Incident Response Manager: Lead Detection & Remediation

HUB International

Chicago (IL)

On-site

USD 130,000 - 150,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health/dental/vision insurance
Life insurance
Disability insurance
401(k) and matching

Job summary

HUB International is seeking a seasoned Security Incident Response Manager to lead a dedicated IR team. You will own the incident lifecycle—from detection and triage to containment, eradication, recovery, and post-incident review—while guiding proactive detection engineering and threat hunting.

You will mentor staff, improve processes, and ensure log analysis across cloud and on-prem environments. Strong DFIR experience and KPI focus are essential.

Qualifications

  • Bachelor’s degree in technology or applicable experience.
  • 10+ years programming/scripting experience; strong knowledge of TCP/IP, DNS, HTTP, WAF, OAuth, SAML.
  • 5+ years with Active Directory/Entra and O365 services.
  • 5+ years with security platforms, automation tooling; hands-on with SIEM, EDR, SOAR.
  • Experience in DFIR, logs, timelines, evidence handling with chain-of-custody.
  • Familiarity with NIST/SANS incident response frameworks; KPI-driven maturity.
  • Proven ability to build or mature an IR team; strong collaboration & adaptability.

Responsibilities

  • Lead and manage a Security Incident Response Team focused on threat detection and response.
  • Oversee end-to-end incident response lifecycle from detection to post-incident review.
  • Mentor team members and drive continuous improvement in processes and tooling.
  • Analyze cloud/on-prem logs, perform forensics, and determine scope of impact.
  • Develop scalable incident response playbooks and escalation frameworks.
  • Report KPIs and coordinate with stakeholders on incident status.

Skills

Powershell
Python
Shell scripting
Networking basics

Education

Bachelor’s degree in technology or applicable experience

Tools

SIEM
EDR
SOAR
Microsoft 365 / Entra

Job description

HUB International is seeking a seasoned Security Incident Response Manager to lead a dedicated IR team. You will own the incident lifecycle—from detection and triage to containment, eradication, recovery, and post-incident review—while guiding proactive detection engineering and threat hunting.

You will mentor staff, improve processes, and ensure log analysis across cloud and on-prem environments. Strong DFIR experience and KPI focus are essential.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Global Incident Detection & Response Lead
Global Incident Detection & Response Lead

Referment • New York (NY)

On-site
USD 180,000 - 280,000
Incident Response Manager - Lead & Evolve Security
Incident Response Manager - Lead & Evolve Security

10 Ancestry.com Operations Inc. • Draper (UT)

Hybrid
USD 132,000 - 166,000
Remote IR Lead: Cloud Security & Incident Response
Remote IR Lead: Cloud Security & Incident Response

FICO • United States

Remote
USD 137,000 - 215,000
Remote-work option
Manager of Security Incident Response
Manager of Security Incident Response

HUB International • Chicago (IL)

On-site
USD 130,000 - 150,000
Remote Senior Incident Response Consultant - Forensics Lead
Remote Senior Incident Response Consultant - Forensics Lead

Forensic Focus • Town of Texas (WI), Northern (KY)

Hybrid
USD 123,000 - 179,000
Senior Incident Responder & Threat Hunter
Senior Incident Responder & Threat Hunter

Halliburton • Houston (TX)

On-site
USD 120,000 - 180,000
Benefits package
Threat Detection & Response Engineer: Incident Leader
Threat Detection & Response Engineer: Incident Leader

Whatnot • San Francisco (CA)

Hybrid
USD 175,000 - 260,000
Health Insurance (Medical, Dental, Vis
Work From Home Support
Home office setup allowance
+5
Incident Response IR Analyst Engineer
Incident Response IR Analyst Engineer

Accrescent Group • Roanoke (TX)

Hybrid
USD 95,000 - 140,000
Lead Incident Manager, Detection & Response
Lead Incident Manager, Detection & Response

Anthropic • Washington

Hybrid
USD 290,000 - 365,000
Senior Security Engineer: Threat Detection & IR Leader
Senior Security Engineer: Threat Detection & IR Leader

HKS, Inc • Dallas (TX)

On-site
USD 120,000 - 160,000