Develop incident response charter, strategy and multi-year roadmap with department manager.
Define service level objectives and agreements and establish audit frameworks with regular drills.
Embed regulatory frameworks such as FedRamp, NIST, ISO, and GDPR into incident response policies.
Track program spend and calculate ROI for tools.
Develop and present dashboards for KPIs and lead monthly business reviews; lead Quarterly Business Reviews.
Coordinate executive briefings, post-incident reviews, and steering-committee sessions.
Design and deliver security onboarding for business units and track completion metrics.
Map incident workflows to identify gaps and drive process improvements.
Partner with Triage Manager and Detections Engineering to implement SOAR and SIEM automation and enhance telemetry pipelines.
Ensure consistency of triage and investigation processes across regions.
Develop and deliver recurring training modules, simulation scenarios and tabletop exercises.
Collaborate with operations and engineering teams to validate readiness and refine playbooks.
Partner with Product, Engineering, and Risk stakeholders to blueprint the new Security Onboarding program, mapping telemetry, designing interactive IR workshops, and ensuring product sensors feed SIEM.
Requirements
5+ years in cybersecurity, with 2+ years managing or program-managing IR/SOC functions in a large, 24/7/365 environment.
Proven track record of scaling IR processes and tooling across multiple regions.
Familiarity with SIEM (Splunk preferred), SOAR platforms, ticketing systems (JIRA), and metrics dashboards.
Solid understanding of the incident lifecycle, forensics basics, and telemetry pipelines.
Certified PMP, PgMP, or equivalent; Agile/Scrum experience a plus.
Expertise in OKR, developing program road maps, budget planning, SOW development, and vendor negotiation.
Exceptional communicator and collaborator; comfortable with executive-level presentations.
Strong analytical mindset with a bias for action and continuous improvement.
Bachelor's in computer science, Information Security, or related field; advanced degree a plus.