CompassMSP · 4 weeks ago
Incident Response Manager
CompassMSP is a company focused on security operations, and they are seeking an Incident Response Manager to lead and coordinate all phases of the security incident lifecycle. This role involves ensuring rapid detection, containment, eradication, and recovery from cybersecurity incidents while maintaining compliance with policies and best practices.
Responsibilities
Act as the incident commander during major security events, directing technical investigations and coordinating cross-functional teams (SOC, IT, Legal, Managed Services, and external vendors)
Oversee the end-to-end incident response lifecycle, ensuring timely triage, containment, eradication, and recovery in line with SLAs
Maintain accurate documentation of all incidents in the incident response platform
Perform and guide advanced forensic analysis, including host-based investigations, network traffic analysis, and malware reverse engineering
Develop and refine incident response playbooks, standard operating procedures (SOPs), and escalation protocols
Partner in leading and mentoring a team of security analysts and responders, fostering continuous improvement and professional development. (No direct people management responsibilities)
Manage on-call rotations and resource allocation to ensure 24/7 coverage for critical incidents
Collaborate with leadership to enhance organizational security posture through proactive threat hunting and vulnerability management
Conduct post-incident reviews and lessons-learned sessions to improve future response strategies
Qualification
Required
Proven experience in incident response, digital forensics, and threat analysis
Strong knowledge of security frameworks (NIST, CIS, ISO 27001) and regulatory requirements
Familiarity with SIEM, EDR, and other security tools
Excellent leadership, communication, and decision-making skills under pressure
Preferred
Relevant certifications (CISSP, GCIH, GCFA, or similar)