Senior Cyber Incident Commander & Crisis Leader

Thrive

Capas

Hybrid

PHP 1,800,000 - 2,400,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Thrive is seeking a highly capable Incident Commander to lead critical security incident operations across the organization in a demanding environment. This role directs all activities and resources involved in a security incident, ensuring alignment across Thrive teams and client stakeholders.

The Incident Commander is the single point of accountability for the lifecycle of high-severity incidents—driving containment, eradication, recovery, and client communication with authority and clarity.

Qualifications

  • Proven incident response experience with demonstrated leadership of cross-functional security teams.
  • Proven success commanding high-impact cybersecurity incidents in a fast-paced, customer-facing environment.
  • Strong understanding of attack lifecycle stages, investigative workflows, and containment best practices.
  • Deep knowledge of modern attacker tactics and incident frameworks (MITRE ATT&CK, Cyber Kill Chain, NIST 800-61).
  • Excellent communication skills, with experience briefing clients, executives, and cross-disciplinary teams.
  • Familiarity with security tools (SIEM, EDR, forensic platforms), system/network architecture, incident response methodologies, and backup and disaster recovery plans.
  • Ability to multitask and make decisions quickly under pressure.

Responsibilities

  • Serve as the lead Incident Commander for complex or high-priority cybersecurity incidents, assuming control from initial scoping through post-incident review.
  • Act as the central coordination point across all parties engaged in security incidents
  • Ensure that all internal actions are synchronized, prioritized, and in alignment with client needs and Thrive’s incident response methodology.
  • Set the operational tempo, assign task owners, and communicate timelines, dependencies, and roadblocks in real-time.
  • Drive incident lifecycle management with a focus on containment, minimizing business disruption, and maintaining security assurance.
  • Maintain clear, structured communication with client stakeholders and Thrive leadership, including updates on threat actor behavior, system impact, business risk, and required decisions.
  • Lead conference bridges during incident response, ensuring everyone is aligned and progressing toward resolution.
  • Approve restoration plans, re-entry conditions, and sequencing to minimize risk of re-compromise.
  • Serve as the public face of Thrive during a cybersecurity crisis, guiding clients with authority and confidence through incident containment and recovery.
  • Provide real-time risk assessments and business impact updates to client executive teams, IT leads, and legal stakeholders.
  • Assist clients in coordination with cyber insurance or legal counsel when applicable.
  • Advocate for long-term maturity improvements post-incident, helping position Thrive as a trusted partner.
  • Continually enhance Thrive’s playbooks, escalation frameworks, and IR documentation based on lessons learned from real-world incidents.
  • Lead internal after-action reviews and root cause analysis meetings with technical teams and business units.
  • Partner with Security Engineering to validate detection coverage and response automation opportunities.
  • Conduct tabletop with internal Thrive teams to test and improve readiness for various threat scenarios.
  • Promote a strong, communicative culture of shared accountability and post-incident learning across all Thrive teams.

Skills

Incident response leadership
Leadership of high-impact incidents
Attack lifecycle understanding
MITRE ATT&CK / NIST 800-61 knowledge
Client/executive briefing
Security tools familiarity
Multitasking under pressure

Tools

SIEM
EDR
Forensic platforms

Job description

Thrive is seeking a highly capable Incident Commander to lead critical security incident operations across the organization in a demanding environment. This role directs all activities and resources involved in a security incident, ensuring alignment across Thrive teams and client stakeholders.

The Incident Commander is the single point of accountability for the lifecycle of high-severity incidents—driving containment, eradication, recovery, and client communication with authority and clarity.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Incident Commander
Senior Cybersecurity Incident Commander

Thrive • Mabalacat

On-site
PHP 900,000 - 1,600,000
Cyber Incident Command Lead
Cyber Incident Command Lead

Thrive • Tarlac City

On-site
PHP 1,200,000 - 1,800,000
Cybersecurity Incident Commander - CIRT
Cybersecurity Incident Commander - CIRT

Thrive • Tarlac City

On-site
PHP 1,200,000 - 1,800,000
Cybersecurity Incident Commander - CIRT
Cybersecurity Incident Commander - CIRT

Thrive • Capas

Hybrid
PHP 1,800,000 - 2,400,000
Cybersecurity Incident Commander - CIRT
Cybersecurity Incident Commander - CIRT

Thrive • Mabalacat

On-site
PHP 900,000 - 1,600,000
SOC Analyst I: Frontline Threat Monitoring & Response
SOC Analyst I: Frontline Threat Monitoring & Response

Thrive • Capas

Hybrid
PHP 300,000 - 540,000
SOC Analyst
SOC Analyst

Thrive • Capas

Hybrid
PHP 300,000 - 540,000
Hybrid Incident Commander — Lead Major IT Incidents
Hybrid Incident Commander — Lead Major IT Incidents

weSource Management Consultancy Firm • Taguig

Hybrid
PHP 130,000 - 153,000
Security Engineer - Remediation
Security Engineer - Remediation

Thrive • Capas

Hybrid
PHP 700,000 - 1,100,000
Security Engineer - Remediation (Vulnerability Response)
Security Engineer - Remediation (Vulnerability Response)

Thrive • Capas

Hybrid
PHP 700,000 - 1,100,000