Lead and manage a Security Incident Response Team focused on responding to security threats and maintaining HUB's critical threat detection and response suite of security applications. * Available 24 ...
Lead and manage a Security Incident Response Team focused on responding to security threats and maintaining HUB's critical threat detection and response suite of security applications. * Available 24 ...
Lead and manage a Security Incident Response Team focused on responding to security threats and maintaining HUB's critical threat detection and response suite of security applications. * Available 24 ...
Lead and manage a Security Incident Response Team focused on responding to security threats and maintaining HUB's critical threat detection and response suite of security applications. * Available 24 ...
Security Incident Response Engineer
Atlanta, GA · On-site
$125 - $150/hr
## Security Incident Response EngineerApplylocations: 1170 Peachtree St Ste 1200 - ATLANTA, GA: 100 Ottawa Ave Sw - GRAND RAPIDS, MItime type: Full timeposted on: Posted Todayjob requisition id:
Security Incident Response Engineer
Atlanta, GA · On-site
$125 - $150/hr
## Security Incident Response EngineerApplylocations: 1170 Peachtree St Ste 1200 - ATLANTA, GA: 100 Ottawa Ave Sw - GRAND RAPIDS, MItime type: Full timeposted on: Posted Todayjob requisition id:
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
10279 - Security Incident Response Manager (SSRM)
Irvine, CA · On-site
$118K - $182K/yr
10279- Manager, Security Incident Response Location: Irvine, HQ Company Overview Hyundai AutoEver America (HAEA) is the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global ...
Quick apply
10279 - Security Incident Response Manager (SSRM)
Irvine, CA · On-site
$118K - $182K/yr
10279- Manager, Security Incident Response Location: Irvine, HQ Company Overview Hyundai AutoEver America (HAEA) is the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global ...
10279 - Security Incident Response Manager (SSRM)
Irvine, CA · On-site
$150 - $200/hr
10279-Manager, Security Incident Response Location: Irvine, HQ Company Overview Hyundai AutoEver America (HAEA) is the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global ...
10279 - Security Incident Response Manager (SSRM)
Irvine, CA · On-site
$150 - $200/hr
10279-Manager, Security Incident Response Location: Irvine, HQ Company Overview Hyundai AutoEver America (HAEA) is the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global ...
IT SECURITY INCIDENT RESPONSE MANAGER Downey, CA 5+ months Responsibilities: 1. Document incident response process and procedures. 2. Provide first responder forensics analysis and investigation a.
IT SECURITY INCIDENT RESPONSE MANAGER Downey, CA 5+ months Responsibilities: 1. Document incident response process and procedures. 2. Provide first responder forensics analysis and investigation a.
Following security incident containment & recovery you will be responsible for engaging with key ... What you'll own * Coordinate incident response in line with the corporate security incident ...
Following security incident containment & recovery you will be responsible for engaging with key ... What you'll own * Coordinate incident response in line with the corporate security incident ...
Incident Response Engineer
Arlington, VA · On-site
The Incident Response Engineer will manage security incident response processes, investigate threats, and implement corrective actions to ensure the safety and security of federal operations.
Incident Response Engineer
Arlington, VA · On-site
The Incident Response Engineer will manage security incident response processes, investigate threats, and implement corrective actions to ensure the safety and security of federal operations.
10279 - Security Incident Response Manager (SSRM)
Irvine, CA · On-site
$118K - $182K/yr
10279- Manager, Security Incident Response Location: Irvine, HQ Company Overview Hyundai AutoEver America (HAEA) is the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global ...
10279 - Security Incident Response Manager (SSRM)
Irvine, CA · On-site
$118K - $182K/yr
10279- Manager, Security Incident Response Location: Irvine, HQ Company Overview Hyundai AutoEver America (HAEA) is the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global ...
Following security incident containment & recovery you will be responsible for engaging with key ... Coordinate incident response in line with the corporate security incident response plan. * Manage ...
Following security incident containment & recovery you will be responsible for engaging with key ... Coordinate incident response in line with the corporate security incident response plan. * Manage ...
Knowledge of operating systems, network protocols, and security technologies * Knowledge of threat intelligence, vulnerability management, and security incident response best practices * Ability to ...
Knowledge of operating systems, network protocols, and security technologies * Knowledge of threat intelligence, vulnerability management, and security incident response best practices * Ability to ...
Experience with incident response * Knowledge of cybersecurity principles, incident detection, analysis, and response methodologies. * Knowledge of operating systems, network protocols, and security ...
Experience with incident response * Knowledge of cybersecurity principles, incident detection, analysis, and response methodologies. * Knowledge of operating systems, network protocols, and security ...
Knowledge of cybersecurity principles, incident detection, analysis, and response methodologies. * Knowledge of operating systems, network protocols, and security technologies * Knowledge of threat ...
Knowledge of cybersecurity principles, incident detection, analysis, and response methodologies. * Knowledge of operating systems, network protocols, and security technologies * Knowledge of threat ...
Security Incident Response Engineer
OR · On-site +1
About the team The Security Incident Response team works to analyze, investigate, and respond to threats before they impact Stripe's business or users. From external attacks to insider threats, our ...
Security Incident Response Engineer
OR · On-site +1
About the team The Security Incident Response team works to analyze, investigate, and respond to threats before they impact Stripe's business or users. From external attacks to insider threats, our ...
Security Incident Response information
See salary details
$41K - $55.4K
6% of jobs
$55.4K - $69.8K
7% of jobs
$69.8K - $84.2K
6% of jobs
$87.6K is the 25th percentile. Wages below this are outliers.
$84.2K - $98.6K
21% of jobs
$98.6K - $113K
7% of jobs
The median wage is $118.4K / yr.
$113K - $127.5K
4% of jobs
$127.5K - $141.9K
3% of jobs
$141.9K - $156.3K
7% of jobs
$167.9K is the 75th percentile. Wages above this are outliers.
$156.3K - $170.7K
15% of jobs
$170.7K - $185.1K
19% of jobs
$185.1K - $199.5K
3% of jobs
$41K
$127.2K
$199.5K
How much do security incident response jobs pay per year?
What is security incident response?
What skills and qualifications are needed for security incident response?
What are common challenges in security incident response and how can they be managed?
What is the difference between Security Incident Response vs Security Analyst?
| Aspect | Security Incident Response | Security Analyst |
|---|---|---|
| Certifications | GCIH, CISSP, CISA | CISSP, Security+ |
| Work Environment | Incident handling teams, cybersecurity operations centers | Monitoring, analyzing security data, risk assessment |
| Employer & Industry Usage | Organizations responding to security breaches | Organizations analyzing security posture |
| Search & Comparison Intent | Understanding incident response roles | Understanding security analysis roles |
Security Incident Response specialists focus on managing and mitigating security breaches and incidents, often working in incident response teams. Security Analysts primarily monitor security systems, analyze threats, and assess risks. While both roles require cybersecurity certifications and work within similar environments, Incident Responders are more reactive, handling specific security events, whereas Analysts proactively monitor and analyze security data to prevent incidents.
What cities are hiring for Security Incident Response jobs?
Cities with the most Security Incident Response job openings:
What states have the most Security Incident Response jobs?
States with the most job openings for Security Incident Response jobs include:
What are popular job titles related to Security Incident Response jobs?
For Security Incident Response jobs, the most frequently searched job titles are:

Manager, Security Incident Response
Chicago, IL • On-site
Full-time
Dental, Vision, Life, Retirement, PTO
Re-posted 10 days ago
HUB International rating
8.0
Based on 140 frontline employees who took The Breakroom Quiz
172nd of 315 rated insurance
Job description
ABOUT US
At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference. Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence.
HUB is a global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, persnal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions
Job Description
In this role, you will manage the Security Incident Response team; for detecting and identifying cyber threats, as well as containment and remediation of these threats. This role owns the full incident response lifecycle-detection, triage, containment, eradication, recovery, and post-incident review-and is responsible for building a scalable Incident Response function that pairs reactive response capability with proactive detection engineering and threat hunting. The Manager ensures investigations are conducted with sound forensic methodology, including log and audit-trail analysis across cloud and on-premises platforms, accurate scoping of impacted systems and accounts.
Objectives of this Role
- Manages and is responsible for the successful completion of all tasks in assigned projects.
- Lead and manage a Security Incident Response Team focused on responding to security threats and maintaining HUB's critical threat detection and response suite of security applications.
- Available 24/7 for any critical incidents that may arise that require immediate resolution, providing leadership and direction to a multi-disciplinary IT team.
- Work with IT teams to ensure managed environments and procedures comply with defined corporate security policies.
- Mentor and develop team members to help foster individuals' professional growth.
- Engage with teams to practice continuous improvement in processes and tooling.
- Supervises assigned operations team members and performs personnel actions including hiring, individual goal tracking, training, performance evaluation.
- Maintains current knowledge of relevant technology, bringing forth ideas for modernization and improvement.
- Identify potential technical issues and assist in engineering possible solutions
- Engage with management regularly with reports on project status, activities, and achievements
- Lead "Technical Archeology" efforts (Platform and System Decomposition), in respect to gaps identified during incident response activities.
- Lead the creation of security incident response processes and playbooks that are scalable, consistent, repeatable, and supportable.
- Direct forensic investigations of security incidents, including analysis of cloud audit logs (e.g., Microsoft 365 Unified Audit Log), endpoint and network telemetry, and identity activity, to identify indicators of compromise, establish attack timelines, and determine scope of impact.
- Design and maintain a tiered escalation framework and on-call rotation so that incidents are routed to the appropriate analyst and management level based on severity and business impact.
- Drive maturity of the Incident Response and Detection Engineering functions against a KPI-based roadmap, tracking metrics such as mean time to detect (MTTD), mean time to respond (MTTR), alert triage volume, and case closure rates.
- Balance the team's dual-track structure of reactive Incident Response and proactive Detection Engineering/threat hunting, ensuring each track has clear ownership, workflows, and staffing.
- Conduct post-incident reviews and root-cause analysis to capture lessons learned, close process gaps, and feed findings back into playbooks and detection content.
Daily and Monthly Responsibilities
- Communicate with stakeholders to assist in the identification of business, technical, and operational requirements.
- Analysis, of root-cause analysis for service interruption, to establish preventive measures, mitigations, or needed changes.
- Evaluate security applications, infrastructure and associated costs at regular intervals
- Be responsible for analysis and recommendation of configuration changes, process improvements or visibility enhancements to the support and scaling of HUB's security response.
- Triage and prioritize incoming security alerts and incidents daily, assigning severity and escalating to the appropriate analyst or on-call tier.
- Perform or oversee forensic log review for active investigations (e.g., Microsoft 365 Unified Audit Log, EDR, network/firewall logs), documenting findings and preserving evidence in line with chain-of-custody practices.
- Report monthly on incident response KPIs, including mean time to detect (MTTD), mean time to respond (MTTR), incident volume, and case closure rates, to leadership.
- Facilitate tabletop exercises and periodic playbook/runbook reviews to validate incident response readiness and identify process gaps.
Skills and Qualifications
- Bachelor's degree in technology or applicable experience.
- 10+ Years of experience with programming/scripting languages (Powershell, python, shell scripting)
- Extensive experience with: TCP/IP, DNS, CDN, HTTP, WAF, OAuth, SAML
- 3+ years of experience with cloud infrastructure as a service (AWS, Azure, GCP)
- 5+ years of experience with Microsoft Active Directory/Entra and O365 services and technology
- 5+ years of experience with security platforms, automation tooling
- Hands-on experience with SIEM, EDR, and SOAR platforms for detection, alerting, and investigation.
- Experience conducting digital forensics and incident response (DFIR), including log analysis, timeline reconstruction, and evidence handling with chain-of-custody rigor.
- Working knowledge of incident response frameworks (e.g., NIST 800-61, SANS) and experience developing incident response playbooks and runbooks.
- Experience building or maturing an incident response team, including defining KPIs/metrics and driving a maturity roadmap.
- Collaboration, prioritization, and adaptability skills
- Desire to continuously develop your skills and knowledge
JOIN OUR TEAM
Do you believe in the power of innovation, collaboration, and transformation? Do you thrive in a supportive and client focused work environment? Are you looking for an opportunity to help build and drive change in a rapidly growing and evolving organization? When you join HUB International, you will be part of a community of learners and doers focused on our Core Values: entrepreneurship, teamwork, integrity, accountability, and service.
The expected salary range for this position is $ 130,000 to $150,000 and will be impacted by factors such as the successful candidate's skills, experience and working location, as well as the specific position's business line, scope and level. HUB International is proud to offer comprehensive benefit and total compensation packages which could include health/dental/vision/life/disability insurance, FSA, HAS and 401(k) accounts, paid-time-off benefits such as vacation, sick, personal, floating holidays and company holidays. In addition, eligible annual bonuses, equity and commissions may be available for some positions.
Department Information Technology
Required Experience: 5-7 years of relevant experience
Required Travel: Negligible
Required Education: Bachelor's degree (4-year degree)
HUB International Limited is an equal opportunity employer that does not discriminate on the basis of race/ethnicity, national origin, religion, age, color, sex, sexual orientation, gender identity, disability or veteran's status, or any other characteristic protected by local, state or federal laws, rules or regulations.
E-Verify Program
We endeavor to make this website accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the recruiting team HUBRecruiting@hubinternational.com. This contact information is for accommodation requests only; do not use this contact information to inquire about the status of applications.
What HUB International employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom