Incident Response Manager
Atlanta, GA · On-site
Strong SIEM experience with log parsing, correlation, and custom detection creation (Wazuh, Microsoft Sentinel, Elastic, Splunk). * Strong Windows Servers, Office 365 & Azure EntraID / Intune ...
Atlanta, GA · On-site
Strong SIEM experience with log parsing, correlation, and custom detection creation (Wazuh, Microsoft Sentinel, Elastic, Splunk). * Strong Windows Servers, Office 365 & Azure EntraID / Intune ...
Atlanta, GA · On-site
Strong SIEM experience with log parsing, correlation, and custom detection creation (Wazuh, Microsoft Sentinel, Elastic, Splunk). * Strong Windows Servers, Office 365 & Azure EntraID / Intune ...
Palo Alto, CA · Hybrid
$168K/yr
SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...
Quick apply
Palo Alto, CA · Hybrid
$168K/yr
SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...
New Haven, CT · On-site
$125 - $150/hr
Perform vulnerability scanning, assessment, remediation, and penetration testing (e.g., Nessus, Wazuh). * Conduct risk assessments and recommend mitigation strategies to reduce exposure to cyber ...
New Haven, CT · On-site
$125 - $150/hr
Perform vulnerability scanning, assessment, remediation, and penetration testing (e.g., Nessus, Wazuh). * Conduct risk assessments and recommend mitigation strategies to reduce exposure to cyber ...
Monitor system performance using programs such as Grafana, Graylog, Wazuh, and Uptime Kuma to ensure high availability, uptime, and security. * Design, configure, and maintain enterprise network ...
Quick apply
Monitor system performance using programs such as Grafana, Graylog, Wazuh, and Uptime Kuma to ensure high availability, uptime, and security. * Design, configure, and maintain enterprise network ...
Tallahassee, FL · Remote
$85K - $100K/yr
Proficiency with tools such as Nessus, OpenVAS, Burp Suite, BloodHound, Kali Linux, Wazuh, Elastic Stack, Wireshark, and Nmap. * Familiarity with Microsoft security technologies including Active ...
Quick apply
Tallahassee, FL · Remote
$85K - $100K/yr
Proficiency with tools such as Nessus, OpenVAS, Burp Suite, BloodHound, Kali Linux, Wazuh, Elastic Stack, Wireshark, and Nmap. * Familiarity with Microsoft security technologies including Active ...
New Haven, CT · On-site
Perform vulnerability scanning, assessment, remediation, and penetration testing (e.g., Nessus, Wazuh). * Conduct risk assessments and recommend mitigation strategies to reduce exposure to cyber ...
New Haven, CT · On-site
Perform vulnerability scanning, assessment, remediation, and penetration testing (e.g., Nessus, Wazuh). * Conduct risk assessments and recommend mitigation strategies to reduce exposure to cyber ...
Palo Alto, CA · On-site
$168K/yr
SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...
Palo Alto, CA · On-site
$168K/yr
SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...
Experience with SIEM or security monitoring tools such as Splunk, QRadar, Rapid7, or Wazuh. * Strong analytical, troubleshooting, and communication skills. Preferred Qualifications * Experience ...
Quick apply
Experience with SIEM or security monitoring tools such as Splunk, QRadar, Rapid7, or Wazuh. * Strong analytical, troubleshooting, and communication skills. Preferred Qualifications * Experience ...
Austin, TX · Hybrid
$141K/yr
SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...
Quick apply
Austin, TX · Hybrid
$141K/yr
SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...
Mountain View, CA · On-site +1
$90K - $120K/yr
Monitor security alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems. * Conduct initial triage and investigation of potential security incidents. * Analyze logs ...
Mountain View, CA · On-site +1
$90K - $120K/yr
Monitor security alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems. * Conduct initial triage and investigation of potential security incidents. * Analyze logs ...
Arlington, VA · On-site
$110K - $170K/yr
Proficiency with SIEM tools (Wazuh, Splunk, SolarWinds Security Event Manager) * Experience with Cybersecurity tools (Tenable Security Center, Trellix ePO, Tanium, WSUS, RedHat Satellite) * Ability ...
Arlington, VA · On-site
$110K - $170K/yr
Proficiency with SIEM tools (Wazuh, Splunk, SolarWinds Security Event Manager) * Experience with Cybersecurity tools (Tenable Security Center, Trellix ePO, Tanium, WSUS, RedHat Satellite) * Ability ...
Washington, DC · Hybrid
$162K/yr
SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...
Quick apply
Washington, DC · Hybrid
$162K/yr
SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...
Maintain centralized logging pipelines (Splunk, Elastic/OpenSearch, or Wazuh) ingesting auditd, syslog, and application events * Develop correlation rules and alerts for STIG-required audit events ...
Maintain centralized logging pipelines (Splunk, Elastic/OpenSearch, or Wazuh) ingesting auditd, syslog, and application events * Develop correlation rules and alerts for STIG-required audit events ...
Mountain View, CA · On-site
$100 - $125/hr
Monitor security alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems. * Conduct initial triage and investigation of potential security incidents. * Analyze logs ...
Mountain View, CA · On-site
$100 - $125/hr
Monitor security alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems. * Conduct initial triage and investigation of potential security incidents. * Analyze logs ...
Mountain View, CA · On-site
Monitor security alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems. * Conduct initial triage and investigation of potential security incidents. * Analyze logs ...
Mountain View, CA · On-site
Monitor security alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems. * Conduct initial triage and investigation of potential security incidents. * Analyze logs ...
Bentonville, AR · Hybrid
$94K - $123K/yr
Using monitoring and analysis tools such as Datadog and Wazuh IDS to collect and analyze system performance metrics for capacity planning, proactive response, and troubleshooting. * The application ...
Bentonville, AR · Hybrid
$94K - $123K/yr
Using monitoring and analysis tools such as Datadog and Wazuh IDS to collect and analyze system performance metrics for capacity planning, proactive response, and troubleshooting. * The application ...
Camden, NJ · On-site
$150 - $200/hr
Operate and improve our observability stack (Datadog, Wazuh, Prometheus, Grafana) - dashboards, alert quality, SLOs, and reducing time-to-detection for market-impacting issues * Run and maintain ...
Camden, NJ · On-site
$150 - $200/hr
Operate and improve our observability stack (Datadog, Wazuh, Prometheus, Grafana) - dashboards, alert quality, SLOs, and reducing time-to-detection for market-impacting issues * Run and maintain ...
Experience with SIEM or security monitoring tools such as Splunk, QRadar, Rapid7, or Wazuh. * Strong analytical, troubleshooting, and communication skills. Preferred Qualifications * Experience ...
Experience with SIEM or security monitoring tools such as Splunk, QRadar, Rapid7, or Wazuh. * Strong analytical, troubleshooting, and communication skills. Preferred Qualifications * Experience ...
Tustin, CA · On-site
$100 - $125/hr
Experience with SIEM or security monitoring tools such as Splunk, QRadar, Rapid7, or Wazuh. * Strong analytical, troubleshooting, and communication skills. Preferred Qualifications * Experience ...
Tustin, CA · On-site
$100 - $125/hr
Experience with SIEM or security monitoring tools such as Splunk, QRadar, Rapid7, or Wazuh. * Strong analytical, troubleshooting, and communication skills. Preferred Qualifications * Experience ...
Camden, NJ · On-site
$57.50 - $76.50/hr
Operate and improve our observability stack (Datadog, Wazuh, Prometheus, Grafana) - dashboards, alert quality, SLOs, and reducing time-to-detection for market-impacting issues * Run and maintain ...
Camden, NJ · On-site
$57.50 - $76.50/hr
Operate and improve our observability stack (Datadog, Wazuh, Prometheus, Grafana) - dashboards, alert quality, SLOs, and reducing time-to-detection for market-impacting issues * Run and maintain ...
Cities with the most Wazuh job openings:
States with the most job openings for Wazuh jobs include:
The top searched job categories for Wazuh jobs are:

Full-time
Re-posted 8 days ago
Company Overview
Fortuna Cysec delivers unified cybersecurity operations through TheFense platform—our integrated MDR, SIEM, EDR, and response ecosystem designed for regulated industries, nonprofits, healthcare, education, and mission-driven organizations. Our global SOC/NOC operates 24×7×365, providing real-time visibility, rapid containment, and deep technical expertise across diverse customer environments.
We are expanding our Incident Response leadership team with a hands-on technical manager who thrives in fast-moving investigations and can guide customers through their most critical security events.
Role Summary
The Cybersecurity Incident Response Manager leads and directly participates in high-severity investigations across Fortuna Cysec’s customer base. This role blends technical depth, operational leadership, and customer-facing communication. You will serve as the senior escalation point for complex incidents, drive containment and remediation, and strengthen TheFense platform’s detection and response capabilities.
Lead and Execute Incident Response
· Command all phases of incident response—triage, investigation, containment, eradication, and recovery—while performing hands-on technical analysis.
· Analyze EDR telemetry, SIEM alerts, network logs, cloud audit logs, and identity events across Microsoft, AWS, and hybrid environments.
· Execute containment actions including endpoint isolation, identity disablement, MFA resets, OAuth token revocation, and firewall/network segmentation changes.
· Conduct forensic acquisition and analysis using Velociraptor, KAPE, FTK, EnCase, and Volatility.
· Reverse-engineer or sandbox suspicious binaries/scripts to determine behavior and impact.
· Lead hypothesis-driven threat hunts mapped to MITRE ATT&CK using TheFense’s unified telemetry.
Strengthen IR Operations
· Oversee daily IR operations across global SOC/NOC teams, ensuring SLA adherence and seamless follow-the-sun handoffs.
· Review and enhance IR playbooks, runbooks, and automated response actions within TheFense.
· Ensure high-quality incident documentation, evidence handling, and customer-ready reporting.
· Conduct root-cause analysis and deliver technically detailed post-incident reviews.
· Partner with engineering to refine detection logic, reduce false positives, and improve automation.
Engage Directly with Customers
· Serve as the technical authority during active breaches, guiding CISOs, IT directors, and executive stakeholders.
· Deliver clear, concise briefings that include attack path analysis, forensic findings, and prioritized remediation steps.
· Support customer teams with hands-on remediation across identity, cloud, endpoint, and email ecosystems.
· Provide strategic recommendations aligned with NIST, CIS Controls, and Fortuna Cysec best practices.
Advance Threat Intelligence and Detection
· Translate emerging threat intelligence into new detection rules, response playbooks, and threat-hunting queries.
· Validate detection logic through lab testing, simulated attacks, and historical telemetry review.
· Identify detection gaps and collaborate with TI teams to enrich investigations with IOCs and adversary behavior patterns.
Build Team and Platform Maturity
· Mentor analysts across global SOC/NOC teams in IR, forensics, cloud investigations, and threat hunting.
· Develop internal tooling and automation using Python or PowerShell.
· Participate in tabletop exercises, purple-team engagements, and breach simulations.
· Contribute to the evolution of TheFense platform by evaluating new telemetry sources and response capabilities.
Required Qualifications
Preferred Qualifications
Fortuna Cysec is an equal opportunity employer. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, pregnancy, age, sexual orientation, transgender status, gender identity, disability, alienage or citizenship status, marital status or partnership status, genetic information, veteran status or any other characteristic protected under applicable law.