Cyber Incident Response - Lead Position

Nexlogica

Downey (CA)

On-site

USD 100,000 - 130,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Nexlogica is seeking an IT Security Incident Response Manager in Downey, CA to oversee incident response processes. This position requires experience in incident documentation, first responder analysis, and managing business-impacting situations. Candidates should have a Bachelor’s degree in a technology-related field and a minimum of three years of experience in a complex security environment.

The ideal candidate will have strong communication abilities, lead containment strategies, and ensure timely reports to management. Certifications like CISSP or CISM are desired.

Qualifications

  • Experience documenting incident response processes.
  • Experience in forensics analysis and investigation.
  • Experience triaging and resolving advanced threats.
  • Experience leading during business-impacting situations.
  • Strong communication skills during incident management.
  • Ability to manage high severity incidents with stakeholders.
  • Experience driving containment strategies during breaches.
  • Experience maintaining evidence chain of custody.
  • Experience bringing incidents to closure.
  • Experience providing recommendations to prevent future incidents.
  • Ability to develop restoration procedures.
  • Experience providing final incident reports to management.
  • Experience collaborating with IT teams to identify root causes.
  • On-call availability for 24/7 coverage.

Skills

Incident response documentation
Forensics analysis
Triage and advanced vector attacks response
Cross-functional cooperation
Timely communication
Data asset management
Containment strategy driving
Chain of custody documentation
Post-containment recovery
Incident prevention recommendations
Restoration procedures development
Reporting to executive management
Collaboration with IT teams
On-call availability

Education

Bachelor’s degree in Computer Science/Engineering/Information Systems

Tools

Microsoft PowerPoint

Job description

Job ID# 10059 – Posted 5/19/22 – Downey CA

Skills Preferred
  • Experience with documenting incident response process and procedures.
  • Experience with first responder forensics analysis and investigation.
  • Experience with triage and resolving advanced vector attacks such as botnets and advanced persistent threats (APTs).
  • Experience as the leas during business impacting situations, and work to restore normal service operations in cooperation with cross‑functional partners.
  • Advanced skills in timely communications and updates are provided for incident management and root‑cause scenarios.
  • Ability to work directly with data asset owners and business response plan owners during high severity events of interest; leads the effort on messaging and communication related to incident reporting for all audiences.
  • Experience driving containment strategy during data loss or breach events.
  • Experience with the documentation and maintaining chain of custody of incident evidence.
  • Experience driving post‑containment recovery effort through to complete incident closure.
  • Should work with teams to provide recommendations to resolve and/or reduce impact of incident and to prevent future similar incidents.
  • Develop and enrich restoration procedures to mitigate future outages and business disruptions. a. Experience providing written final incident report to executive management that provide; assessing scope of incident damage and assisting in the determination of incident severity; document activities such as investigation, discovery and recovery during the incident.
  • Experience with collaborating with departmental IT team to identify the root cause of recurring incidents and create action‑plans for remediate and prevent recurring situations.
  • Maintain on‑call availability for 24x7x365 coverage.
Experience Preferred
  • One or more of the following professional certifications requited: Qualified Security Assessor (QSA), Certified Information Systems Auditor (CISA), Certified Information Systems Security Professionals (CISSP), Certified Information Security Manager (CISM), Certified Information Privacy Professional (CIPP), GIAC Certified Incident Handler (GCIH) or GIAC Network Forensic Analyst.
  • Desired of three (3) years’ experience in the last five (5) years as an IT Security Incident Response Manager, supporting a complex enterprise security environment for a large public or private organization.
  • Desired of three (3) years of experience in the past five (5) years as an IT Security Incident Response Manager, supporting Enterprise Multi‑Tenant environment, including responding, containing, remediating, and reporting on the infrastructure connecting to large private or public organization and Public Cloud Providers, such as AWS, Azure and/or GCP.
  • Minimum of two (2) years’ experience in the last three (3) years analyzing, responding, and remediating enterprise network & security architectures.
  • Minimum of two (2) years’ experience in the last three (3) years leading IT Security/Information Security teams.
  • Minimum of two (2) years’ experience in the last three (3) years delivering Incident Reports and Remediation Recommendations in a large enterprise organization.
  • Demonstrated ability to create clear, concise technical documentations such as procedures, Visio diagrams, and system support documents, and strong presentation skills with experience using Microsoft PowerPoint.
Education Required

Bachelor’s degree from an accredited college in a technology‑related discipline (e.g., Computer Science, Engineering, Information Systems, etc.) or equivalent experience/combined education.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Incident Response Lead
IT Incident Response Lead

Nexlogica • Downey (CA)

On-site
USD 140,000 - 170,000
Incident Manager I
Incident Manager I

Solutions³ LLC • Virginia (MN)

On-site
USD 85,000 - 105,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Sr. Lead Incident Response / Supervisor Level 5
Sr. Lead Incident Response / Supervisor Level 5

WaveStrong, Inc. • Dallas (TX)

On-site
USD 140,000 - 190,000
Sr. Lead Incident Response / Supervisor Level 5
Sr. Lead Incident Response / Supervisor Level 5

WaveStrong, Inc. • Town of Texas (WI)

On-site
USD 100,000 - 130,000
Incident Response Manager
Incident Response Manager

Crowe LLP • United States

On-site
USD 120,000 - 150,000
Incident Manager I
Incident Manager I

Solutions³ LLC • Arlington (VA)

On-site
USD 90,000 - 130,000
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

INSPYR Solutions • California (MO)

Remote
USD 100,000 - 130,000
Senior Incident Response Lead & Forensics Expert
Senior Incident Response Lead & Forensics Expert

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Cybersecurity Incident Responder
Cybersecurity Incident Responder

DivIHN Integration Inc • Saint Paul (MN)

On-site
USD 70,000 - 100,000