across humans and AI ...
Incident and Escalation Manager
San Francisco, CA · On-site
$180K - $220K/yr
Write it down so anyone on rotation runs it the same way. * Build and train the incident commander rotation. Build a realistic balance of hiring and utilizing existing resources across humans and AI ...
This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP ... Collaborate with IT and infrastructure teams to validate that security controls are implemented ...
This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP ... Collaborate with IT and infrastructure teams to validate that security controls are implemented ...
Lead and direct IT incident response activities, including serving as Incident Commander during service disruptions and major incidents. These activities occur during or outside of routine work hours*
Lead and direct IT incident response activities, including serving as Incident Commander during service disruptions and major incidents. These activities occur during or outside of routine work hours*
Senior Incident Handler
$18.25 - $22/hr
You build calm and confidence when it matters most. * Deep Threat Investigation: Lead advanced ... Command-level instincts: Demonstratedability to act as an incident commander or technical lead in ...
Senior Incident Handler
$18.25 - $22/hr
You build calm and confidence when it matters most. * Deep Threat Investigation: Lead advanced ... Command-level instincts: Demonstratedability to act as an incident commander or technical lead in ...
Senior Incident Handler
Chicago, IL · On-site
$18.25 - $22.25/hr
You build calm and confidence when it matters most. * Deep Threat Investigation: Lead advanced ... Command-level instincts: Demonstratedability to act as an incident commander or technical lead in ...
Senior Incident Handler
Chicago, IL · On-site
$18.25 - $22.25/hr
You build calm and confidence when it matters most. * Deep Threat Investigation: Lead advanced ... Command-level instincts: Demonstratedability to act as an incident commander or technical lead in ...
... IT incidents affecting internal and external customers. This individual serves as the command-and ... Major Incident Management (MIM) - Act as the primary incident lead for highimpact IT incidents ...
... IT incidents affecting internal and external customers. This individual serves as the command-and ... Major Incident Management (MIM) - Act as the primary incident lead for highimpact IT incidents ...
Incident Response Manager
San Francisco, CA · On-site
$172K - $258K/yr
If you're going to spend your time, spend it on something that matters to the world. The Security ... Lead incidents as a senior incident commander in the on-call rotation, and serve as the escalation ...
Incident Response Manager
San Francisco, CA · On-site
$172K - $258K/yr
If you're going to spend your time, spend it on something that matters to the world. The Security ... Lead incidents as a senior incident commander in the on-call rotation, and serve as the escalation ...
Senior Incident Handler
$18.25 - $22/hr
You build calm and confidence when it matters most. * Deep Threat Investigation: Lead advanced ... Command-level instincts: Demonstrated ability to act as an incident commander or technical lead in ...
Senior Incident Handler
$18.25 - $22/hr
You build calm and confidence when it matters most. * Deep Threat Investigation: Lead advanced ... Command-level instincts: Demonstrated ability to act as an incident commander or technical lead in ...
A breach isn't a leak, it's the frontier walking out the door. * Build the entire security program ... Lead incidents as a senior incident commander in the on-call rotation, and serve as the escalation ...
A breach isn't a leak, it's the frontier walking out the door. * Build the entire security program ... Lead incidents as a senior incident commander in the on-call rotation, and serve as the escalation ...
... IT incidents affecting internal and external customers. This individual serves as the command-and ... Major Incident Management (MIM) - Act as the primary incident lead for highimpact IT incidents ...
... IT incidents affecting internal and external customers. This individual serves as the command-and ... Major Incident Management (MIM) - Act as the primary incident lead for highimpact IT incidents ...
... IT incidents affecting internal and external customers. This individual serves as the command-and ... Major Incident Management (MIM) - Act as the primary incident lead for highimpact IT incidents ...
... IT incidents affecting internal and external customers. This individual serves as the command-and ... Major Incident Management (MIM) - Act as the primary incident lead for highimpact IT incidents ...
... IT incidents affecting internal and external customers. This individual serves as the command-and ... Major Incident Management (MIM) - Act as the primary incident lead for high-impact IT incidents ...
... IT incidents affecting internal and external customers. This individual serves as the command-and ... Major Incident Management (MIM) - Act as the primary incident lead for high-impact IT incidents ...
... IT incidents affecting internal and external customers. This individual serves as the command-and ... Major Incident Management (MIM) - Act as the primary incident lead for high‑impact IT incidents ...
... IT incidents affecting internal and external customers. This individual serves as the command-and ... Major Incident Management (MIM) - Act as the primary incident lead for high‑impact IT incidents ...
Incident Detection/Response Manager (SOC Manager) with Security Clearance
Hampton, VA · On-site
$140K - $160K/yr
When incidents occur, you become the incident commander, orchestrating response from the moment a ... U.S. Citizenship required. * 8+ years of IT experience, with 4+ years of dedicated incident ...
Incident Detection/Response Manager (SOC Manager) with Security Clearance
Hampton, VA · On-site
$140K - $160K/yr
When incidents occur, you become the incident commander, orchestrating response from the moment a ... U.S. Citizenship required. * 8+ years of IT experience, with 4+ years of dedicated incident ...
Write it down so anyone on rotation runs it the same way. * Build and train the incident commander rotation. Build a realistic balance of hiring and utilizing existing resources across humans and AI ...
Write it down so anyone on rotation runs it the same way. * Build and train the incident commander rotation. Build a realistic balance of hiring and utilizing existing resources across humans and AI ...
Senior Manager, Incident Response
Atlanta, GA · On-site
$106K - $144K/yr
This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP ... Collaborate with IT and infrastructure teams to validate that security controls are implemented ...
Senior Manager, Incident Response
Atlanta, GA · On-site
$106K - $144K/yr
This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP ... Collaborate with IT and infrastructure teams to validate that security controls are implemented ...
Senior Incident Manager
Austin, TX · On-site
... it's executed consistently and accurately, while continuously improving it. You'll lead incident ... as Incident Commander on high-severity events, owning the response from declaration through ...
Senior Incident Manager
Austin, TX · On-site
... it's executed consistently and accurately, while continuously improving it. You'll lead incident ... as Incident Commander on high-severity events, owning the response from declaration through ...
Senior Incident Manager
Austin, TX · On-site
... it's executed consistently and accurately, while continuously improving it. You'll lead incident ... Serve as Incident Commander on high-severity events, owning the response from declaration through ...
Senior Incident Manager
Austin, TX · On-site
... it's executed consistently and accurately, while continuously improving it. You'll lead incident ... Serve as Incident Commander on high-severity events, owning the response from declaration through ...
Senior Incident Manager
Austin, TX · On-site
... it's executed consistently and accurately, while continuously improving it. You'll lead incident ... as Incident Commander on high-severity events, owning the response from declaration through ...
Senior Incident Manager
Austin, TX · On-site
... it's executed consistently and accurately, while continuously improving it. You'll lead incident ... as Incident Commander on high-severity events, owning the response from declaration through ...
It Incident Commander information
See salary details
$41K - $55.4K
6% of jobs
$55.4K - $69.8K
7% of jobs
$69.8K - $84.2K
6% of jobs
$87.6K is the 25th percentile. Wages below this are outliers.
$84.2K - $98.6K
21% of jobs
$98.6K - $113K
7% of jobs
The median wage is $118.4K / yr.
$113K - $127.5K
4% of jobs
$127.5K - $141.9K
3% of jobs
$141.9K - $156.3K
7% of jobs
$167.9K is the 75th percentile. Wages above this are outliers.
$156.3K - $170.7K
15% of jobs
$170.7K - $185.1K
19% of jobs
$185.1K - $199.5K
3% of jobs
$41K
$127.2K
$199.5K
How much do it incident commander jobs pay per year?
What are popular job titles related to It Incident Commander jobs?
For It Incident Commander jobs, the most frequently searched job titles are:
Senior Manager, Incident Response
Atlanta, GA • On-site
Full-time
Posted 20 days ago
Key responsibilities
Serve as the primary Incident Commander for high-severity and critical security incidents, leading response activities and coordinating cross-functional teams.
Make and communicate decisions to contain incidents, prevent escalation, and restore normal operations, while briefing executive leadership and stakeholders.
Lead security engineering efforts by developing detection content, recommending control improvements, and automating security workflows.
Newell Brands rating
7.3
Based on 80 frontline employees who took The Breakroom Quiz
Job description
Alternate Locations:
Newell Brands is a leading consumer products company with a portfolio of iconic brands like Graco®, Coleman®, Oster®, Rubbermaid®, Sharpie® and Yankee Candle® - and 24,000 talented teammates around the world. Our culture is built on values in action: Integrity, Teamwork, Passion for Winning, Ownership, and Leadership. We work together to win, grow, and make a real impact-supported by a high-performing, inclusive, and collaborative environment where you can be your best, every day.
Job Summary
The Cyber Security Senior Manager, Incident Response reports to the Senior Manager of Security Operations and serves as the senior-most technical leader within the Newell Brands Security Operations function. This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP) - owning end-to-end response coordination for high-severity and critical security incidents across Newell's global environment.
Beyond incident response, the Senior Manager sets the technical direction for Security Operations, leading detection engineering, automation and control-improvement initiatives while directing the team's day-to-day operational execution. This is a hands-on leadership role: the right candidate pairs deep, current IR and engineering expertise with the operational judgment to run a modern SOC and translate lessons learned into durable, scalable process improvements.
Key Responsibilities
Incident Command & Response
- Serve as primary Incident Commander in accordance with the Newell Brands CSIRP, leading response activities across all CSIRT functional teams for high-severity and critical incidents.
- Make and communicate time-sensitive decisions to contain incidents, prevent escalation and restore normal operations as quickly and efficiently as possible.
- Coordinate response activities across Security Operations, IT, Legal, HR, Corporate Communications, Privacy and other cross-functional teams, ensuring alignment with CSIRP priorities.
- Partner with the CISO to brief executive leadership, the Information Security Governance Committee, and other key stakeholders on incident status, business impact and response actions.
- Determine when to activate external IR retainer resources, manage those vendor relationships throughout an engagement, and ensure evidentiary integrity.
- Lead post-incident reviews and after-action analysis; document findings and drive implementation of corrective actions to reduce recurrence.
- Maintain and continuously improve CSIRP documentation, incident runbooks and playbooks; conduct tabletop exercises and simulation drills at least annually.
Security Engineering & Control Improvement
- Develop and recommend security control improvements based on incident findings, threat intelligence and gap assessments across endpoint, network, identity and cloud environments.
- Design, build and maintain detection engineering content - SIEM correlation rules, behavioral analytics and custom signatures - to improve fidelity and reduce mean time to detect.
- Lead automation initiatives across Security Operations workflows including alert triage, enrichment, containment actions and case management integrations (SOAR/XSOAR or equivalent).
- Evaluate emerging security technologies and make evidence-based recommendations for tooling investments that improve detection and response capabilities.
- Collaborate with IT and infrastructure teams to validate that security controls are implemented correctly and test them through adversary simulation and purple team activities.
Security Operations
- Lead day-to-day Security Operations, directing SOC monitoring, alerting and triage to ensure operational coverage and response readiness across global time zones.
- Set the technical direction and continuous-improvement roadmap for the SOC, prioritizing the work that most reduces risk and improves detection and response performance.
- Provide senior technical leadership and mentorship to SOC analysts, elevating investigation quality and accelerating analyst skill development.
- Own the Security Operations KPI and metrics program, using it to demonstrate measurable improvement in SOC maturity and risk reduction to leadership.
- Maintain an in-depth understanding of Newell Brands' current and forward-looking threat profile relevant to a global consumer goods company, and ensure operational coverage reflects it.
- Own Security Operations tooling coverage and effectiveness, identifying and closing gaps across the detection and response stack.
- Develop and maintain trusted relationships with stakeholders across IT, Legal, HR, Privacy, Ethics and business unit leadership.
- Represent Security Operations in the information security community to identify emerging threats, intelligence and techniques that may impact Newell Brands.
Education
- Bachelor's degree in Information Security, Computer Science, Information Management Systems or a related field required.
Required Qualifications
- 10+ years of experience in cyber security required, with a minimum of 6 years in a dedicated Incident Response or Security Operations role.
- Experience leading the technical operations of a SOC or Security Operations team, including setting priorities, mentoring analysts and driving measurable operational improvement.
- Demonstrated experience serving as an Incident Commander or leading response efforts for high-severity incidents (ransomware, data breach, nation-state intrusion or equivalent).
- Proven experience managing cross-functional response teams under pressure, including coordination with Legal, Communications and executive stakeholders.
- Experience managing and directing external IR retainer engagements and third-party forensic vendors.
- Hands-on expertise with endpoint and network-based forensic investigation, malware analysis and log-based intrusion analysis.
- Practical security engineering experience: SIEM detection content development, SOAR playbook authoring and security automation scripting (Python, PowerShell or equivalent).
- Demonstrated ability to provide security control recommendations and architecture guidance across endpoint, network, cloud (Azure, M365) and identity environments.
- Strong knowledge of network protocols, OS internals and application-layer vulnerabilities, along with corresponding risk mitigations.
- Prior experience in a Fortune 500 or complex global enterprise environment preferred.
Preferred Qualifications
One or more of the following certifications or similar:
- GIAC Certified Incident Handler (GCIH)
- BTL2 (Security Blue Team Level 2)
- OffSec Defense Analyst (OSDA)
- Certified Information Systems Security Professional (CISSP)
Newell Brands (NASDAQ: NWL) is a leading global consumer goods company with a strong portfolio of well-known brands, including Rubbermaid, Sharpie, Graco, Coleman, Rubbermaid Commercial Products, Yankee Candle, Paper Mate, FoodSaver, Dymo, EXPO, Elmer's, Oster, NUK, Spontex and Campingaz. We are focused on delighting consumers by lighting up everyday moments. Newell Brands and its subsidiaries are Equal Opportunity Employers and comply with applicable employment laws. EOE/M/F/Vet/Disabled are encouraged to apply.
Date Posted: Aug 24, 2026
What Newell Brands employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Newell Brands
Sourced by ZipRecruiter
Newell Brands (NASDAQ: NWL) is a leading global consumer goods company with a strong portfolio of well-known brands, including Rubbermaid, Sharpie, Graco, Coleman, Rubbermaid Commercial Products, Yankee Candle, Paper Mate, FoodSaver, Dymo, EXPO, Elmer's, Oster, NUK, Spontex and Campingaz.
Industry
Manufacturing
Company size
10,000+ Employees
Headquarters location
Atlanta, GA, US
Year founded
1903