Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Manager of Security Incident Response

$130k - $150k
Full-time

HUB International

ABOUT US

At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference. Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence.

HUB is a global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, personal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions

Job Description

In this role, you will manage the Security Incident Response team; for detecting and identifying cyber threats, as well as containment and remediation of these threats. This role owns the full incident response lifecycle—detection, triage, containment, eradication, recovery, and post-incident review—and is responsible for building a scalable Incident Response function that pairs reactive response capability with proactive detection engineering and threat hunting. The Manager ensures investigations are conducted with sound forensic methodology, including log and audit-trail analysis across cloud and on-premises platforms, accurate scoping of impacted systems and accounts.

Objectives of this Role

  • Manages and is responsible for the successful completion of all tasks in assigned projects.
  • Lead and manage a Security Incident Response Team focused on responding to security threats and maintaining HUB’s critical threat detection and response suite of security applications.
  • Available 24/7 for any critical incidents that may arise that require immediate resolution, providing leadership and direction to a multi-disciplinary IT team.
  • Work with IT teams to ensure managed environments and procedures comply with defined corporate security policies.
  • Mentor and develop team members to help foster individuals’ professional growth.
  • Engage with teams to practice continuous improvement in processes and tooling.
  • Supervises assigned operations team members and performs personnel actions including hiring, individual goal tracking, training, performance evaluation.
  • Maintains current knowledge of relevant technology, bringing forth ideas for modernization and improvement.
  • Identify potential technical issues and assist in engineering possible solutions
  • Engage with management regularly with reports on project status, activities, and achievements
  • Lead “Technical Archeology” efforts (Platform and System Decomposition), in respect to gaps identified during incident response activities.
  • Lead the creation of security incident response processes and playbooks that are scalable, consistent, repeatable, and supportable.
  • Direct forensic investigations of security incidents, including analysis of cloud audit logs (e.g., Microsoft 365 Unified Audit Log), endpoint and network telemetry, and identity activity, to identify indicators of compromise, establish attack timelines, and determine scope of impact.
  • Design and maintain a tiered escalation framework and on-call rotation so that incidents are routed to the appropriate analyst and management level based on severity and business impact.
  • Drive maturity of the Incident Response and Detection Engineering functions against a KPI-based roadmap, tracking metrics such as mean time to detect (MTTD), mean time to respond (MTTR), alert triage volume, and case closure rates.
  • Balance the team's dual-track structure of reactive Incident Response and proactive Detection Engineering/threat hunting, ensuring each track has clear ownership, workflows, and staffing.
  • Conduct post-incident reviews and root-cause analysis to capture lessons learned, close process gaps, and feed findings back into playbooks and detection content.

Daily and Monthly Responsibilities

  • Communicate with stakeholders to assist in the identification of business, technical, and operational requirements.
  • Analysis, of root-cause analysis for service interruption, to establish preventive measures, mitigations, or needed changes.
  • Evaluate security applications, infrastructure and associated costs at regular intervals
  • Be responsible for analysis and recommendation of configuration changes, process improvements or visibility enhancements to the support and scaling of HUB’s security response.
  • Triage and prioritize incoming security alerts and incidents daily, assigning severity and escalating to the appropriate analyst or on-call tier.
  • Perform or oversee forensic log review for active investigations (e.g., Microsoft 365 Unified Audit Log, EDR, network/firewall logs), documenting findings and preserving evidence in line with chain-of-custody practices.
  • Report monthly on incident response KPIs, including mean time to detect (MTTD), mean time to respond (MTTR), incident volume, and case closure rates, to leadership.
  • Facilitate tabletop exercises and periodic playbook/runbook reviews to validate incident response readiness and identify process gaps.

Skills and Qualifications

  • Bachelor’s degree in technology or applicable experience.
  • 10+ Years of experience with programming/scripting languages (Powershell, python, shell scripting)
  • Extensive experience with: TCP/IP, DNS, CDN, WAF, OAuth, SAML
  • 3+ years of experience with cloud infrastructure as a service (AWS, Azure, GCP)
  • 5+ years of experience with Microsoft Active Directory/Entra and O365 services and technology
  • 5+ years of experience with security platforms, automation tooling
  • Hands-on experience with SIEM, EDR, and SOAR platforms for detection, alerting, and investigation.
  • Experience conducting digital forensics and incident response (DFIR), including log analysis, timeline reconstruction, and evidence handling with chain-of-custody rigor.
  • Working knowledge of incident response frameworks (e.g., NIST 800-61, SANS) and experience developing incident response playbooks and runbooks.
  • Experience building or maturing an incident response team, including defining KPIs/metrics and driving a maturity roadmap.
  • Collaboration, prioritization, and adaptability skills
  • Desire to continuously develop your skills and knowledge

JOIN OUR TEAM

Do you believe in the power of innovation, collaboration, and transformation? Do you thrive in a supportive and client focused work environment? Are you looking for an opportunity to help build and drive change in a rapidly growing and evolving organization? When you join HUB International , you will be part of a community of learners and doers focused on our Core Values: entrepreneurship, teamwork, integrity, accountability, and service.

The expected salary range for this position is $ 130,000 to $150,000 and will be impacted by factors such as the successful candidate’s skills, experience and working location, as well as the specific position’s business line, scope and level. HUB International is proud to offer comprehensive benefit and total compensation packages which could include health/dental/vision/life/disability insurance, FSA, HAS and 401(k) accounts, paid-time-off benefits such as vacation, sick, personal, floating holidays and company holidays. In addition, eligible annual bonuses, equity and commissions may be available for some positions.

Vacancy posted 17 hours ago
Similar jobs that could be interesting for youBased on the Manager of Security Incident Response in Chicago, IL vacancy
  • $80k - $100k

     ...Reporting to the Sr. Director, Enterprise Safety & Security, the Manager of Enterprise Safety & Security (ESS) is responsible for providing support to field operations of...  ...are properly implemented. ~ Support the Incident Commander program for the Covista Enterprise.... 
    Suggested
    Full time
    Work at office
    Flexible hours

    Covista

    La Grange, IL
    1 day ago
  • $153k - $297k

     ...Director, Cyber Operations - Cyber Response and Digital Forensics to join our Enterprise Security Services organization.Responsibilities:Serve as the lead incident handler and direct end-to-end...  ...exercise sound judgment, effectively manage stress and work safely and... 
    Suggested
    H1b
    Local area
    Immediate start

    KPMG

    Chicago, IL
    2 days ago
  •  ...Head of Information Security About the Company Innovative cloud technology provider...  .... The successful candidate will be responsible for overseeing the evolution of...  ...secure development, identity and access management, and incident response. Experience in regulated... 
    Suggested

    Confidential

    Chicago, IL
    4 days ago
  •  ...Chief Security Officer About the Company Diverse provider of document management products & solutions Industry Information Technology...  ...domains. The CSO will be responsible for setting and executing a...  ...of security operations, incident response, and the ability to... 
    Suggested
    Work at office

    Confidential

    Chicago, IL
    5 days ago
  •  ...Head of Security About the Company Innovative platform for sending...  ...dedicated security hire, responsible for owning the security...  ...address security gaps, lead incident response, and drive a cultural...  ...and technologies. Hiring Manager Title VP of Engineering... 
    Suggested
    Shift work

    Confidential

    Chicago, IL
    4 days ago
  •  ...Description Head of High School Security Job Description Reports...  ...enforces school protocols in response to emergency situations....  ...administration on best practices for managing student movement throughout...  ...of student or staff incidents.  Assists the administration... 
    Day shift
    Afternoon shift

    Meridian Charter Schools

    Chicago, IL
    a month ago
  • $161.5k - $299.7k

     ...development.Job SummaryThis Position Is Responsible for directing and managing the activities of the HCSC’s Cyber...  ...improve the organization’s Cyber Security Posture, ensuring the CFC is...  ...including vulnerability management, incident handling and forensics* Problem solving... 
    Full time

    Health Care Service

    Chicago, IL
    4 days ago
  •  ...available for future use. As a responsible corporate citizen, we...  ...future is as bright, safe, and secure as it has ever been in our long...  ...operations, cyber risk management, governance, compliance, identity...  ...security assurance, incident response, cyber resilience,... 
    Local area
    Remote work
    Worldwide

    Sims Limited

    Chicago, IL
    1 hour ago
  • $200k - $215k

     ...everything possible.The Director, Global Security is responsible for leading the company’s global...  ...Responsible for enterprise security risk management, physical security, crisis management...  ...programs.Support crisis management, incident response, business continuity, and... 
    Hourly pay
    Full time
    Remote work
    Work from home
    Flexible hours

    Danaher Corporation

    Chicago, IL
    2 days ago
  •  ...Skills ~10+ years of information security experience, including cloud and...  ...~ Strong program and project management capabilities. Roles & Responsibilities Define and evolve AI security...  ...support monitoring, vulnerability management, and incident readiness.... 
    Full time

    2T Consulting

    Chicago, IL
    14 days ago
  • $97k - $189k

     ...fullest potential. The Consulting Director, AI Security is a hands-on technical contributor responsible for reviewing, evaluating, and validating...  ...workflows. Assist with vulnerability management, security monitoring, and incident readiness for AI systems. Provide... 
    Full time
    Work experience placement

    CNA Financial

    Chicago, IL
    2 days ago
  •  ...individual that is multi-task-oriented to manage a Security contract. Manages the accountability...  ...staff for given accounts. Has full responsibility for performance, service and budget...  ...employees and clients, observe and report incidents, and direct others. Frequent... 
    Contract work
    For contractors
    Local area
    Immediate start
    Shift work

    Andy Frain

    Oak Brook, IL
    20 hours ago
  • $70k

     ...of Science and Industry is the right place for you. The Security Manager is responsible for overseeing the safety and security operations of the...  ...operational and effective. Prepare and file safety, criminal, incident, and other department reports. Participate in setting and... 
    Contract work
    Temporary work
    Local area

    msichicago

    Chicago, IL
    2 days ago
  • $80k - $90k

     ...Overview: The Safety & Security Manager contributes to the transportation safety...  ...TAS employees ; coordinates accident/incident process; conducts audits and inspections...  ...vary by location. Key Responsibilities: ~ Ensure compliance with state... 
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Shift work
    Weekend work

    Transdev

    Chicago, IL
    1 day ago
  •  ...We are seeking an experienced Managing Director, Information Security to lead Cresset's enterprise information...  ...technology leadership role is responsible for developing and executing the firm...  .... Security Operations & Incident Response Lead the firm's cybersecurity... 
    Full time
    Internship
    Work at office
    3 days per week

    Cresset

    Chicago, IL
    1 day ago
  • $150k - $180k

     ...strategic marketing and financial management to human resources and...  ...implement game-changing policies. Responsibilities Job Purpose: At StoneX, our Security Operations Center is more than a...  ...capability, judgment, and confidence. Incident Coordination: Manage escalations... 
    Work at office
    Shift work

    StoneX

    Chicago, IL
    20 hours ago
  • $107k - $120k

     ...job involves:As a Health, Safety, Security and Environment Manager at JLL, you'll be at the forefront...  ...their workplace every day. You'll lead incident investigations, conduct risk...  ...everyone understands their safety responsibilities.Monitor regulatory changes and industry... 
    Full time
    For contractors
    Work at office
    Local area

    Jones Lang LaSalle

    Chicago, IL
    2 days ago
  • $215k - $300k

    OverviewThe Next 150 Operations Manager is a senior operational leader responsible for translating Next 150’s strategic plan and forecast into disciplined,...  ...performance expectationsDrives the safety culture; review incidents and trends; partner with Safety to implement... 
    Work at office
    Remote work

    Gilbane Building Company

    Chicago, IL
    4 days ago
  •  ...capabilities in digital, cloud and security. Combining unmatched...  ...seeking an experienced Senior Manager, AIOps & Agentic Operations...  ...background leading NOC/SOC and major incident command, navigating...  ...person at Accenture has the responsibility to create and sustain an inclusive... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Night shift

    Accenture

    Chicago, IL
    20 hours ago
  •  ...procedures, operational site audits and incident lessons learned. This position will...  ...related functions, including significant responsibility for developing and leading technical programs...  ...organization / project planning, time management, and change management skills across... 
    Full time
    Local area
    Remote work

    CyrusOne

    Chicago, IL
    1 day ago
  • $317.5k - $365k

     ...everyone is a stakeholder.What You’ll Be Responsible ForCircle is building the next...  ...native APIs. As VP, Global Head of Product Security & Risk, you will define and lead the enterprise...  ..., compliance operations, and risk management.Serve as a primary executive interface... 
    Worldwide
    Flexible hours

    Circle

    Chicago, IL
    4 days ago
  •  ...equipment. You’ll also document incidents and share observations that...  ...customer support—helping to manage robot deployments, escalate technical...  ...robots, ensuring timely response, coordination, and order...  ...Manage end-of-shift recovery by securing, charging, sanitizing, and... 
    Part time
    Live in
    Local area
    Flexible hours
    Shift work
    Night shift

    Serve Robotics Inc

    Chicago, IL
    more than 2 months ago
  • $102k - $184.3k

     ...development.Job SummaryThis position is responsible for leading a Cloud security engineering and operations team,...  ..., and Infrastructure Service Management teams in the design and build of secure...  ...architecture.Threat detection, incident response, and vulnerability... 
    Full time
    Relocation

    Health Care Service

    Chicago, IL
    4 days ago
  • $30k - $34k

     ...prioritizing artistic risk; engaging in responsible financial planning; nurturing connections...  ...with the Artistic Director, this role manages the full lifecycle of productions—from contracting...  ...and coordination as needed. Oversee incident response procedures and ensure... 
    Part time
    Work at office
    Afternoon shift

    Steep Theatre Company

    Chicago, IL
    3 days ago
  • $171k - $223k

     ...for an experienced Engineering Manager within the Infrastructure Engineering group to lead our Security Engineering team. Security engineering at Reverb is responsible for leading, designing, and building...  ...concepts with SIEM, EDR, Incident Management, IDS, and WAF like Cloudflare... 
    Full time
    Temporary work
    Work at office
    Remote work

    Reverb

    Chicago, IL
    2 hours ago
  • $95.6k - $162.4k

     ...TrustAs a global leader in innovative wealth management, asset servicing, asset management and...  ...SummaryThe AV Operations Lead is responsible for the day-to-day operation, support,...  ...technology, coordinate AV resources, oversee incident management, and serve as a trusted... 
    Full time
    H1b
    Worldwide
    Flexible hours
    Afternoon shift
    Early shift

    Northern Trust

    Chicago, IL
    2 days ago
  • $125.32k - $141.66k

     ...MANAGEROffice of Emergency Management and CommunicationsPolice DispatchNumber...  ...DUTIES· Directs personnel responsible for supervising Police...  ...field units to reported incidents of crime or emergencies· Monitors...  ...hours, responsible for security and building operations for... 
    Work experience placement
    Work at office
    Local area
    Shift work

    City of Chicago, IL

    Chicago, IL
    20 hours ago
  • $90k - $120k

     ..., onboarding and offboarding, endpoint management, IT support, office technology, and our...  ...physical access, equipment recovery, and secure access removal.Administer our device...  ...vulnerability management, monitoring, and incident response.Maintain strong coverage for MFA,... 
    Full time
    Temporary work
    For contractors
    Work at office
    Immediate start
    Remote work
    Flexible hours
    Shift work

    Formic Technologies

    Chicago, IL
    2 days ago
  • $70k

     ...floor. Hit the plan. Build the bench. Managed Labor Solutions, a nationwide leader in...  ...overtime. Review accident and incident reports. Manage and post employee schedule...  ...fast-paced ops leadership - and real responsibility for labor cost and gross profit, not headcount... 
    Hourly pay
    Contract work
    Local area
    All shifts
    Shift work

    Managed Labor Solutions

    Chicago, IL
    3 days ago
  • Description Position Title: Security Manager Department: Technology Reports To: VP of IT Location: Chicago / Remote Employment Type:...  ...assessments across systems, business units, and processes Support incident response: detection, triage, containment, and post-incident review... 
    Full time
    Remote work

    Avant Communications LLC

    Chicago, IL
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Manager of Security Incident Response. Be the first to apply!