Manager, Incident Response (Cybersecurity)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Location: Remote, United States of America; location-flexible work may also include office or hybrid arrangements subject to eligible US location restrictions.
Salary: $132,410β$165,510 base salary annually, with bonus and equity eligibility.
Company
provides family history and personal DNA products that help people discover, preserve, and share their family stories through large-scale records, science, and technology.
What you will do
- Lead, mentor, and develop incident response engineers, threat hunters, and forensic analysts while supporting psychological safety and sustainable team performance.
- Govern the end-to-end response lifecycle for high-impact enterprise security incidents, including triage, containment, forensics, eradication, and recovery.
- Establish and analyze operational metrics such as MTTD, MTTR, and true-positive and false-positive ratios, presenting risk-focused updates to leadership.
- Coordinate major incident response and translate technical findings into actionable summaries for leadership, legal counsel, and public relations.
- Lead root-cause reviews and turn lessons learned into improved detections, architecture, and operational processes.
- Develop and mature incident response runbooks and automation workflows to reduce containment timelines.
Requirements
- 3+ years of direct people management and mentoring experience with incident response professionals.
- 6+ years of hands-on enterprise incident response, digital forensics, and advanced blue team operations.
- Strong understanding of attacker tactics, techniques, and procedures, threat actor motivations, and MITRE ATT&CK detection mapping.
- Experience with enterprise EDR/XDR, AWS security capabilities including CloudTrail, GuardDuty, and IAM, SIEM, SOAR, and DFIR tools.
- Proven ability to remain composed during high-stress incidents, lead cross-functional teams, and communicate clearly with technical and non-technical stakeholders.
- Familiarity with AI tools and large language models for productivity and technical workflows.
Nice to have
- Advanced Elasticsearch search, data correlation, and analytics optimization for incident investigations.
- AI-driven security process optimization, documentation, runbook creation, or scripting workflows.
- GIAC certifications such as GCIH, GCFA, or GNFA, or CISSP or CISM certification.
- Purple Team exercises, tabletop simulations, and Red Team collaboration.
- Cloud forensics experience with Kubernetes, Docker, or serverless environments.
Culture & Benefits
- Human-centered, inclusive, and diverse work environment.
- Choice of working from home, an eligible office, or a hybrid arrangement, subject to US location restrictions and role requirements.
- Comprehensive health, dental, and vision benefits.
- Bonus and equity eligibility.
- Commitment to pay transparency, pay equity, and equal employment opportunity.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β