Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

CSOC Incident Response Lead

$108.53k - $140.09k
Full-time

Sherwin-Williams Paint Store

The Cybersecurity Security Operations Center (CSOC) Incident Response (IR) Lead is a cybersecurity professional responsible for overseeing and coordinating the response to all security incidents within the organization, acting as the primary decision-maker during a breach by leading the incident response team, assessing the situation, implementing response plans, and communicating updates to stakeholders throughout the incident lifecycle, with the primary goal of minimizing risk and restoring operations quickly and safely. This role requires a strategic thinker with strong leadership and technical skills, capable of making quick and informed decisions in high-pressure situations. Ability to support the IR lifecycle using our Security Information and Event Monitoring (SIEM) and Security Orchestration and Automated Response (SOAR) technologies.

This role reports directly to the CSOC manager.

Responsibilities

· Serve as the primary point of contact and decision-maker during cybersecurity incidents.

· Assist in utilization of full CSOC toolset in support of IR (i.e. SIEM / SOAR, sandbox, email security, End Point Detection and Response, etc.)

· Lead and coordinate incident response efforts within the Triage & Response team, including mobilizing resources, assessing the situation, and implementing response plans.

· Collaborate with internal and external stakeholders to gather information, assess impact, and prioritize response actions.

· Provide clear and timely communication to stakeholders, including executive leadership, throughout the incident lifecycle.

· Implement and refine the analysis and forensics process.

· Implement and refine incident response procedures, protocols, and playbooks to enhance effectiveness and efficiency.

· Conduct monthly post-incident reviews to help identify lessons learned, areas for improvement, and enforce consistent action item remediation with analysts, engineers, and relevant stakeholders.

· Stay abreast of emerging cyber threats, vulnerabilities, and best practices in incident response through collaboration with Vulnerability management and Cyber Threat Intelligence teams.

· Hold monthly workshops with stakeholders from Information Technology and Operational Technology to discuss on-going and future initiatives related to Incident Response.

· Collaborate with security engineers to enhance detection and playbook automation.

· Lead tabletop exercises with CSOC team members and internal stakeholders to facilitate training, identify gaps, and support continuous improvement.

· Assist with managing the IR database to ensure adherence to audit and compliance requirements.

· Support CSOC manager with vendor management of the IR retainer(s).

· Oversee formal / informal IR training. Identify training opportunities with unused IR retainer credits.

This is a remote position.

This position is not eligible for sponsorship for work authorization now or in the future, including conversion to H1-B visa. Must be legally authorized to work in the country of employment without needing sponsorship for employment work visa status now or in the future.

Job duties include contact with other employees and access confidential and proprietary information and/or other items of value, and such access may be supervised or unsupervised. The Company therefore has determined that a review of criminal history is necessary to protect the business and its operations and reputation and is necessary to protect the safety of the Company’s staff, employees, and business relationships.

Qualifications

Education & Experience

Required:

  • Bachelor’s degree in computer science, Information Technology, or related field (or equivalent experience).
  • 8+ years IT/Cybersecurity experience.
  • Proven experience leading and coordinating IR efforts in a fast-paced environment.
  • Strong technical knowledge of network security, malware analysis, intrusion detection, and related technologies.
  • Excellent communication and interpersonal skills, with the ability to interact effectively with stakeholders at all levels and explain technical information to non-technical stakeholders.
  • Ability to remain calm and focused under pressure, with a commitment to delivering results.
  • Understanding of various operating systems (z/OS, Window, UNIX, Linux, AIX, etc.).
  • Must be eighteen years or older
  • Must be legally authorized to work in the United States without company sponsorship

Preferred Experience

  • Relevant certifications such as the GIAC Incident Handler (GCIH) are preferred.
  • Previous experience with IR and handling
  • Deep understanding of cybersecurity concepts, including incident response methodologies and threat intelligence
  • Familiarity with relevant cybersecurity frameworks and regulations (e.g., NIST, GDPR)
  • SIEM/SOAR solutions, such as Splunk and Sumo Logic.
  • CSOC or working with a Managed Security Service Provider.
  • Threat Intelligence Platform (TIP) and importance of integrating into the SIEM in support of IR and Indicators of Compromise.
  • Exposure to Incident Response in the Operational Technology domain.

At Sherwin-Williams, our purpose is to inspire and improve the world by coloring and protecting what matters. Our paints, coatings and innovative solutions make the places and spaces in our world brighter and stronger. Your skills, talent and passion make it possible to live this purpose, and for customers and our business to achieve great results. Sherwin-Williams is a place that takes its stability, growth and momentum and translates it to possibility for our people. Our people are behind the strength of our success, and we invest and support you in:

Life … with rewards, benefits and the flexibility to enhance your health and well-being
Career … with opportunities to learn, develop new skills and grow your contribution
Connection … with an inclusive team and commitment to our own and broader communities
It's all here for you... let's Create Your Possible

At Sherwin-Williams, part of our mission is to help our employees and their families live healthier, save smarter and feel better. This starts with a wide range of world-class benefits designed for you. From retirement to health care, from total well-being to your daily commute—it matters to us. A general description of benefits offered can be found at Click on “Candidates” to view benefit offerings that you may be eligible for if you are hired as a Sherwin-Williams employee.

Compensation decisions are dependent on the facts and circumstances of each case and will impact where actual compensation may fall within the stated wage range. The wage range listed for this role takes into account the wide range of factors considered in making compensation decisions including skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. The wage range, other compensation, and benefits information listed is accurate as of the date of this posting. The Company reserves the right to modify this information at any time, with or without notice, subject to applicable law.

Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable federal, state, and local laws including with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act where applicable.

Sherwin-Williams is proud to be an Equal Employment Opportunity employer. All qualified candidates will receive consideration for employment and will not be discriminated against based on race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, pregnancy, genetic information, creed, marital status or any other consideration prohibited by law or by contract.

As a VEVRAA Federal Contractor, Sherwin-Williams requests state and local employment services delivery systems to provide priority referral of Protected Veterans.

Please be aware, Sherwin-Williams recruiting team members will never request a candidate to provide a payment, ask for financial information, or sensitive personal information like national identification numbers, date of birth, or bank account numbers during the application process.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the CSOC Incident Response Lead in Remote vacancy
  • $140k - $150k

    Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent upon additional funding.We are seeking a senior-level Incident Response Lead to join our advanced security operations team which is a... 
    Suggested
    Work at office
    Remote work

    ECS Federal

    Washington DC
    13 hours ago
  • $40 - $80 per hour

     ...Incident Response Lead, Cyber Security $40-80/hr Remote Freelance CODING About the Role What if your hard-won experience in the SOC trenches could directly strengthen how organizations detect, respond to, and contain real threats? We're looking for a seasoned... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours
    Night shift

    Alignerr

    United States
    4 days ago
  • $162.8k - $303k

     ...Job Number: R0247651 Global Incident Response Business Development Leader The Opportunity Serve as the Global Business Development Leader for...  ..., and direct enterprise relationships with our IR retainer. Lead and develop a global team of business development, relationship... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Crane, IN
    2 days ago
  •  ...Position Title: Cyber Security Incident Response Lead Location: Texas (Teleworker) Clearance Requirements: Public Trust Clearance Pay Rate: Competitive salary based on experience Position Description: We are seeking a highly skilled and experienced Cyber... 
    Suggested
    For contractors
    Remote work

    Seneca

    United States
    4 days ago
  • $240k - $280k

     ...Obsidian Security is the leading SaaS security platform, trusted by global enterprises...  ...ownership mentality, sound judgment, personal responsibility, and initiative. Your Responsibilities...  ...and response actions, and partner with incident response to operationalize them.... 
    Suggested
    Work from home
    Flexible hours

    Obsidian Security

    Palo Alto, CA
    5 days ago
  •  ...UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,00...  ...take appropriate actions based upon that analysis. Responsibilities include rapidly responding to potential incidents and events to minimize risk exposure and ensure... 
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Tempe, AZ
    13 hours ago
  •  ...Platform Strategy team, reporting to the Cyber Monitoring and Incident Response Team Director, you are responsible for managing a functional...  ...successful as possible at DTCC.Utilize metrics, feedback from team leads, feedback from stakeholders, threat intelligence, and... 
    Remote work
    Flexible hours

    DTCC- The Depository Trust & Clearing Corporation

    Tampa, FL
    13 hours ago
  • 2K is seeking a Lead Security Analyst to direct high-profile incident response efforts, train analysts, and mature our global security program. You will investigate incidents, hunt threats in online retail and game environments, and collaborate with cross-team stakeholders... 

    2K

    Austin, TX
    1 day ago
  •  ...Nana Management Services, LLC is seeking a Remote Security Sergeant to lead security operations at remote client locations in Alaska. You will supervise daily activities, enforce policies, manage staffing, and coordinate with clients and agencies. Requirements include... 
    Remote work

    NANA Management Services

    Anchorage, AK
    4 days ago
  •  ...exciting organization, please visit us at We are seeking a Cybersecurity Incident and Application Lead to join our team and support our client. The ideal candidate is a strong incident response and application security professional who remains calm under pressure and... 
    Temporary work
    For contractors
    Work experience placement
    Work at office
    Remote work
    Flexible hours
    2 days per week

    Unissant

    Herndon, VA
    7 days ago
  • $175.1k - $236.9k

     ...security leader, you will own building and managing a team of incident managers and technical leaders, fostering a strong team...  ...level of ownership and accountability is a must.Key job responsibilities- Build and lead a high-performing team of security engineers, focusing on... 
    Remote work
    Flexible hours
    Shift work
    Night shift

    Amazon

    Seattle, WA
    4 days ago
  • $32 per hour

     ...Patrol Specialist! Ready to suit up as a Lead Mobile Patrol Special? What...  ...people, property, and products. Your primary responsibility will be to prevent financial loss, theft...  ...crime by being visible and spotting incidents as, or even before, they happen. Conduct... 
    Hourly pay
    Full time
    Work at office
    Local area
    Immediate start
    Remote work
    Flexible hours
    Shift work
    Night shift
    Day shift
    Afternoon shift

    GardaWorld

    Auburn Hills, MI
    7 days ago
  • About the Role:We are seeking a Lead, Cybersecurity Operations to play a...  ...global Cybersecurity Operations (CSOC) capabilities. This individual will...  ...serve as a senior technical leader responsible for overseeing threat detection, incident response, and continuous improvement... 
    Full time
    Worldwide

    RB Global

    Westchester, IL
    4 days ago
  • PingWind is actively seeking an Incident Manager to lead incident management for the FSA IAM systems, ensuring rapid detection, response, and resolution to minimize disruption for users, applications, and services. The role follows FSA incident and problem management processes... 
    Remote job

    PingWind

    New York, NY
    2 days ago
  •  ...databases, and other technologies. Responsibilities Contributes to the planning and maintenance...  ...the field's concepts and principles. Leads and directs the work of other employees...  ...to perform, monitor, and report on the incident remediation efforts. Responsible for... 
    Contract work
    For contractors
    Local area
    Remote work

    NANA Regional Corp

    Ashburn, VA
    2 days ago
  • A technology services company is looking for an Incident and Problem Manager in California. The successful candidate will oversee incident management processes, lead a remote team, and drive continual improvement in service delivery. Key qualifications include 3+ years... 
    Remote work

    F3 Design

    Anaheim, CA
    1 day ago
  •  ...Children's 24/7 Mobile Mental Health Crisis Response Teams The Manager of Adult & Children'...  ...and manage risk, and the capacity to lead teams in fast-paced, high-pressure environments...  ...when staffing shortages or critical incidents occur. Review clinical documentation for... 
    Work from home
    All shifts
    Flexible hours
    Afternoon shift

    AltaPointe Health

    Mobile, AL
    2 days ago
  • $70.33k - $90.66k

     ...field-based lessons into broader systems and policy change. Primary Function: This position primarily supports the Eviction Data Response Network (EDRN), a groundbreaking initiative to create the country’s first large-scale eviction data infrastructure and use that... 
    Full time
    Work at office
    Local area
    Immediate start
    Work from home

    New America

    Washington DC
    18 days ago
  • $58k - $62k

     ...Catholic Charities of the Archdiocese of Newark is currently seeking a  Full Time Lead Mobile Response Worker  for its Mobile Response & Stabilization Services Program located in Jersey City, NJ. POSITION DUTIES: Provides mobile crisis intervention and assessment... 
    Full time
    Immediate start

    Catholic Charities of the Archdiocese of Newark

    Jersey City, NJ
    7 days ago
  • $100k - $157k

     ...Position Overview J ob Title Regional Lead, Vulnerability Response Management Corporate Title Vice President Location Jacksonville, FL Overview The Regional Lead for Vulnerability Response Management is responsible for overseeing vulnerability response... 
    Work at office
    Work from home
    Jacksonville, FL
    15 days ago
  • $65.25 - $79.92 per hour

     ...Description We have an opening for a Deployed Team Crafts Supervisor/Responsible Individual (RI) assigned to the Maintenance Production...  ...investigation and completion of documents related to accidents/incidents, and performance management. Solicit technical advice from subject... 
    Hourly pay
    Full time
    For contractors
    Work experience placement
    Relocation package
    Flexible hours

    Lawrence Livermore National Laboratory

    Livermore, CA
    5 days ago
  • $143k - $222k

     ...Position Overview J ob Title Global Lead, Vulnerability Response Management Corporate Title Director Location Jacksonville, FL Overview The Global Lead, Vulnerability Response Management is responsible for defining and leading the enterprise-wide... 
    Full time
    Work at office
    Work from home
    Jacksonville, FL
    15 days ago
  • $175k - $257.15k

     ...partnership with the Vertical Engineering Lead for Tech Labs — needed to embed them...  ...consistently and practically across accounts.Key Responsibilities:Develop and maintain the Tech Labs...  ...are being followed and applied.Support incident management for the lab space —... 
    Full time
    Local area
    Remote work

    Jones Lang LaSalle

    Trenton, NJ
    1 day ago
  •  ...future for local news.Microservices Team Lead — Platform EngineeringThe RoleWe are...  ...Cloud team for infrastructural requisites.Responsibilities:Lead a distributed team of...  ...for your team's domain, including SLAs, incident response, and reducing operational toil... 
    Full time
    Temporary work
    Part time
    Live in
    Local area
    Flexible hours

    Tegna

    Knoxville, TN
    1 day ago
  • $158.6k - $285.5k

    The Role:We are seeking an Associate Director to lead the design, selection, and implementation of enterprise cybersecurity solutions...  ...and execution-control bypass; partner with SecOps and Cyber Incident Response on playbooks and response. Author standards, reference... 
    Permanent employment
    Full time
    Temporary work
    Work at office
    Remote work
    Work from home

    Moderna Therapeutics

    Cambridge, MA
    1 day ago
  • $86.6k - $181.8k

    Job Title: Team Lead- Network Operations - Tier 2Job Category: Information TechnologyTime...  ...and streaming services. Responsibilities:As a Team Lead of our Tier 2 Network Operations...  ...network components to research errors, incidents, problems and to perform incident analysis... 
    Contract work
    Work experience placement
    Remote work
    Flexible hours

    CACI International

    Washington DC
    4 days ago
  •  ...Security Team!Do you possess a strong security operations center background and want to lead others while working on interesting problems and helping to advance incident response capabilities? Have you always wanted to make a real impact on effective delivery of security... 
    Full time
    Work at office
    Remote work

    Crane

    Stamford, CT
    13 hours ago
  • $165k - $185k

     ...DescriptionEverforth ECS is seeking a Cyber Threat Intelligence (CTI) SME (Team Lead) to join our team in Arlington, VA (Hybrid). This position is...  ..., actionable leads for Proactive Threat Hunting (PHB) and Incident Response (IRB) teams. This position is located in Ballston, VA (... 
    Remote work

    ECS Federal

    Arlington, VA
    3 days ago
  •  ...the team.CSDM/CMDB Ownership & Health: Lead CMDB design, governance, and ongoing health...  ....Experience with ITSM modules (Incident, Problem, Change, CMDB) and working knowledge...  ...not intended to describe all duties, responsibilities, and qualifications. At CSC, we’re always... 
    Local area
    Remote work
    Worldwide

    CSC Corporation Service Company

    Wilmington, DE
    2 days ago
  •  ...competitive edge, taking ownership of our responsibilities, being flexible to adapt to ever-...  ...Corporate IT is looking for a Corporate IT Lead to innovate and grow our Corporate...  ...continuous improvements.• Mange Major Incident, Incident, Problem and Change processes... 
    Remote work
    Worldwide
    Flexible hours

    FlexTrade

    Great Neck, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to CSOC Incident Response Lead. Be the first to apply!