Cyber Incident Responder

Canopius Group

Chicago (IL)

On-site

USD 75,000 - 88,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Canopius Group is seeking an Incident Manager for its 24/7 CIMT to triage and lead cyber incident responses across the globe. You will coordinate experts, manage containment to restoration, and communicate clearly to policyholders under pressure.

You’ll work with Claims, Underwriting and Analytics to capture lessons, improve playbooks, and ensure SLAs are met across regions including Chicago, Sydney and London.

Qualifications

  • A minimum of two years working in cybersecurity, ideally with incident handling or response experience.
  • Clear ability to communicate technical concepts to non‑technical audiences.

Responsibilities

  • Own the incident from notification to closure, triage, and define the response plan.
  • Orchestrate vendors and manage timelines, decisions and next steps.
  • Collaborate with Claims, Underwriting and Analytics to provide insights and post‑incident summaries.

Skills

Cybersecurity
Incident handling
Threat behaviors
Problem solving
Communication
Data skills
Empathy & composure

Tools

Excel
Power BI
SQL
Python

Job description

The Role

Canopius is a market ‑ leading cyber insurer with an in ‑ house Cyber Incident Management Team (CIMT) that delivers immediate, expert support to our policyholders during their most critical moments. As an Incident Manager, you’ll be the first point of contact when a client faces a cyber event—whether business email compromise, ransomware, social engineering, data theft, or other attacks. You will triage and lead the response, mobilize our expert panel (forensics, legal, PR, and specialist advisors), and project ‑ manage recovery from containment through restoration, providing calm, clear communication throughout.

Job Description

Operating in a global, follow ‑ the ‑ sun model across Sydney, London, and Chicago, you’ll ensure true 24/7 coverage for new notifications, collaborate closely with our Claims team to support timely coverage assessment, and help clients navigate local legal and regulatory obligations. Sitting at the coal face of live incidents, you’ll also capture structured insights and trends that inform our underwriting, analytics, and ongoing service evolution, all while meeting and exceeding internal SLAs.

Responsibilities
  • Own the incident from notification to closure
    • Be the first point of contact for policyholder incident notifications.
    • Rapidly triage, assess severity, and set the response plan and cadence.
    • Orchestrate specialist vendors (IR firms, forensics, legal, PR, ransom advisors), ensuring right‑sized support at the right time.
    • Maintain clear timelines, decisions, and next steps
  • Deliver best in class customer service‑in‑class customer service
    • Provide calm, empathetic guidance under pressure; translate technical issues into clear business impact and options.
    • Set and manage expectations on milestones (containment, restoration, notifications) and costs.
    • Conduct welcome/onboarding calls; explain how to notify, what to expect, and how the IR panel operates.
    • Capture and act on policyholder feedback to continuously improve service.
    • Hit internal SLAs (acknowledgement, triage, vendor mobilization, comms cadence).
  • Operate within a global, 24/7 team model
    • Participate in rota/on call coverage to ensure true follow the sun response. ‑call coverage to ensure true follow‑the‑sun response.
    • Perform structured handovers across regions; maintain accurate case notes and status.
  • Evolve the service offering
    • Contribute to playbook/runbook enhancements and decision trees (e.g., ransomware, BEC, DDoS, data exfil).
    • Recommend panel/vendor improvements and measure vendor SLAs and outcomes.
    • Support content development (guides, FAQs, tabletop scenarios).
  • Collaborate with Claims, Underwriting and Insights & Analytics
    • Partner with the Claims team to ensure smooth coverage confirmation and claim handling.
    • Surface material facts, costs, and causation signals; ensure incident files are complete and timely.
    • Escalate complex matters promptly and appropriately.
    • Sit “at the coal face” of live incidents and distil timely, high-quality insights (threat vectors, controls efficacy, vendor performance, and industry signals). ‑quality insights (threat vectors, controls efficacy, vendor performance,
    • Provide structured post incident summaries and trend themes for underwriters and leadership. ‑incident summaries and trend themes for underwriters and leadership.
    • Ensure precise, consistent capture of incident metadata and outcomes (e.g., root cause, initial access, controls in place, dwell time, MTTA/MTTR, costs).
    • Champion data quality standards; work with Analytics to refine taxonomies and dashboards.
    • Collaborate in delivery of incident preparedness sessions, tabletops, and executive simulations for insureds. ‑deliver incident preparedness sessions, tabletops, and executive simulations for insureds.
    • Feed real world lessons learned into control uplift recommendations. ‑world lessons learned into control uplift recommendations.
Skills And Experience
  • A minimum of two years working in the cybersecurity field, ideally with hands ‑ on involvement in incident handling or response activities.
  • Strong foundational knowledge of cyber ‑ attack methods, threat behaviors, and the end ‑ to ‑ end lifecycle of incident response.
  • Demonstrate ability to solve complex problems and make sound judgements quickly, especially when operating in high pressure or fastmoving situations. ‑pressure or fast‑moving situations.
  • Excellent organisational habits with a focus on accuracy and thoroughness in all tasks.
  • Clear and confident communication skills—both written and verbal— with the capability to explain technical issues in an accessible way for non-technical audiences. ‑technical audiences.
  • Basic data skills to partner with Analytics (e.g., Excel/Power BI; familiarity with SQL/Python advantageous).
  • High empathy, composure under pressure, and a service mindset.

Salary Range: $75,000 - 87,500

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Incident Responder
Senior Cyber Incident Responder

vavemga • Chicago (IL)

On-site
USD 95,000 - 115,000
Senior Cyber Incident Responder
Senior Cyber Incident Responder

Canopius Group • Chicago (IL)

Hybrid
USD 95,000 - 115,000
Hybrid working
Competitive base salary
Discretionary bonus
+1
Senior Cyber Incident Responder
Senior Cyber Incident Responder

Canopius • Chicago (IL)

Hybrid
USD 95,000 - 115,000
Hybrid working model
Competitive benefits package
Global Cyber Incident Lead – Response & Recovery
Global Cyber Incident Lead – Response & Recovery

Canopius • Chicago (IL)

Hybrid
USD 95,000 - 115,000
Hybrid working model
Competitive benefits package
Cyber Incident Responder - 24/7 Global Crisis Lead
Cyber Incident Responder - 24/7 Global Crisis Lead

Canopius Group • Chicago (IL)

On-site
USD 75,000 - 88,000
Incident Response Senior Manager
Incident Response Senior Manager

Cognizant • Frankfort (KY)

Remote
USD 135,000 - 145,000
Incident Response Senior Manager
Incident Response Senior Manager

Cognizant • Annapolis (MD)

Remote
USD 135,000 - 145,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
401(k) plan and contributions
+3
Cyber Defense Incident Responder - Associate Director
Cyber Defense Incident Responder - Associate Director

Ernst & Young Advisory Services Sdn Bhd • Hoboken (NJ)

On-site
USD 140,000 - 210,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MFI Technologies Incorporated • New York (NY)

On-site
USD 75,000 - 100,000
Incident Response Manager
Incident Response Manager

Crowe LLP • United States

On-site
USD 120,000 - 150,000