Cyber Incident Responder
$75k - $87.5kvavemga
The Role Canopius is a market‑leading cyber insurer with an in‑house Cyber Incident Management Team (CIMT) that delivers immediate, expert support to our policyholders during their most critical moments. As an Incident Manager, you’ll be the first point of contact when a client faces a cyber event—whether business email compromise, ransomware, social engineering, data theft, or other attacks. You will triage and lead the response, mobilize our expert panel (forensics, legal, PR, and specialist advisors), and project‑manage recovery from containment through restoration, providing calm, clear communication throughout. Operating in a global, follow‑the‑sun model across Sydney, London, and Chicago, you’ll ensure true 24/7 coverage for new notifications, collaborate closely with our Claims team to support timely coverage assessment, and help clients navigate local legal and regulatory obligations. Sitting at the coal face of live incidents, you’ll also capture structured insights and trends that inform our underwriting, analytics, and ongoing service evolution, all while meeting and exceeding internal SLAs. Responsibilities Own the incident from notification to closure Be the first point of contact for policyholder incident notifications. Rapidly triage, assess severity, and set the response plan and cadence. Orchestrate specialist vendors (IR firms, forensics, legal, PR, ransom advisors), ensuring right‑sized support at the right time. Maintain clear timelines, decisions, and next steps Deliver best in class customer service‑in‑class customer service Provide calm, empathetic guidance under pressure; translate technical issues into clear business impact and options. Set and manage expectations on milestones (containment, restoration, notifications) and costs. Conduct welcome/onboarding calls; explain how to notify, what to expect, and how the IR panel operates. Capture and act on policyholder feedback to continuously improve service. Hit internal SLAs (acknowledgement, triage, vendor mobilization, comms cadence). Operate within a global, 24/7 team model Participate in rota/on call coverage to ensure true follow the sun response. ‑call coverage to ensure true follow‑the‑sun response. Perform structured handovers across regions; maintain accurate case notes and status. Evolve the service offering Contribute to playbook/runbook enhancements and decision trees (e.g., ransomware, BEC, DDoS, data exfil). Recommend panel/vendor improvements and measure vendor SLAs and outcomes. Support content development (guides, FAQs, tabletop scenarios). Collaborate with Claims, Underwriting and Insights & Analytics Partner with the Claims team to ensure smooth coverage confirmation and claim handling. Surface material facts, costs, and causation signals; ensure incident files are complete and timely. Escalate complex matters promptly and appropriately. Sit “at the coal face” of live incidents and distil timely, high-quality insights (threat vectors, controls efficacy, vendor performance, and industry signals). ‑quality insights (threat vectors, controls efficacy, vendor performance, Provide structured post incident summaries and trend themes for underwriters and leadership. ‑incident summaries and trend themes for underwriters and leadership. Ensure precise, consistent capture of incident metadata and outcomes (e.g., root cause, initial access, controls in place, dwell time, MTTA/MTTR, costs). Champion data quality standards; work with Analytics to refine taxonomies and dashboards. Collaborate in delivery of incident preparedness sessions, tabletops, and executive simulations for insureds. ‑deliver incident preparedness sessions, tabletops, and executive simulations for insureds. Feed real world lessons learned into control uplift recommendations. ‑world lessons learned into control uplift recommendations. Skills and Experience A minimum of two years working in the cybersecurity field, ideally with hands‑on involvement in incident handling or response activities. Strong foundational knowledge of cyber‑attack methods, threat behaviors, and the end‑to‑end lifecycle of incident response. Demonstrate ability to solve complex problems and make sound judgements quickly, especially when operating in high pressure or fast‑moving situations. ‑pressure or fast‑moving situations. Excellent organisational habits with a focus on accuracy and thoroughness in all tasks. Clear and confident communication skills—both written and verbal—with the capability to explain technical issues in an accessible way for non‑technical audiences. ‑technical audiences. Basic data skills to partner with Analytics (e.g., Excel/Power BI; familiarity with SQL/Python advantageous). High empathy, composure under pressure, and a service mindset. Salary Range: $75,000 - 87,500 #J-18808-Ljbffr vavemga
$95.6k - $159.3k
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver... ...’ll Do As a PROJECT - Security Engineer II performing as an Incident Responder on the Enterprise Security team, you will be responsible for…...CyberLocal area$91.1k - $170.4k
...Information Security (InfoSec) - InfoSec prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and our information... ...opportunityThe Cyber & Investigative Services (CIS) Junior Incident Coordinator will exercise strong incident management...CyberSummer holidayLocal areaRemote workFlexible hours- ...Incident Commander The Office of Technology and Innovation (OTI) leverages technology to... ...difference through technology. About Cyber Command Cyber Command is charged with protecting... ...offices to protect, detect, identify, respond to, and recover from cyber threats. The...CyberWork at officeImmediate startShift workNight shiftAfternoon shift
- ...MIOS in Arlington, VA seeks a Security Operations Center Analyst to monitor, detect, and respond to cyber threats across program networks. The role includes SIEM monitoring, incident handling, log analysis, and coordination with stakeholders to contain and recover from...Cyber
- Deloitte’s GPS cyber team is seeking a Security Engineer II acting as Incident Responder on the Enterprise Security team in the Colorado Springs area. You will support development and delivery of Incident Response Upgrade Training and contribute to hunting, emulation, and...Cyber
- Canopius is seeking an Incident Manager to be the first point of contact for policyholders during cyber events, triaging and leading responses from containment to restoration. You'll mobilize our expert panel, coordinate with Claims, Underwriting and Analytics, and maintain...Cyber
- EY is seeking a Cyber & Investigative Services Junior Incident Coordinator in Hoboken, NJ. You will coordinate security incident responses, interface with multiple teams, and help maintain incident playbooks and metrics. This role requires strong communication and a collaborative...Cyber
- The Options Clearing Corporation (OCC) is seeking an Associate Principal, Cyber Defense to lead in-depth investigations of security incidents escalated from Tier 1. The role emphasizes advanced threat intelligence usage, incident response, and collaboration with cross-functional...Cyber
$95.7k - $144.9k
...Company success is only possible with a strong cyber defense, which enables Bank of America to... ...candidates with malware analysis and incident response experience. Specific experience... ..., Web, or Endpoint. Responsibilities Respond, triage, and adapt to real-time threats targeting...CyberWork at officeFlexible hoursShift workDay shift$100k - $166k
Position Summary:At JetBlue, cyber security operates across a complex IT environment, encompassing... ...end-user environment.We are seeking an Incident Operations Lead to support the Cyber... ...to improve the organization’s ability to respond to cybersecurity incidents.Support...CyberTemporary workWork experience placementWork at officeImmediate startFlexible hoursNight shift- EY seeks a Cyber & Investigative Services Junior Incident Coordinator to coordinate security incident response and support cyber defense efforts. You will work with multiple teams, manage after-hours incidents, and help improve processes and metrics for leadership reporting...Cyber
- ...is seeking an Enterprise Resiliency Crisis Manager to coordinate the firm’s response to operational disruptions, technology incidents, and cyber events. This role leads preparedness, response coordination, and continuous improvement, partnering with business, technology...Cyber
- Surefire Cyber Inc. is seeking a Director of Digital Forensics and Incident Response to lead complex client engagements from detection through recovery. You will mentor a team of 3-5 forensic professionals, coordinate with cross-functional teams, and partner with insurance...CyberRemote job
- EY is seeking a Cyber & Investigative Services (CIS) Junior Incident Coordinator to coordinate security incident response and manage communications across teams. The role requires hands-on incident response, forensics knowledge, and strong written/verbal skills to handle...Cyber
$160k - $205k
...Development Security Framework Program within Bank of America’s Cyber Security Assurance Offensive Security group. The program... ...assessors in technical tradecraft and soft skills.Respond to security incidents and provide technical assistance to leadership across the...CyberFull timeWork at officeShift workDay shift- ...Troubleshooting application and server issues and responding to federal customer service requests.... ...factors affecting performance. Support incident response efforts by identifying... ...and implement network systems. Perform cyber investigations and analysis. Research and...CyberFull time
$144.9k - $302.1k
...and network sensing solutions to protect client networks from cyber threats. You will work within a team of cybersecurity... ...actively monitor network traffic, analyze security events, and respond to incidents to mitigate risks effectively. Additionally, you will collaborate...CyberFull timeSummer holidayFlexible hours$110k - $160k
...assets; and to detect, prepare for, and respond effectively to security events. To that end... ...and Data Governance; Enterprise Incident Management; Global Security; Technology... ...Requirements : ~ BA or Equivalent ~5+ Years of Cyber Security or consulting experience ~...CyberFull timeContract workLocal area- ...Cyber Security EngineerUnder the general guidance of the IT/Security Architect or Systems... ...e.g. firewall rules, SSL/IPSec, security incident and event management (SIEM), data... ...not afraid of challenging the status quo. Respond swiftly to all alerts, performing initial...CyberFlexible hours
$141.92k - $212.89k
...? As a Senior Principal Risk Specialist, Cyber Engagements, you'll play a pivotal role in... ...workshops that simulate real-world cyber incidents, helping member firms sharpen their... ...vulnerabilities—it's about empowering firms to respond, recover, and thrive in the face of cyber...CyberFull timeTemporary workFor contractorsFor subcontractorLocal areaImmediate start$134.5k - $265.1k
...professional looking to help organizations reduce cyber risk and improve resilience? At Deloitte... ...dataSupporting exception management, incident-driven response activities, and process... ..., support digital transformation, and respond to evolving threats. Within this practice...CyberLocal area- ...and work remotely one day. A member of our recruitment team will provide more details.The analyst for Incident Response Planning and Operations is responsible for cyber security wargaming and incident readiness program. While the focus is the Americas, this role has...CyberFull timeWork experience placementWork at officeLocal areaRemote workHome office1 day per week
$123k - $194k
...remotely one day. A member of our recruitment team will provide more details.Job SummaryThe VP for Incident Response Planning and Operations is responsible for leading the cyber security wargaming and incident readiness program, especially the planning and operational...CyberFull timeWork experience placementWork at officeLocal areaRemote workHome officeShift work$140k - $184k
...provides advanced digital forensics and incident response (DFIR) expertise, supporting investigation... ..., and reverse engineering. Support cyber threat intelligence production, mobile... ...of specialized professional experience responding to information system security incidents...CyberFull timeFlexible hours$91.1k - $170.4k
...services, as well as detect and quickly respond to security events as they happen. Together... ...blend risk strategy, digital identity, cyber defense, application security and technology... ...and respond to information security incidents, develop, maintain, and follow procedures...CyberWork experience placementSummer holidayLocal areaFlexible hoursShift work$104.8k - $192.2k
...alert: Select how often (in days) to receive an alert: Cyber SDC - Zero Trust (ZScaler) - Senior- Location Open Other... ...network infrastructure, conducting risk assessments, and responding to security incidents. At our core, our Zero Trust services play a pivotal role...CyberSummer holidayFlexible hours$134.5k - $265.1k
Position Summary Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a... ...in consulting or professional services • Experience responding to and recovering from cybersecurity incidents • Hands-on experience configuring, tuning, and...CyberLocal areaVisa sponsorship$112k
...Experience documenting, tracking, and monitoring incidents and problems using applicable help desk,... ...service management systems. Experience responding to telephone, email, chat, and online... ...Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. With 2...Cyber- ...team will provide more details.The Global Director of Autonomous Incident Response and Forensic Analysis leads the strategy, execution,... ...planning, vendor management, and financial governance for global cyber operations tooling, services, and staffing; optimize spend to...CyberFull timeWork at officeLocal areaRemote work1 day per week
- ...of defense, responsible for monitoring, detecting, and responding to security events and incidents across both IT and Operational Technology (OT)/Industrial... ...phishing, malware, spam, malicious websites, and other cyber threats. Qualifications & Skills: Associate's degree in...Cyber
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Incident Responder. Be the first to apply!

