Cyber Security Incident Response Lead

Staples Advantage Canada

Framingham (MA)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

PTO 22 days + holidays
401(k) matching
Wellness programs
Employee discounts

Job summary

Staples Digital Solutions in Framingham, MA seeks a Senior Cyber Security Incident Response Lead to own complex investigations and drive incident response across endpoints, identity, cloud, and network. You'll mentor teams, establish playbooks, and push threat-hunting initiatives.

The role requires strong technical judgment, collaboration, and the ability to translate findings into business risk. Relocation support is considered as needed.

Qualifications

  • Bachelor’s degree or equivalent work experience.
  • 7+ years of cybersecurity experience in IR, forensics, threat hunting or SOC.
  • Experience conducting complex investigations in large enterprise environments.
  • Experience developing or maintaining IR plans, procedures, playbooks, exercises, metrics.

Responsibilities

  • Lead complex investigations from escalation through containment and recovery.
  • Analyze telemetry across endpoint, identity, cloud, network, and email.
  • Provide senior technical guidance during major incidents.
  • Coordinate response activities across multiple teams and external partners.
  • Develop and improve IR plans, playbooks, and drills.
  • Conduct proactive threat hunting based on intelligence and anomalies.
  • Support insider risk investigations and data loss concerns.
  • Document findings and lessons learned from post-incident reviews.
  • Collaborate with Detection Engineering and Threat Intelligence to improve detection.
  • Participate in on-call escalation rotation for significant incidents.

Skills

Advanced investigation
Analytical thinking
Technical judgment
Communication skills
Collaboration
Threat intelligence
Incident response
On-call escalation

Education

Bachelor’s degree or equivalent

Tools

Microsoft Defender XDR
Microsoft Sentinel
Microsoft Defender for Endpoint
Microsoft Entra ID
SOAR
SIEM

Job description

Staples Digital Solutions is strengthening its cyber defense capabilities, and we’re looking for a senior technical incident response professional to help protect our associates, customers, data, and enterprise technology environment. This role sits within Cyber Security and partners closely with Security Operations, Infrastructure, Cloud, Identity, Legal, Privacy, Risk, Human Resources, and other teams to respond to complex and high-impact cybersecurity events. Based in Framingham, MA, this opportunity reports to the Director of Security Operations and operates as a senior individual contributor with meaningful influence across the enterprise.

As a Cyber Security Incident Response Lead, you’ll serve as a senior technical escalation resource for significant cybersecurity incidents across Staples. You’ll lead hands‑on investigation and response activities across endpoint, identity, cloud, network, email, and security telemetry to determine threat scope, business impact, root cause, and recommended response actions. You’ll also help mature the incident response program by improving playbooks, exercises, metrics, processes, threat‑hunting practices, detection recommendations, and automation opportunities.

Role requires the incumbent to work at our Framingham, MA facility but we are open to candidates that are willing to relocate to the area. We will also consider providing relocation assistance.

What you’ll be doing:
  • Conduct complex cybersecurity investigations from initial escalation through containment, eradication, recovery, and post-incident review.
  • Analyze endpoint, identity, cloud, network, email, and log‑based telemetry to identify attacker activity, determine incident scope, and assess potential impact.
  • Provide senior technical guidance during significant incidents in partnership with SOC Leads and Managers.
  • Coordinate response activities across Cyber Security, Infrastructure, Cloud, Identity, Legal, Privacy, GRC, Human Resources, external partners, and other business and technology teams.
  • Develop and continuously improve incident response plans, investigative procedures, escalation processes, playbooks, exercises, metrics, and supporting documentation.
  • Conduct proactive threat hunting based on threat intelligence, vulnerabilities, anomalous activity, and observed adversary techniques.
  • Support insider risk investigations involving suspicious user behavior, misuse of access, data loss, or potentially malicious internal activity.
  • Document investigation findings, lessons learned, recurring risks, and improvement opportunities from post‑incident reviews.
  • Partner with Detection Engineering, Threat Intelligence, and security technology teams to improve detection coverage, investigative capabilities, and automation.
  • Participate in an on‑call escalation rotation for significant cybersecurity incidents requiring senior technical expertise.
What you bring to the table:
  • Advanced technical investigation, analytical, and problem‑solving skills.
  • Sound technical judgment and the ability to make recommendations using incomplete or evolving information.
  • Ability to support complex cybersecurity incidents calmly and effectively under pressure.
  • Strong written and verbal communication skills, including the ability to translate technical findings into clear business risk considerations and recommended actions.
  • Strong collaboration skills across technical and non‑technical teams.
  • Curiosity and initiative to identify improvements within the incident response discipline.
  • Strong understanding of evolving attacker behaviors, techniques, and technologies.
  • Discretion and sound judgment when handling sensitive investigations, including potential insider risk matters.
  • Ability to participate in an on‑call escalation rotation for significant cybersecurity incidents.
What’s needed- Basic Qualifications:
  • Bachelor’s degree in Computer Science, Information Security, a related field or equivalent work experience.
  • 7+ years of cybersecurity experience, including incident response, digital forensics, threat hunting, detection engineering, or Security Operations.
  • Experience conducting complex cybersecurity investigations in large enterprise environments.
  • Experience developing or maintaining incident response plans, procedures, playbooks, exercises, metrics, or supporting processes.
  • Experience conducting post‑incident reviews, root cause analysis, or lessons‑learned documentation.
  • Experience coordinating technical response activities across multiple technology and business teams.
What’s needed- Desired Qualifications:
  • Experience within larger distributed enterprise environments, ideally retail and/or e-commerce.
  • Advanced technical training or relevant cybersecurity certifications such as GCIH, GCFA, GCFE, GNFA, CISSP.
  • Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Endpoint, or Microsoft Entra ID.
  • Experience with SOAR platforms and automated incident response workflows.
  • Hands‑on experience investigating endpoint, identity, cloud, network, email, or log‑based security telemetry.
  • Hands‑on experience using SIEM, EDR/XDR, identity security, cloud security monitoring, or security automation technologies.
  • Experience conducting enterprise threat hunting or developing detection content.
  • Experience supporting insider risk, user behavior, data loss, or other user‑focused security investigations.
  • Experience investigating identity‑based or cloud‑based attacks.
  • Experience responding to ransomware, credential compromise, business email compromise, insider threats, data theft, or supply‑chain incidents.
  • Knowledge of cybersecurity incident response requirements, including PCI DSS and applicable privacy requirements.
What’s needed- Desired Qualifications:
  • Advanced technical training or relevant cybersecurity certifications such as GCIH, GCFA, GCFE, GNFA, CISSP.
  • Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Endpoint, or Microsoft Entra ID.
  • Experience with SOAR platforms and automated incident response workflows.
  • Experience conducting enterprise threat hunting or developing detection content.
  • Experience supporting insider risk, user behavior, data loss, or other user‑focused security investigations.
  • Experience investigating identity‑based or cloud‑based attacks.
  • Experience responding to ransomware, credential compromise, business email compromise, insider threats, data theft, or supply‑chain incidents.
  • Knowledge of cybersecurity incident response requirements, including PCI DSS and applicable privacy requirements.
  • Experience within large retail, e‑commerce, or distributed enterprise environments.
We Offer:
  • Inclusive culture with associate‑led Business Resource Groups
  • 22 days of PTO and Holiday Schedule (7 observed paid holidays + 1 floating holiday)
  • Online and Retail Discounts, Company Match 401(k), Physical and Mental Health Wellness programs, and more!

The salary range represents the expected compensation for this role at the time of posting. The specific base pay may be influenced by a variety of factors to include the candidate's experience, skill set, education, geography, business considerations, and internal equity. In addition to base pay, this role may be eligible for bonuses, or other forms of variable compensation.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Incidence Response Lead
Cyber Security Incidence Response Lead

Staples Advantage Canada • Framingham (MA)

On-site
USD 140,000 - 180,000
Inclusive culture with ERGs
22 days PTO + holidays
Company discounts & 401(k) match
Lead Cyber Security Analyst
Lead Cyber Security Analyst

Staples Advantage Canada • Framingham (MA)

On-site
USD 120,000 - 170,000
Flexible PTO
Holiday & wellness programs
Employee discounts
Lead Cyber Security Analyst
Lead Cyber Security Analyst

Staples • Framingham (MA)

On-site
USD 130,000 - 170,000
Inclusive BRGs
Flexible PTO
Holiday schedule + floating holiday
+2
Cyber Fraud Analyst II
Cyber Fraud Analyst II

Staples • Framingham (MA)

On-site
USD 85,000 - 115,000
Inclusive culture
Flexible PTO
Employee discounts
Enterprise Security Operations Center Supervisor
Enterprise Security Operations Center Supervisor

Staples • Framingham (MA)

Hybrid
USD 90,000 - 120,000
22 days PTO
Employee discounts
401(k) match
+1
Cyber Fraud Analyst II
Cyber Fraud Analyst II

Staples Advantage Canada • Framingham (MA)

On-site
USD 90,000 - 120,000
Flexible PTO
Discounts on products
Company 401(k) match
Enterprise Security Operations Center Supervisor
Enterprise Security Operations Center Supervisor

Staples Advantage Canada • Framingham (MA)

Hybrid
USD 110,000 - 150,000
22 days PTO
Company match 401(k)
Wellness programs
Senior Cyber Incident Response Lead: Threat Hunter & Responder
Senior Cyber Incident Response Lead: Threat Hunter & Responder

Staples Advantage Canada • Framingham (MA)

On-site
USD 140,000 - 180,000
Inclusive culture with ERGs
22 days PTO + holidays
Company discounts & 401(k) match
Senior Cyber Incident Response Lead - Relocation Included
Senior Cyber Incident Response Lead - Relocation Included

Staples Advantage Canada • Framingham (MA)

On-site
USD 140,000 - 190,000
PTO 22 days + holidays
401(k) matching
Wellness programs
+1
Technical Engineer II- Retail Infrastructure
Technical Engineer II- Retail Infrastructure

Socket.dev • Framingham (MA)

On-site
USD 90,000 - 120,000
Bonus plan
Flexible work hours
401(k) with company match
+1