Manager of Security Incident Response

HUB International

Chicago (IL)

On-site

USD 130,000 - 150,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

HUB International is seeking a Senior Security Incident Response Manager to lead the IR team, driving detection engineering, threat hunting, and forensics across cloud and on-premises environments.

You will own the incident lifecycle, develop scalable playbooks, and mentor staff while coordinating with IT to align with security policies and KPI targets.

Qualifications

  • Bachelor’s degree in technology or equivalent experience.
  • 10+ years programming/scripting experience (PowerShell, Python, shell).
  • Extensive security tech: TCP/IP/DNS/CDN/HTTP/WAF/OAuth/SAML.
  • 3+ years cloud infra (AWS/Azure/GCP).
  • 5+ years AD/Entra, O365.
  • 5+ years security platforms, automation tooling.
  • Hands-on DFIR with log analysis and forensics.
  • Experience building IR playbooks and KPIs.

Responsibilities

  • Lead the Security Incident Response Team focused on threats and incident response delivery.
  • Ensure 24/7 availability for critical incidents and provide leadership to IT teams.
  • Develop scalable incident response processes, runbooks, and detection content.
  • Oversee post-incident reviews, root cause analysis, and lessons learned.
  • Report KPIs (MTTD/MTTR/case closure) to leadership and improve processes.

Skills

Programming/scripting
Powershell
Python
Shell scripting
Cloud platforms
Active Directory/Entra
O365
SIEM/EDR/SOAR
DFIR
NIST/SANS
KPIs/metrics
Team leadership

Education

Bachelor’s degree in technology or applicable experience

Tools

Microsoft 365
EDR tooling

Job description

At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference. Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence.

HUB is a global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, personal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions

Job Description

In this role, you will manage the Security Incident Response team; for detecting and identifying cyber threats, as well as containment and remediation of these threats. This role owns the full incident response lifecycle - detection, triage, containment, eradication, recovery, and post-incident review, and is responsible for building a scalable Incident Response function that pairs reactive response capability with proactive detection engineering and threat hunting. The Manager ensures investigations are conducted with sound forensic methodology, including log and audit-trail analysis across cloud and on-premises platforms, accurate scoping of impacted systems and accounts.

Objectives of this Role
  • Manages and is responsible for the successful completion of all tasks in assigned projects.
  • Lead and manage a Security Incident Response Team focused on responding to security threats and maintaining HUB’s critical threat detection and response suite of security applications.
  • Available 24/7 for any critical incidents that may arise that require immediate resolution, providing leadership and direction to a multi-disciplinary IT team.
  • Work with IT teams to ensure managed environments and procedures comply with defined corporate security policies.
  • Mentor and develop team members to help foster individuals’ professional growth.
  • Engage with teams to practice continuous improvement in processes and tooling.
  • Supervises assigned operations team members and performs personnel actions including hiring, individual goal tracking, training, performance evaluation.
  • Maintains current knowledge of relevant technology, bringing forth ideas for modernization and improvement.
  • Identify potential technical issues and assist in engineering possible solutions
  • Engage with management regularly with reports on project status, activities, and achievements
  • Lead "Technical Archeology" efforts (Platform and System Decomposition), in respect to gaps identified during incident response activities.
  • Lead the creation of security incident response processes and playbooks that are scalable, consistent, repeatable, and supportable.
  • Direct forensic investigations of security incidents, including analysis of cloud audit logs (e.g., Microsoft 365 Unified Audit Log), endpoint and network telemetry, and identity activity, to identify indicators of compromise, establish attack timelines, and determine scope of impact.
  • Design and maintain a tiered escalation framework and on-call rotation so that incidents are routed to the appropriate analyst and management level based on severity and business impact.
  • Drive maturity of the Incident Response and Detection Engineering functions against a KPI-based roadmap, tracking metrics such as mean time to detect (MTTD), mean time to respond (MTTR), alert triage volume, and case closure rates.
  • Balance the team’s dual-track structure of reactive Incident Response and proactive Detection Engineering/threat hunting, ensuring each track has clear ownership, workflows, and staffing.
  • Conduct post-incident reviews and root-cause analysis to capture lessons learned, close process gaps, and feed findings back into playbooks and detection content.
Daily and Monthly Responsibilities
  • Communicate with stakeholders to assist in the identification of business, technical, and operational requirements.
  • Analysis, of root-cause analysis for service interruption, to establish preventive measures, mitigations, or needed changes.
  • Evaluate security applications, infrastructure and associated costs at regular intervals
  • Be responsible for analysis and recommendation of configuration changes, process improvements or visibility enhancements to the support and scaling of HUB’s security response.
  • Triage and prioritize incoming security alerts and incidents daily, assigning severity and escalating to the appropriate analyst or on-call tier.
  • Perform or oversee forensic log review for active investigations (e.g., Microsoft 365 Unified Audit Log, EDR, network/firewall logs), documenting findings and preserving evidence in line with chain-of-custody practices.
  • Report monthly on incident response KPIs, including mean time to detect (MTTD), mean time to respond (MTTR), incident volume, and case closure rates, to leadership.
  • Facilitate tabletop exercises and periodic playbook/runbook reviews to validate incident response readiness and identify process gaps.
Skills and Qualifications
  • Bachelor’s degree in technology or applicable experience.
  • 10+ Years of experience with programming/scripting languages (Powershell, python, shell scripting)
  • Extensive experience with: TCP/IP, DNS, CDN, HTTP, WAF, OAuth, SAML
  • 3+ years of experience with cloud infrastructure as a service (AWS, Azure, GCP)
  • 5+ years of experience with Microsoft Active Directory/Entra and O365 services and technology
  • 5+ years of experience with security platforms, automation tooling
  • Hands‑on experience with SIEM, EDR, and SOAR platforms for detection, alerting, and investigation.
  • Experience conducting digital forensics and incident response (DFIR), including log analysis, timeline reconstruction, and evidence handling with chain-of-custody rigor.
  • Working knowledge of incident response frameworks (e.g., NIST 800-61, SANS) and experience developing incident response playbooks and runbooks.
  • Experience building or maturing an incident response team, including defining KPIs/metrics and driving a maturity roadmap.
  • Collaboration, prioritization, and adaptability skills
  • Desire to continuously develop your skills and knowledge
JOIN OUR TEAM

Do you believe in the power of innovation, collaboration, and transformation? Do you thrive in a supportive and client focused work environment? Are you looking for an opportunity to help build and drive change in a rapidly growing and evolving organization? When you join HUB International, you will be part of a community of learners and doers focused on our Core Values: entrepreneurship, teamwork, integrity, accountability, and service.

The expected salary range for this position is $ 130,000 to $150,000 and will be impacted by factors such as the successful candidate’s skills, experience and working location, as well as the specific position’s business line, scope and level. HUB International is proud to offer comprehensive benefit and total compensation packages which could include health/dental/vision/life/disability insurance, FSA, HAS and 401(k) accounts, paid-time-off benefits such as vacation, sick, personal, floating holidays and company holidays. In addition, eligible annual bonuses, equity and commissions may be available for some positions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Security Incident Response
Manager, Security Incident Response

HUB International • Chicago (IL)

On-site
USD 130,000 - 150,000
Health/dental/vision insurance
401(k) with company match
Paid time off
Privilege Access Management Engineer
Privilege Access Management Engineer

HUB International • Chicago (IL)

On-site
USD 100,000 - 120,000
Comprehensive benefits package
Lead Security Incident Response & Threat Detection
Lead Security Incident Response & Threat Detection

HUB International • Chicago (IL)

On-site
USD 130,000 - 150,000
Health/dental/vision insurance
401(k) with company match
Paid time off
Senior Risk Consultant
Senior Risk Consultant

HUB International • Chicago (IL)

On-site
USD 135,000 - 150,000
Health insurance
401(k) plan
Paid time off
Legal Counsel/Sr. Counsel, Cybersecurity
Legal Counsel/Sr. Counsel, Cybersecurity

HUB International • Chicago (IL)

On-site
USD 150,000 - 180,000
Health/dental/vision insurance
401(k) accounts
Paid-time-off benefits
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
IAM Architect
IAM Architect

HUB International • Chicago (IL)

Hybrid
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+3
Manager, Security Engineering, AWS Security Incident Response
Manager, Security Engineering, AWS Security Incident Response

Amazon • Seattle (WA)

On-site
USD 175,100 - 236,900
Health insurance
401(k) matching
Paid time off
+1
Consulting/Principal Security Engineer
Consulting/Principal Security Engineer

RELX • Raleigh (NC)

On-site
USD 104,900 - 174,700
Senior Incident Responder
Senior Incident Responder

Halliburton • Houston (TX)

On-site
USD 120,000 - 180,000
Benefits package