SOC Incident Commander

Optimum

Norwalk (CT)

On-site

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Optimum is seeking a Cyber Security Incident Commander to lead incident response for significant cybersecurity events, coordinating cross-functional teams across IT, Legal, Communications, and Engineering. You will guide containment, recovery, and communications to executives while striving to improve processes and playbooks.

You will perform forensic analysis across hosts, networks, and the cloud, integrate threat intelligence, and apply an AI-first approach to accelerate triage and

Qualifications

  • Bachelor's degree in Computer Science or related field.
  • Advanced certifications such as CISSP or incident-response GIAC certifications preferred.
  • Minimum five years experience in Information Technology.
  • Minimum three years of direct IT Security experience in Cyber Security operations and Incident Response.
  • Experience with event and log analysis across security tools.
  • Strong communication of complex information to leadership.

Responsibilities

  • Own incident command for mid-tier and major incidents with cross-functional teams.
  • Monitor alerts and triage incidents by severity and business impact.
  • Execute incident response playbooks to contain and remediate breaches.
  • Lead post-incident reviews and root-cause analyses; drive remediation.
  • Develop and mature incident-response playbooks and drills.
  • Coordinate with law enforcement, regulators, and vendors.

Skills

Incident Command
Log Analysis
MITRE ATT&CK
Forensics
AI Tools
Communication

Education

Bachelor's degree in CS or related field
CISSP or GIAC (GCIH/GCFA/GCFE/GNFA) preferred

Tools

SIEM/EDR
Forensic Tools
Cloud Forensics

Job description

SOC Incident Commander

Location: Norwalk, CT, US, 06851

Brand: Optimum

Requisition #: 12603

Are you looking to Optimize your life? Start your exciting path to a rewarding career today!

We are Optimum, a leader in the fast-paced world of connectivity, and we're seeking driven and enthusiastic professionals to join our team, empower lives, fuel businesses, and drive innovation. Connectivity is no longer a luxury, but a necessity. A career at Optimum means you'll be enabling progress and enhancing lives by providing reliable, high-speed connectivity solutions that keep the world connected. Our successes, now and in the future, are powered by our amazing product, a commitment to our people and culture, and the connections we make in our communities.

If you are resourceful, collaborative, and passionate about delivering consistent excellence, Optimum is for you!

Job Summary

As a Cyber Security Incident Commander, you will be responsible for safeguarding our organization's digital assets by promptly identifying, analyzing, and responding to cyber security incidents. You will play a critical role in minimizing the impact of security breaches and preventing future incidents through proactive measures and continuous improvement of our incident response processes.

Responsibilities
  • Incident command & response
  • Serve as incident commander for mid-tier and major incidents: own the full lifecycle and direct cross-functional workstreams (IT, Legal, Communications/PR, Engineering, executives).
  • Monitor alerts and logs; triage and prioritize incidents by severity, criticality, and business impact.
  • Execute incident response playbooks to contain, mitigate, and remediate breaches, then restore affected systems and close off unauthorized access.
  • Act as primary point of contact to executive leadership and the CISO, translating technical events into business-impact briefings.
  • Forensics & analysis
  • Conduct host, network, memory, and cloud/hybrid forensics to determine root cause, scope, and extent of compromise - preserving evidence and maintaining chain of custody to legal and regulatory standards.
  • Perform malware triage and static/dynamic analysis, including sandbox detonation, to establish capability and indicators of compromise.
  • Integrate threat intelligence and proactively hunt for adversary TTPs mapped to MITRE ATT&CK.
  • Leverage AI-enabled tooling to accelerate triage, enrichment, and investigation (AI First mindset).
  • Readiness & continuous improvement
  • Own post-incident reviews and root cause analyses; capture lessons learned and drive remediation to closure.
  • Develop and mature incident-response playbooks, tabletop exercises, and readiness drills.
  • Organize and execute security exercises including Purple Team Exercises, penetration tests, and audits.
  • Define and report IR metrics (MTTD, MTTR) and major-incident tracking to leadership.
  • Prepare detailed incident reports covering timeline, impact, remediation, and lessons learned.
  • Coordinate with external parties including law enforcement, regulators, and third-party vendors.
  • Develop security policies, procedures, and best practices; perform risk assessments and audits for compliance with industry standards.
  • Evaluate and recommend security technologies, partnering with IT to design and implement solutions.
  • Lead and mentor junior analysts, fostering continuous learning.
  • Stay current on emerging threats, vulnerabilities, and industry trends.
Qualifications
  • Bachelor's degree in Computer Science or related field.
  • Advanced certifications such as CISSP or incident-response/forensics GIAC certifications (GCIH, GCFA, GCFE, GNFA) are preferred
  • Minimum five years experience in Information Technology
  • Minimum three years of direct IT Security experience in Cyber Security operations and Incident Response
  • Experience performing event and log analysis including one or more of the following: Anti-Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security
  • Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means
  • Solid working knowledge of networking technology and tools, firewalls, proxies, IDS/IPS, encryption, SIEM and EDR
  • Experience writing scripts, tools, or methodologies to enhance the investigative process
  • Working knowledge of the MITRE ATT&CK framework and the NIST incident response lifecycle (NIST SP 800-61).
  • Hands-on experience with industry-standard forensic toolsets and with cloud forensics across major cloud and productivity platforms.
  • Familiarity with AI tools and an AI First mindset.

At Optimum, every action and interaction we take part in, is driven by our three Guiding Principles: Do What's Right, Drive One Optimum, and Make It Happen. These aren't just words, they help us build trust, create real community, and embrace new ways of thinking. Our employees are empowered to do the right thing for our customers and co-workers and to recognize and reward these behaviors when we see them. It's all part of the bigger picture of "Be The Difference" where each employee knows they have the power to enact real change, share new ideas, and understand that learning never stop.

All job descriptions and required skills, qualifications and responsibilities for a particular position are subject to modification by the company from time to time, in the company's discretion based on business necessity.

We are an Equal Opportunity Employer committed to recruiting, hiring and promoting qualified people of all backgrounds regardless of gender, race, color, creed, national origin, religion, age, marital status, pregnancy, physical or mental disability, sexual orientation, gender identity, military or veteran status, or any other basis protected by federal, state, or local law.

Applicants must be authorized to work for ANY employer in the U.S.

Please note that at this time, we do not provide visa sponsorship for employment.

Nearest Major Market: Bridgeport
Nearest Secondary Market: Danbury

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Incident Commander
SOC Incident Commander

Optimum • Bethpage (NY)

On-site
USD 82,000 - 137,000
SOC Incident Commander
SOC Incident Commander

Optimum Communications Inc. • Norwalk (CT)

On-site
USD 130,000 - 170,000
Security Operations Center (SOC) Operator (2+ years of work experience required))
Security Operations Center (SOC) Operator (2+ years of work experience required))

Austin Community College • Norwalk (CT)

On-site
USD 70,000 - 90,000
Career development opportunities
Collaborative work environment
Continuous learning and training
SOC Incident Responder
SOC Incident Responder

Optimum Communications Inc. • Norwalk (CT)

On-site
USD 90,000 - 120,000
Lead Cyber Defense Strategy
Lead Cyber Defense Strategy

Optimum • Bethpage (NY)

On-site
USD 134,000 - 220,000
Lead Cyber Defense Strategy
Lead Cyber Defense Strategy

Optimum • Norwalk (CT)

On-site
USD 134,000 - 220,000
SOC Incident Commander
SOC Incident Commander

Optimum Communications Inc. • Bethpage (NY)

On-site
USD 84,000 - 137,000
Sr Prod Sec Eng - Devices
Sr Prod Sec Eng - Devices

Optimum • Plano (TX)

On-site
USD 140,000 - 190,000
Sr Security Analyst
Sr Security Analyst

Optimum Communications Inc. • Bethpage (NY)

On-site
USD 70,000 - 110,000
Lead Incident Mgmt Comms
Lead Incident Mgmt Comms

Optimum • Bethpage (NY)

On-site
USD 123,000 - 203,000