Incident Response Manager

Crowe LLP

United States

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Crowe LLP is looking for an Incident Response Manager to oversee complex cybersecurity incidents. As a senior technical leader, you will manage engagements and mentor incident responders while acting as a trusted advisor to clients during crises.

This role requires 7+ years of experience and strong leadership skills in incident response and digital forensics, alongside expertise in tools like SIEM and EDR platforms. The position also involves business development and contribution to thought leadership.

Qualifications

  • 7+ years of cybersecurity experience, including incident response.
  • Strong understanding of networking, operating systems, and cloud security.
  • Experience managing project teams and mentoring staff.

Responsibilities

  • Lead incident response engagements and manage client relationships.
  • Conduct forensic investigations and threat hunting activities.
  • Develop and maintain incident response methodologies and playbooks.

Skills

Cybersecurity experience
Incident response
Leadership
Communication skills
Scripting and automation

Education

Relevant certifications such as GCFA, GCIH, CISSP

Tools

SIEM platforms (Splunk, Microsoft Sentinel)
EDR platforms (CrowdStrike, Microsoft Defender)

Job description

Incident Response Manager

The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders, overseeing engagement delivery, and acting as a trusted advisor to clients during cybersecurity crises.

Responsibilities
  • Serve as the primary client-facing leader during major cybersecurity incidents.
  • Lead multiple concurrent incident response engagements involving ransomware, data breaches, insider threats, cloud compromises, and advanced threat actor activity.
  • Provide executive-level briefings to CISOs, CIOs, legal counsel, executive leadership, boards of directors, and other stakeholders.
  • Direct forensic investigations, threat hunting activities, containment efforts, eradication plans, and recovery operations.
  • Review and approve technical findings, investigation reports, executive summaries, and client deliverables.
  • Coordinate internal and external resources to ensure successful engagement execution and client outcomes.
  • Ensure investigations meet legal, regulatory, and evidentiary requirements.
  • Develop and maintain incident response methodologies, playbooks, procedures, and service offerings.
  • Lead and mentor Incident Response consultants and senior staff through coaching, technical guidance, and performance feedback.
  • Assist with recruiting, onboarding, and professional development of team members.
  • Support business development efforts through proposal development, scoping, client presentations, and strategic discussions.
  • Identify opportunities to expand client relationships and deliver additional cybersecurity services.
  • Contribute to thought leadership through whitepapers, webinars, conference presentations, and market-facing content.
Requirements
  • 7+ years of cybersecurity experience with at least 3 years focused on incident response, digital forensics, threat hunting, or cyber defense operations.
  • Demonstrated experience leading complex incident response engagements from initial detection through recovery.
  • Experience managing project teams, mentoring technical staff, and coordinating cross-functional stakeholders.
  • Strong leadership, decision-making, and risk management capabilities.
  • Excellent communication skills with the ability to present technical findings to executive and non-technical audiences.
  • Ability to manage competing priorities and multiple concurrent engagements.
  • Strong understanding of networking, operating systems, identity systems, cloud technologies, and cybersecurity principles.
  • Experience utilizing SIEM platforms such as Splunk, Elastic, Microsoft Sentinel, or FortiSIEM.
  • Experience utilizing EDR platforms such as CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, or Carbon Black.
  • Proficiency with scripting and automation using PowerShell, Python, Bash, or similar technologies.
  • Strong documentation and report-writing capabilities.
  • Willingness to travel approximately 15% or more as required.
Preferred Qualifications
  • Expert knowledge of Windows, Linux, Active Directory, Microsoft Entra ID, Microsoft 365, AWS, Azure, and Google Cloud environments.
  • Advanced understanding of attacker tactics, techniques, and procedures (MITRE ATT&CK).
  • Experience leading enterprise-scale ransomware investigations and recovery efforts.
  • Experience coordinating legal counsel, cyber insurance carriers, law enforcement, and third-party stakeholders during incidents.
  • Experience developing incident response programs, tabletop exercises, and cyber resilience strategies.
  • Experience managing consulting engagements and project financials.
  • Experience building and managing cybersecurity teams.
  • Relevant certifications such as GCFA, GCIH, GCED, GREM, GCTD, CISSP, CCSP, CISM, AWS Security Specialty, or Azure Security Engineer Associate.
Employment Information

Application deadline for this role is 09/30/2026.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

We provide equal employment opportunities to all employees and applicants for employment and prohibit discrimination and harassment of any type without regard to race, color, religion, age, sex, sexual orientation, gender identity or expression, genetics, national origin, disability or protected veteran status, or any other characteristic protected by federal, state or local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Manager
Incident Response Manager

Jobtailor • Colorado

On-site
USD 140,000 - 210,000
Sr. Cyber Defense Analyst
Sr. Cyber Defense Analyst

Patriot Talent Solutions • United States

On-site
USD 120,000 - 190,000
Cyber Incident Responder
Cyber Incident Responder

Meriplex-Communication • Town of Texas (WI)

On-site
USD 110,000 - 160,000
Incident Response Manager
Incident Response Manager

Fortuna Cysec • Atlanta (GA)

On-site
USD 100,000 - 150,000
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

INSPYR Solutions • California (MO)

Remote
USD 100,000 - 130,000
Cyber Incident Responder
Cyber Incident Responder

Meriplex • Town of Texas (WI)

On-site
USD 120,000 - 180,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Incident Response Team Lead
Incident Response Team Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 155,000 - 180,000
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MFI Technologies Incorporated • New York (NY)

On-site
USD 75,000 - 100,000