Principal Incident Response Consultant

Cypress HCM

United States

On-site

USD 140,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Cypress HCM is seeking a Principal Incident Response Consultant to serve as interim technical lead for our Security Operations Center. This contract role starts immediately for 6 to 12 months and may extend, reporting to the Sr. Director, Security Operations.

You will run point on major incidents, perform triage and escalation calls, mentor the IR team, and coordinate with Enterprise Security and Threat Intelligence to keep detection and response moving when leadership is unavailable.

Qualifications

  • 7+ years in incident response or security operations, including time leading investigations.
  • Comfortable owning decisions during live incidents without a direct manager present.
  • Hands-on experience with SIEM, EDR, and case management tooling.

Responsibilities

  • Act as technical lead and escalation point for the SOC during active incidents.
  • Guide and mentor the incident response team through investigations, from triage to containment to root cause.
  • Make severity and escalation calls independently when the SOC director is unavailable.
  • Coordinate with Enterprise Security, Threat Intelligence, and other teams during multi-team incidents.
  • Flag process or coverage shortfalls to leadership as they come up.

Skills

Incident response leadership
SIEM
EDR
Case management tooling

Job description

Principal Incident Response Consultant, that can help as a SOC Technical Lead

Engagement: contract, immediate start, initial 6 to 12 months, could be extended.

Reports to: Sr. Director, Security Operations Center.

We need an experienced incident response leader to serve as interim technical lead for our Security Operations Center. This person will run point on major incidents, make triage and escalation calls, and keep detection and response work moving if our SOC director is out on leave or otherwise engaged.

Responsibilities
  • Act as technical lead and escalation point for the SOC during active incidents.
  • Guide and mentor the incident response team through investigations, from triage to containment to root cause.
  • Make severity and escalation calls independently when the SOC director is unavailable.
  • Coordinate with Enterprise Security, Threat Intelligence, and other teams in the company during multi-team incidents.
  • Flag process or coverage shortfalls to leadership as they come up.
Requirements
  • 7+ years in incident response or security operations, including time leading investigations, not just executing them.
  • Comfortable owning decisions during a live incident without a manager in the room.
  • Hands-on experience with SIEM, EDR, and case management tooling.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Lead - SOC Contract
Senior Incident Response Lead - SOC Contract

Cypress HCM • United States

On-site
USD 140,000 - 180,000
Sr. Lead Incident Response / Supervisor Level 5
Sr. Lead Incident Response / Supervisor Level 5

WaveStrong, Inc. • Dallas (TX)

On-site
USD 140,000 - 190,000
Sr. Lead Incident Response / Supervisor Level 5
Sr. Lead Incident Response / Supervisor Level 5

WaveStrong, Inc. • Town of Texas (WI)

On-site
USD 100,000 - 130,000
Security Operations Center Manager
Security Operations Center Manager

AGS • Boulder (CO)

On-site
USD 140,000 - 200,000
Senior Director of Security Operations
Senior Director of Security Operations

Code Red Partners • United States

On-site
USD 180,000 - 280,000
Senior Incident Response Engineer
Senior Incident Response Engineer

Sophos • United States

On-site
USD 150,000 - 190,000
SOC Lead: 24/7 Incident Detection & Response
SOC Lead: 24/7 Incident Detection & Response

Optimalsemi • United States

On-site
USD 140,000 - 190,000
Senior SOC & Incident Response Lead (Hybrid Remote)
Senior SOC & Incident Response Lead (Hybrid Remote)

Layer8security • Northern (KY)

Hybrid
USD 120,000 - 190,000
Medical insurance
Life insurance
Unlimited vacation
+2
Sr SOC and IR Manager (Remote or On Site)
Sr SOC and IR Manager (Remote or On Site)

Crane Co. • Stamford (CT)

Hybrid
USD 130,000 - 160,000
Remote SOC Supervisor - Lead Incident Response
Remote SOC Supervisor - Lead Incident Response

CTS • United States

On-site
USD 110,000 - 115,000
Health Insurance
401(k) with company match
Paid Time Off
+1