Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Manager - Cyber Operations & Assurance- Incident Response

$123k - $215.25k

American Express

Job ID: 26012722Posted: 2026-08-19Location: Phoenix, AZ, United States; Atlanta, GA, United States; Palo Alto, CA, United States; Salt Lake City, UT, United States; Sunrise, FL, United States; Charlotte, NC, United States; New York, NY, United StatesSalary: $123000 - $215250 annually + bonus + benefitsJob Function: CybersecuritySchedule: Full timeShift: DayWorkplace: HybridCareer Area: TechnologyCompany: American ExpressDescriptionJoining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.At American Express, our mission is to deliver the world’s best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage—empowering you to innovate, grow, and help shape the future of a Fortune 100 company.Trust. Service. Security.American Express seeks to recruit a passionate and experienced Leader for its Incident Response team. This is a senior-level, hands-on, highly technical role performing incident response activities ranging from pre-incident preparation, active incident response, and post-incident analysis and recovery. You will be a key technical resource conducting investigations, performing advanced analysis, identifying attacker TTPs, building attack narratives, and executing response actions.As part of our evolution toward a Next Generation Agentic SOC, this role will also help drive the adoption of AI-enabled security operations, intelligent automation, and autonomous analyst workflows. The ideal candidate combines deep incident response expertise with curiosity and practical experience in AI-assisted detection, security automation, and modern SOC engineering practices.You are a motivated leader who will directly manage, mentor, and develop a team of SOC analysts while driving the people, processes, and technology that empower the team to investigate sophisticated threats at scale. This role requires critical thinking, innovative problem solving, technical leadership, people leadership, and effective communication across both technical and executive audiences.ResponsibilitiesPeople Leadership & Team Development Directly lead and manage a team of SOC analysts, including hiring, onboarding, day-to-day supervision, performance management, and career development, fostering a high-performing and engaged team culture.Conduct regular 1:1s, performance reviews, and goal-setting with direct reports; provide timely, constructive feedback and coaching to accelerate individual and team growth.Mentor and develop junior and mid-level analysts, building technical skills, investigative rigor, and professional capabilities across the team; create clear career progression pathways from Tier 1 through senior roles.Manage shift schedules, on-call rotations, and workload distribution to ensure 247 operational coverage while proactively mitigating analyst burnout and maintaining team morale.Drive a culture of continuous learning by identifying training opportunities, encouraging pursuit of industry certifications (e.g., GCIH, GCFA, GCIA), facilitating hands-on exercises (e.g., Immersive Labs, tabletop exercises), and championing knowledge-sharing across the team.Recruit and retain top talent by partnering with HR and hiring managers to define role requirements, conduct interviews, and build a diverse and skilled analyst pipeline.Incident Response & Technical Operations Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations and escalations from junior analysts across Windows, Mac, Linux, Cloud, SaaS, and hybrid environments.Participate in incident response, cyber crisis management, and enterprise-wide security events.Advise leadership on containment, eradication, and recovery strategies during incident response.Fully scope incidents through proper identification of all affected systems, identities, applications, and/or accounts.Recognize attacker tactics, techniques, and procedures (TTPs) as well as Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) applicable to current and future investigations.Serve as a technical escalation point for the analyst team, providing real-time guidance on complex or high-severity investigations and ensuring quality and consistency of investigative outputs.Contribute to team projects, process improvement, and development of new security operations capabilities.Help curate a world-class security operations and incident response program with a relentless focus on innovation, intelligent automation, and continuous improvement.Assess and develop incident response best practices to help mature the overall security operations and AI-assisted defense capabilities of the organization.Produce high-quality written and verbal reports, recommendations, executive briefings, and technical findings.Participate in on-call rotation and provide after-hours support on an as-needed basis.AI-Enabled Security Operations & Automation Partner with detection engineering, threat intelligence, data science, and security engineering teams to operationalize AI-driven detection and response capabilities.Assist in the design, tuning, and oversight of AI-enabled SOC workflows, analyst copilots, and autonomous or semi-autonomous response agents.Develop and optimize prompts, workflows, and guardrails for large language model (LLM) and AI-agent-assisted investigations and triage processes.Evaluate and validate AI-generated investigative outputs to ensure operational accuracy, reliability, explainability, and security.Help identify opportunities to leverage AI/ML, orchestration, and automation technologies to reduce analyst toil and accelerate response times.Participate in development and integration of SOAR playbooks, AI-assisted enrichment pipelines, and security automation frameworks.Contribute to AI governance and operational risk management efforts related to AI-enabled security tooling and workflows.Champion AI adoption within the team by training analysts on AI-assisted tools and workflows, gathering analyst feedback to drive iterative improvements, and ensuring responsible use aligned with organizational governance.Stay current on industry trends, attack techniques, AI-enabled threats, adversarial AI risks, mitigation techniques, and emerging security technologiesQualifications3+ years of experience in information security, security operations, incident response, threat hunting, or cyber defense.Experience with host, network, and/or memory forensics.Experience with various network and/or host-based security tools used to detect and respond to security events (e.g., SIEM, EDR, NDR, SOAR, web proxy, IDS/IPS, cloud-native security platforms, etc.).Theoretical and practical security knowledge and investigation experience with Mac, Linux, Windows, and cloud environments.Strong understanding of incident response lifecycles, attacker methodologies, and cyber kill chain concepts.Experience performing analysis of complex security incidents in enterprise environments.Familiarity with scripting or programming languages such as Python, PowerShell, Go, or similar.Ability to convey complex technical concepts to audiences with varying levels of technical expertise.Strong analytical, investigative, documentation, and communication skills.Demonstrated curiosity and adaptability toward emerging AI-enabled security technologies and workflows.Demonstrated ability to lead, motivate, and develop technical teams in high-tempo, operationally demanding environments.Strong interpersonal and conflict-resolution skills, with the ability to foster a collaborative, inclusive, and psychologically safe team environment.Preferred:1+ years of experience in a people leadership, team lead, or supervisory role, including direct responsibility for coaching, mentoring, or managing technical staff.Experience working within a modern SOC leveraging AI-assisted analysis, security automation, and/or SOAR technologies.Familiarity with AI/ML concepts and practical applications within cybersecurity operations.Experience with prompt engineering, LLM-assisted workflows, or AI copilots for security investigations and operational efficiency.Understanding of AI agent architecture, orchestration frameworks, retrieval-augmented generation (RAG), vector databases, or autonomous workflow concepts.Experience integrating APIs, automation pipelines, or AI-enabled tooling into SOC workflows.Knowledge of adversarial AI threats, prompt injection risks, model misuse, or AI security governance principles.Experience building or operationalizing automated detection, enrichment, triage, or response capabilities.Knowledge and investigation experience in a global, multi-cloud environment.Experience with detection engineering, threat hunting, or behavioral analytics.Familiarity with cloud-native security technologies and telemetry sources.Multiple applicable certifications (GSE, GDAT, GCIA, GCIH, GCFA, GNFA, GCFE, GREM, CCSP, CISSP, CEH, etc.).AI-related certifications or hands-on experience with enterprise AI platforms, orchestration frameworks, or automation tooling.Experience managing performance cycles, conducting calibrations, and building talent development plans within a security operations or SOC environment.Experience managing geographically distributed or shift-based teams supporting 247 operations.Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.

Vacancy posted 14 hours ago
Similar jobs that could be interesting for youBased on the Senior Manager - Cyber Operations & Assurance- Incident Response in Atlanta, GA vacancy
  •  ...valued and empowered, then we invite you to apply to our Senior Cyber Incident Response Attorney position. While the position is based in our New...  ...response work by AssociatesInteraction with senior level management and technical personnel at client companiesAnalysis of state... 
    Cyber
    Senior
    Work at office
    Remote work
    Flexible hours

    Wilson Elser

    Atlanta, GA
    3 days ago
  • $142.9k - $266k

    Cyber Incident Response Business Development Senior ManagerThe Opportunity:Join a team to contribute to Booz Allen's growth...  ...marketing, thought leadership, operations, events, and logistics, which...  ...revenueExperience developing and managing strategic relationships across cyber... 
    Cyber
    Senior
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Atlanta, GA
    22 hours ago
  •  ...inquiries won't receive a response).Regular or...  ...job description:The Cyber Hunt & Respond Senior Engineer is a senior...  ...threat hunting and incident response activities....  ...organization.  This role operates in a fast-paced...  ...Experience implementing and managing complex information... 
    Cyber
    Senior
    Permanent employment
    Full time
    Part time
    H1b
    Work at office
    Work visa
    Shift work
    Night shift
    Day shift

    Truist

    Atlanta, GA
    22 hours ago
  •  ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize...  ...and the Senior Incident Manager, integrates with cyber defenders when needed, and champions...  ...major incidents and produce operational and executive reporting. ~ Excellent... 
    Cyber
    Senior
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Atlanta, GA
    3 days ago
  • $105.4k - $207.8k

     ...Summary Deloitte’s Cyber Services help our...  ...with the management of information and technology...  ...secure, and reliable operations across the enterprise...  ...experience in Cyber Incident Response. This role involves supporting...  ...-level employees to senior leaders, we believe... 
    Cyber
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Atlanta, GA
    22 hours ago
  •  ...possible.Job Summary: The Security Incident Response Engineer is responsible for...  ...key member of the Security Operations team and works closely with...  ...activities. Execute cyber incident response procedures...  ...teams. Support major incident management activities and provide technical... 
    Cyber
    Full time
    Immediate start
    Flexible hours

    Acrisure

    Atlanta, GA
    1 day ago
  •  ...community.DescriptionKEY RESPONSIBILITIES: The Senior Cyber Defense Engineer has...  ...to the team such as: incident response, vulnerability management, intrusion detection...  ..., and security operations, in cloud and on-premise...  ...faculty, and staff are assured of participation in... 
    Cyber
    Senior
    Work experience placement
    Work at office
    Remote work

    Emory University

    Atlanta, GA
    1 day ago
  •  ...We are currently seeking a Manager, Incident Response to join our Advisory practice...  ...and manage cyber incident response activities...  ...effectively—including presenting to senior executivesDemonstrated professionalism...  ..., and safeguard business operations and company reputation.... 
    Cyber
    Work experience placement
    H1b
    Local area

    KPMG

    Atlanta, GA
    2 days ago
  •  ...The Incident Response Coordinator supports the end‑to‑end response...  ...restore normal operations quickly and reduce impact...  ...established incident management processes, service...  ...escalations to Senior Coordinators and the...  ...incidents; engage infra/app/cyber/vendor dependencies.... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Atlanta, GA
    22 hours ago
  • $168.09k - $234.02k

     ...Description:At Regions, the Cyber Security Manager is responsible for leading a...  ...with the daily operations of enforcing, monitoring...  ...and implements incident response protocols...  ...projected threats to senior management and...  ...driven, continuous assurance and intelligent automation... 
    Cyber
    Full time
    Work at office
    Relocation
    Visa sponsorship
    Work visa
    Relocation package
    Flexible hours
    3 days per week

    Regions Financial

    Atlanta, GA
    2 days ago
  • OverviewJob PurposeThe Senior Engineer,...  ...is part of a team responsible for the global Information...  ...security incidents,maintaining a reputation...  ...controls are operating effectively via...  ...vulnerability management program to identify...  ...management. NIST Cyber Security Framework... 
    Cyber
    Senior

    Black Knight Financial Services

    Atlanta, GA
    2 days ago
  •  ...Summary   As a Senior Internal Audit Manager, Technology, you will manage a team responsible for driving...  ...improved technology, cyber, and operational risk management. You...  ...audit methodology and assurance practices,...  ...penetration testing, and incident response.... 
    Cyber
    Senior
    Work at office
    Local area
    Worldwide

    CRH

    Atlanta, GA
    22 days ago
  •  ...Summary of Purpose: The Senior IT Security Analyst...  ...'s mission-critical operations in the nuclear power...  ...and hands-on, is responsible for managing and maturing INPO's cybersecurity...  ...Monitors emerging cyber and AI risks,...  ...technology, information assurance, network engineering... 
    Cyber
    Senior
    Full time
    Work experience placement

    Inpo External

    Atlanta, GA
    22 hours ago
  • OverviewJob PurposeThe Senior Manager of Systems Operations’ role is responsible for managing a team of analysts providing immediate assistance to traders, back...  ...and drive process improvements that reduce incident frequency, eliminate operational toil, and increase... 
    Senior
    Immediate start

    Intercontinental Exchange

    Atlanta, GA
    5 days ago
  •  ...the global Service & Operations function at GBG, supporting...  ...region. The team is responsible for delivering high-...  ...the Global service management function to support...  ...operational performance.Senior Manager - Customer...  ...to customer impacting incidents, The role will lead... 
    Senior
    Full time
    Flexible hours

    GB Group

    Atlanta, GA
    22 hours ago
  •  ...make an impact:The Senior Security is a...  ...reporting to the Sr. Manager, IT Security. The...  ...ownership of advanced cyber security...  ...a bridge between operational execution and strategic...  ...vulnerability, alert, and incident oversightStaying...  ...response & digital forensics... 
    Cyber
    Senior
    Full time
    Local area
    Flexible hours

    Carter's

    Atlanta, GA
    3 days ago
  • $100k - $110k

     ...Cloud Security Posture Management (CSPM) and workload...  ...Global Information and Cyber Security Defense (...  ...alerts, and support incident response efforts. The ideal candidate...  ...of cybersecurity operations with a strong...  ...All Level 38 and more senior roles may also be eligible... 
    Cyber
    Senior
    Temporary work
    Local area
    Visa sponsorship
    Work visa
    Flexible hours

    Willis Towers Watson

    Atlanta, GA
    1 day ago
  • $90.4k - $168.2k

     ...currently seeking a Senior Associate, Content Development...  ...organization.Responsibilities:Execute the end-to-end...  ..., SOC, and Incident Response teams to map...  ...while designing and managing scalable security data...  ...tracesSupport and streamline Cyber Operations by actively automating... 
    Cyber
    Senior
    H1b
    Local area

    KPMG

    Atlanta, GA
    1 day ago
  • $105.4k - $207.8k

     ...Our Deloitte Cyber team understands the...  ...powerful solutions and managed services that...  ...enable our clients to operate with resilience,...  ...Work you'll doAs a Senior Engineering Management...  ...team, you will be responsible for:Supporting the...  ...issues and incidents efficiently.Integrate... 
    Cyber
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Atlanta, GA
    1 day ago
  •  ...both native and responsive web...  ...Technologies Accelerator operating system and...  ...direction and management of Honeywell's...  ...oversight for quality assurance of IAM...  ...managementManage incident/problem...  ...supervision of the Sr. Cyber Security...  ...interacts with Senior/Portfolio ArchitectFull... 
    Cyber
    Senior
    Temporary work
    Flexible hours

    Honeywell

    Atlanta, GA
    2 days ago
  • $105.4k - $207.8k

     ...Our Deloitte Cyber team understands the...  ...powerful solutions and managed services that...  ...enable our clients to operate with resilience,...  ...Work you'll do As a Senior Consultant,...  ...team, you will be responsible for: Architecting,...  ...threat hunting, and incident responseSupporting... 
    Cyber
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Atlanta, GA
    2 days ago
  •  ...Our Deloitte Cyber team understands the...  ...powerful solutions and managed services that...  ...enable our clients to operate with resilience,...  ...systems. This role is responsible for identifying...  ...crisis and cyber incident response, ensuring...  ...level employees to senior leaders, we believe... 
    Cyber
    Senior
    Work at office
    Local area
    Relocation
    Night shift

    Deloitte

    Atlanta, GA
    1 day ago
  •  ...Our Deloitte Cyber team understands the...  ...powerful solutions and managed services that...  ...enable our clients to operate with resilience,...  ...Do As a Delivery Senior Consultant, Software...  ...team, you will be responsible for... Supporting...  ...CIS-RC), Security Incident Response (CIS-SIR)... 
    Cyber
    Senior
    Work at office
    Local area
    Relocation
    Night shift

    Deloitte

    Atlanta, GA
    22 hours ago
  •  ...lighting controls, building management solutions, and an...  ..., Georgia, with operations across North America,...  ...strong background in both cyber security and...  ...environments. Key Tasks & Responsibilities (Essential Functions)...  ...networks for security incidents, analyze threats, and... 
    Cyber
    Senior

    Acuity

    Atlanta, GA
    1 day ago
  • $105.4k - $207.8k

     ...Security Engineer / Senior Consultant,...  ...TransformationDeloitte’s Cyber business is...  ...powerful solutions and managed services that simplify...  ...our clients to operate with resilience,...  ...team, you will be responsible for…Designing, deploying...  ...detection and incident response... 
    Cyber
    Senior
    Work experience placement
    Local area

    Deloitte

    Atlanta, GA
    1 day ago
  • $148.5k - $247.5k

     ...ArchitectManagement LevelSr Manager - Non People...  ...DescriptionThe Senior Lead Cybersecurity Architect is responsible for defining the...  ...development of non-cyber architecture-related...  ...events and incident response to identify...  ...underpin development and operational decision making.... 
    Cyber
    Senior
    Full time
    Remote work
    Visa sponsorship
    Flexible hours

    Cox Enterprises

    Atlanta, GA
    1 day ago
  • $120k - $202.5k

     ...Looking For State Street's Cyber Data & Analytics (...  ...seeking a Sr.Platform Operations Engineer to help shape...  ..., observability, log management, and security operations...  ...production support, incident handling, user support...  ...environment. What You Will Be Responsible For Lead the support,... 
    Cyber
    Senior
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Atlanta, GA
    22 hours ago
  •  ...our distinctive investment management capabilities, we provide...  ...DescriptionYour RoleThe Senior Principal, Fund Assurance provides independent oversight...  ...insights.You will be responsible for:Serving as a senior...  ...judgment to assess accounting, operational, and control issues,... 
    Senior
    Full time
    Work at office
    Flexible hours

    Invesco

    Atlanta, GA
    3 days ago
  •  ...Murata Electronics is seeking an Operations Incident Specialist to manage operational incidents impacting demand management and ensure timely resolutions. This role requires strong problem-solving abilities and experience in a fast-paced environment. Candidates should... 

    Murata Electronics

    Atlanta, GA
    2 days ago
  • $138k - $201k

     ...and secure Developer Security Operations pipelines by designing...  ...Materials (SBOM) mapping to manage supply chain risks, while advising...  ..., Information Systems, Cyber-security, related technical...  ...defense, threat intelligence and incident response services. Mandiant's... 
    Cyber
    Senior
    Work at office
    Remote work

    Google

    Atlanta, GA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Manager - Cyber Operations & Assurance- Incident Response. Be the first to apply!