Lead Incident Response Specialist

Optomi

Boston (MA)

Hybrid

USD 150,000 - 210,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Optomi, in partnership with a fast-growing medical technology organization, seeks an experienced Incident Response Lead to mature enterprise incident response capabilities in a highly technical, R&D-driven environment. This role requires hands-on IR leadership, playbook development, and crisis management across the full incident lifecycle.

The ideal candidate has led major security incidents, can coordinate diverse stakeholders, and drive improvements post-incident.

Qualifications

  • 5+ years dedicated Incident Response experience, with senior leadership exposure.
  • Experience leading complex/high-severity cybersecurity incidents.
  • Strong experience with incident lifecycle: detection, containment, eradication, recovery, post-incident review.
  • Proven ability to develop and improve IR playbooks and procedures.
  • Experience planning and running tabletop exercises with cross-functional teams.
  • Solid understanding of legal, privacy, and regulatory aspects of incidents.

Responsibilities

  • Lead the response and coordination of significant cybersecurity incidents across the organization.
  • Serve as senior incident commander during high-severity events with clear decisions under pressure.
  • Develop and maintain enterprise Incident Response plans, procedures, and playbooks.
  • Lead tabletop exercises involving technical teams, leadership, legal, and compliance.
  • Coordinate investigation, containment, eradication, recovery, and evidence gathering.

Skills

Incident Response
Crisis leadership
Playbooks and runbooks
Tabletop exercises
Stakeholder comms
Regulatory awareness

Job description

Optomi, in partnership with a fast-growing medical technology organization operating in a highly technical, R&D-driven environment, is looking for an experienced Incident Response Lead to help mature and lead its enterprise incident response capabilities.

This role is designed for a senior Incident Response professional who has personally led major security incidents and can confidently take command when a high-impact event occurs. The ideal candidate will bring a strong combination of hands-on incident response experience, crisis leadership, playbook development, tabletop facilitation, and an understanding of the legal and regulatory considerations surrounding security breaches.

This is not primarily a detection engineering, SOC monitoring, or security-tool administration position. The organization is looking for someone who has been through complex incidents in the real world and can effectively steer the response from initial escalation through containment, investigation, evidence preservation, recovery, and post-incident review.

Responsibilities

  • Lead the response and coordination of significant and escalated cybersecurity incidents across the organization.
  • Serve as a senior incident commander during high-severity events, providing structure, direction, and clear decision-making under pressure.
  • Develop, maintain, and continuously improve enterprise Incident Response plans, procedures, and playbooks.
  • Lead and facilitate tabletop exercises involving technical teams, business stakeholders, leadership, legal, compliance, and other relevant groups.
  • Coordinate investigation, containment, eradication, recovery, and evidence-gathering activities during security incidents.
  • Provide leadership during ransomware, data breach, account compromise, malware, and other major cybersecurity events.
  • Ensure appropriate forensic evidence and incident documentation are preserved throughout investigations.
  • Partner with Legal, Compliance, Privacy, Risk, and business leadership to understand notification, reporting, and regulatory obligations following an incident.
  • Conduct post-incident reviews and translate lessons learned into improvements to processes, controls, playbooks, and organizational readiness.
  • Help strengthen overall incident preparedness across a highly technical and rapidly evolving environment.
  • Participate in an incident-response escalation/on-call structure as needed.

Qualifications

  • 5+ years of dedicated Incident Response experience, with significant preference for candidates bringing deeper senior-level experience.
  • Demonstrated experience personally leading complex or high-severity cybersecurity incidents.
  • Experience responding to significant security breaches and/or ransomware incidents.
  • Strong background developing and implementing Incident Response playbooks and procedures.
  • Demonstrated experience planning and leading cybersecurity tabletop exercises.
  • Strong understanding of incident investigation, containment, evidence preservation, escalation, recovery, and post-incident analysis.
  • Working knowledge of the legal, privacy, compliance, and regulatory considerations associated with cybersecurity incidents and data breaches.
  • Ability to coordinate technical and nontechnical stakeholders during high-pressure situations.
  • Excellent written and verbal communication skills, including the ability to communicate incident status, risk, and recommended actions to senior leadership.
  • Ability to operate independently and take ownership of major incidents with minimal ramp-up.

Preferred Experience

  • Experience supporting medical technology, healthcare technology, life sciences, or another highly regulated industry.
  • Familiarity with cybersecurity considerations involving FDA-regulated products or medical devices.
  • Experience responding to incidents involving connected products, IoT, or other technology operating at the intersection of enterprise IT and regulated products.
  • Experience within organizations containing substantial engineering, research, or product-development environments.

The strongest candidates will be professionals who can point to situations where they have personally taken control of a significant cybersecurity incident, coordinated multiple stakeholders, made difficult decisions under pressure, and guided the organization through the full incident lifecycle.

*There is a strong preference for candidates who are local to Boston to work remotely but who can come on-site during major incidents.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Commander - Enterprise Cyber Response
Senior Incident Commander - Enterprise Cyber Response

Optomi • Boston (MA)

Hybrid
USD 150,000 - 210,000
Incident Responder
Incident Responder

SOClogix • Catonsville (MD)

Hybrid
USD 100,000 - 145,000
Health, dental, and vision insurance
401(k) with company match
Unlimited PTO
+1
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group. • Northern (KY)

Hybrid
USD 110,000 - 170,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group • United States

Hybrid
USD 120,000 - 170,000
Senior Incident Responder
Senior Incident Responder

TENEX.AI • United States

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

Atlas Search • New York (NY)

On-site
USD 140,000 - 190,000
Senior Incident Response Lead & Forensics Expert
Senior Incident Response Lead & Forensics Expert

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

INSPYR Solutions • California (MO)

On-site
USD 100,000 - 130,000
Incident Response Specialist
Incident Response Specialist

myBridge Corporation • Arlington (VA)

On-site
USD 90,000 - 120,000
Sr. Lead Incident Response / Supervisor Level 5
Sr. Lead Incident Response / Supervisor Level 5

WaveStrong • Town of Texas (WI)

On-site
USD 140,000 - 190,000