Lead, Incident Operations

JetBlue

New York (NY)

On-site

USD 100,000 - 166,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

JetBlue seeks an Incident Operations Lead to orchestrate cybersecurity incident response across a complex IT environment, including data centers, SaaS, cloud, and end-user systems. You will coordinate incident activity, communicate with stakeholders, and maintain leadership-ready updates during high-pressure events.

You will translate technical timelines and actions into concise summaries, keep accurate incident records, and drive post-incident follow-through with actionable improvements.

Qualifications

  • Bachelor's Degree in Cyber Security, IT, CS, or related field.
  • 4+ years coordinating cybersecurity incidents or high-priority operations.
  • Security fluency to understand incident response concepts and risks.
  • Experience managing incident calls and cross-team coordination.
  • Excellent written and verbal communication for leadership.
  • Ability to work under time pressure and manage multiple priorities.
  • Willingness to on-call and travel as needed.
  • Authorized to work in the United States.

Responsibilities

  • Lead operational coordination of cybersecurity incidents and status updates.
  • Coordinate response activity across multiple teams and stakeholders.
  • Support declaration, escalation, severity alignment and workflow execution.
  • Translate findings into clear leadership-ready summaries.
  • Maintain incident records: timelines, decisions, attendees, actions.
  • Drive post-incident follow-through with lessons learned and actions.
  • Identify gaps in incident readiness (tools, access, playbooks).
  • Develop and improve incident response procedures and templates.
  • Coordinate tabletop exercises and readiness reviews.
  • Support prioritization during high-volume periods.
  • Provide guidance on documentation and escalation hygiene.
  • Other duties as assigned.

Skills

Incident coordination
Incident response
Stakeholder communication
Tabletop exercises
Bridge management
Documentation
Leadership updates

Education

Bachelor's Degree in Cyber Security

Tools

Splunk
Microsoft Defender
XSOAR
Jira
ServiceNow

Job description

Position Summary:

At JetBlue, cyber security operates across a complex IT environment, encompassing traditional data centers, Software as a Service (SaaS) services, multiple cloud providers, e-commerce platforms, and a diverse end-user environment.

We are seeking an Incident Operations Lead to support the Cyber Security Incident Response function through incident coordination, stakeholder communication, readiness, documentation, and post-incident follow-through. The ideal candidate is security-fluent, highly organized, comfortable operating during high-pressure events, and able to translate technical findings into clear actions and leadership-ready updates.

This role works closely with technical Incident Response analysts, but is focused on continuous improvement of and leading the operational execution of Incident Response and supporting the technical investigators.

Essential Responsibilities:
  • Lead the operational coordination of cybersecurity incidents, including bridge management, stakeholder communication, action tracking, handoffs, documentation, and leadership-ready status updates.
  • Coordinate response activity across Incident Response, Threat Intelligence, Detection Engineering, Security Monitoring, IT Operations, Identity, Infrastructure, application teams, Legal, Communications, vendors, and other stakeholders as needed.
  • Support incident declaration, escalation, severity alignment, communication cadence, and response workflow execution in accordance with established incident response procedures.
  • Translate technical findings, timelines, risks, containment actions and remediation status into clear summaries for leadership and non-technical stakeholders.
  • Maintain accurate incident records, including timelines, key decisions, attendees, action items, evidence references, follow-up owners, and closure documentation.
  • Drive post-incident follow-through by converting lessons learned, gaps, and corrective actions into tracked issues with owners, due dates, updates, and closure evidence.
  • Identify gaps in incident readiness, including access, tooling, logging, escalation paths, contact lists, documentation, playbooks, templates, evidence handling, and cross-team dependencies.
  • Develop, maintain, and improve incident response procedures, bridge guidance, communication templates, after-action processes, tabletop materials, and response readiness documentation.
  • Coordinate tabletop exercises, readiness reviews, control tests and follow-up tracking to improve the organization’s ability to respond to cybersecurity incidents.
  • Support operational prioritization during high-volume periods or active incidents by helping organize response activity, reduce coordination friction, and maintain visibility into outstanding work.
  • Provide guidance to analysts and stakeholders on incident documentation, communication expectations, escalation hygiene, and action tracking during response activities.
  • Other duties as assigned.
Minimum Experience and Qualifications:
  • Bachelor’s Degree in Cyber Security, Information Technology, Computer Science, Business, Emergency Management, or other relevant discipline; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience in cyber security operations, incident response, technology incident management, enterprise IT operations, or a related field.
  • Four (4) years of experience coordinating or supporting cybersecurity incidents, technology incidents, security operations, or similar high-priority operational response activities.
  • Demonstrated security fluency, including the ability to understand incident response concepts, common security events, severity/risk, containment, remediation, evidence handling, and escalation needs.
  • Experience managing incident calls, operational bridges, action trackers, status updates, stakeholder communications, or cross-team response coordination.
  • Strong written and verbal communication skills, including the ability to summarize complex technical information clearly for technical and non-technical audiences.
  • Ability to organize ambiguous information into clear priorities, owners, actions, timelines, risks, and decisions during time-sensitive events.
  • Ability to work effectively with technical responders without micromanaging investigation steps, while ensuring response activity remains structured, documented, and moving forward.
  • Strong problem-solving, judgment, ownership, and follow-through skills in a fast-paced operational environment.
  • Ability to manage multiple priorities, stakeholders, issues, and deadlines at once.
  • Ability to pass a live scenario-based interview or skills demonstration with JetBlue Crew Members.
  • Available and willing to participate in periodic on‑call duties and off‑hours Incident Response as required.
  • Available for occasional overnight travel (10%).
  • Must pass a pre‑employment drug test.
  • Must be legally eligible to work in the country in which the position is located.
  • Authorization to work in the United States is required. This position is not eligible for visa sponsorship.
  • Must be eligible to hold a US government security clearance if JetBlue deems it relevant to the role.
Preferred Experience and Qualifications:
  • Five (5) or more years of experience in cybersecurity operations, incident response, security operations, technology incident management, crisis management, or a similar operational leadership function.
  • Experience serving as an Incident Commander, Incident Manager, Cyber Incident Coordinator, Response Lead, Major Incident Manager, CSIRT Coordinator, or similar role.
  • Experience working in or closely with a SOC, Incident Response team, Threat Detection team, managed security provider, or enterprise cyber security organization.
  • Familiarity with SIEM, EDR, SOAR, case management, ticketing, identity, email security, cloud security, endpoint security, and network security concepts.
  • Experience with platforms such as Splunk, Microsoft Defender, SentinelOne, XSOAR, ServiceNow, Jira, or similar investigation, response, and work tracking tools.
  • Experience developing or maintaining incident response playbooks, runbooks, communication templates, after‑action reports, tabletop exercises, metrics, dashboards, or process documentation.
  • Familiarity with cybersecurity incident response frameworks or practices such as NIST SP 800‑61, CSIRT operating models, MITRE ATT&CK, ITIL Major Incident Management, or similar guidance.
  • Experience coordinating legal, communications, executive leadership, vendor, or external partner involvement during significant incidents or operational events.
  • Experience tracking corrective actions, remediation items, issue backlogs, control gaps, or cross‑team dependencies to closure.
  • Airline, transportation, critical infrastructure, or large‑enterprise experience in Security Operations, Incident Response, Threat Detection, Technology Operations, or Crisis Management.
  • Relevant certifications such as Security+, CISSP, GCIH, GCIA, GCFA, PMP, ITIL, or similar security, incident management, or project management credentials.
  • Strong sense of urgency, professionalism, ownership, and desire to continuously improve incident response readiness and execution.
Crewmember Expectations:
  • Regular attendance and punctuality.
  • Potential need to work flexible hours and be available to respond on short notice.
  • Able to maintain a professional appearance.
  • When working or traveling on JetBlue flights, and if time permits, all capable crewmembers are asked to assist with light cleaning of aircraft.
  • Organizational fit for the JetBlue culture, that is, exhibit JetBlue's values of Safety, Caring, Integrity, Fun and Passion.
  • Promote JetBlue's #1 value of safety as a Safety Ambassador, supporting JetBlue's Safety Management System (SMS) components, Safety Policy and behavioral standards.
  • Must fulfill safety accountabilities as prescribed by JetBlue's Safety Management System.
  • Responsible for adhering to all applicable laws, regulations (FAA, OSHA, DOT, etc.) and Company policies, procedures and risk controls.
  • Responsible for ensuring crewmembers have requisite training, resources and support to achieve safety objectives.
  • Identify safety and security concerns, issues, incidents or hazards that should be reported and report them whenever possible and by any means necessary including JetBlue's confidential reporting systems (Aviation Safety Action Program (ASAP) or Safety Action Report (SAR)).
  • The use of ChatGPT or any other automated tool during the interview process will disqualify a candidate from being considered for the position.
Equipment:
  • Computer and other office equipment.
Work Environment:
  • Traditional office environment.
Physical Effort:
  • Generally not required, or up to 10 pounds occasionally, 0 pounds frequently. (Sedentary)
Compensation:
  • The base pay range for this position is between $100,000 and $166,000 per year. Base pay is one component of JetBlue's total compensation package, which may also include access to healthcare benefits, a 401(k) plan and company match, crewmember stock purchase plan, short-term and long-term disability coverage, basic life insurance, free space available travel on JetBlue, and more.

#LI-AC1

#LI-Hybrid

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Responder
Incident Responder

JetBlue • New York (NY)

On-site
USD 91,000 - 129,000
Healthcare benefits
401(k) plan with company match
Crew travel benefits
Senior Principal DevOps Engineer
Senior Principal DevOps Engineer

JetBlue • New York (NY)

On-site
USD 135,000 - 210,000
Senior Analyst Operations Strategy (Tech Ops)
Senior Analyst Operations Strategy (Tech Ops)

JetBlue • New York (NY)

On-site
USD 66,000 - 103,000
Evaluator Occupational Health & Safety
Evaluator Occupational Health & Safety

JetBlue Airways • Boston (MA)

On-site
USD 67,000 - 101,000
Healthcare benefits
401(k) plan with company match
Crew travel benefits
Senior Principal Engineer
Senior Principal Engineer

JetBlue • New York (NY)

Hybrid
USD 135,000 - 210,000
Associate Engineer Configuration Control
Associate Engineer Configuration Control

JetBlue Airways • New York (NY)

On-site
USD 57,000 - 103,000
Senior Analyst Operations Strategy (Tech Ops)
Senior Analyst Operations Strategy (Tech Ops)

JetBlue • New York (NY)

On-site
USD 66,000 - 103,100
Healthcare benefits
401(k) plan
Company stock purchase plan
Inflight Crew Trainee at JetBlue
Inflight Crew Trainee at JetBlue

JetBlue • Orlando (FL)

On-site
USD 74,390,000 - 165,312,000
Manager Operations Data Analysis
Manager Operations Data Analysis

Jetblue Airways • Seattle (WA)

On-site
USD 81,000 - 137,000
Engineer Powerplant
Engineer Powerplant

JetBlue • New York (NY)

On-site
USD 72,000 - 118,000