Назад
Company hidden
41 ΠΌΠΈΠ½ΡƒΡ‚Ρƒ Π½Π°Π·Π°Π΄

Manager, Incident Response (Cybersecurity)

132Β 410 - 165Β 510$
Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
remote (Ρ‚ΠΎΠ»ΡŒΠΊΠΎ USA)/hybrid/onsite
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
senior
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
US
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Manager, Incident Response (Cybersecurity): Leading and maturing an incident response team responsible for detecting, containing, investigating, and eradicating advanced threats across modern enterprise infrastructure with an accent on people leadership, crisis management, and operational metrics. Focus on governing complex incident lifecycles, developing automated response playbooks, analyzing AWS and SIEM telemetry, and converting post-incident findings into stronger detections and architecture.

Location: Remote, United States of America; location-flexible work may also include office or hybrid arrangements subject to eligible US location restrictions.

Salary: $132,410–$165,510 base salary annually, with bonus and equity eligibility.

Company

hirify.global provides family history and personal DNA products that help people discover, preserve, and share their family stories through large-scale records, science, and technology.

What you will do

  • Lead, mentor, and develop incident response engineers, threat hunters, and forensic analysts while supporting psychological safety and sustainable team performance.
  • Govern the end-to-end response lifecycle for high-impact enterprise security incidents, including triage, containment, forensics, eradication, and recovery.
  • Establish and analyze operational metrics such as MTTD, MTTR, and true-positive and false-positive ratios, presenting risk-focused updates to leadership.
  • Coordinate major incident response and translate technical findings into actionable summaries for leadership, legal counsel, and public relations.
  • Lead root-cause reviews and turn lessons learned into improved detections, architecture, and operational processes.
  • Develop and mature incident response runbooks and automation workflows to reduce containment timelines.

Requirements

  • 3+ years of direct people management and mentoring experience with incident response professionals.
  • 6+ years of hands-on enterprise incident response, digital forensics, and advanced blue team operations.
  • Strong understanding of attacker tactics, techniques, and procedures, threat actor motivations, and MITRE ATT&CK detection mapping.
  • Experience with enterprise EDR/XDR, AWS security capabilities including CloudTrail, GuardDuty, and IAM, SIEM, SOAR, and DFIR tools.
  • Proven ability to remain composed during high-stress incidents, lead cross-functional teams, and communicate clearly with technical and non-technical stakeholders.
  • Familiarity with AI tools and large language models for productivity and technical workflows.

Nice to have

  • Advanced Elasticsearch search, data correlation, and analytics optimization for incident investigations.
  • AI-driven security process optimization, documentation, runbook creation, or scripting workflows.
  • GIAC certifications such as GCIH, GCFA, or GNFA, or CISSP or CISM certification.
  • Purple Team exercises, tabletop simulations, and Red Team collaboration.
  • Cloud forensics experience with Kubernetes, Docker, or serverless environments.

Culture & Benefits

  • Human-centered, inclusive, and diverse work environment.
  • Choice of working from home, an eligible office, or a hybrid arrangement, subject to US location restrictions and role requirements.
  • Comprehensive health, dental, and vision benefits.
  • Bonus and equity eligibility.
  • Commitment to pay transparency, pay equity, and equal employment opportunity.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’