Head of Cyber Incident Response
$152.29k - $250.2kThe Guardian Life Insurance Company of America
Head of Cyber Incident Response Position Overview Are you passionate about leading complex cyber incident response efforts while remaining deeply technical? This role sits at the intersection of hands‑on incident response, threat mitigation, and team leadership. You will be part of a highly collaborative cyber defense organization, leading the response to high‑impact security incidents while mentoring and developing the next generation of incident responders. The ideal candidate is an analytical, curious, and resilient technical leader with a strong investigative mindset and a desire to reduce risk through decisive action. You bring deep knowledge of modern attack techniques and frameworks, communicate clearly under pressure, and naturally step in to lead during critical situations. You thrive in partnership working closely with security, IT, legal, HR, communications, and business teams to drive effective identification, containment, investigation, response, and recovery. As a leader within Guardian’s cybersecurity organization, you are expected to think big, accelerate operational excellence, and lead through change with confidence and courage scaling both technical impact and team capability in a rapidly evolving threat landscape. Qualifications 7-10 years of overall cybersecurity experience with a focus in digital forensics, incident response, SOC, or threat mitigation. Broad and deep technical expertise across enterprise environments, including public cloud and SaaS platforms. 3+ years of security leadership experience, ideally in incident response or cyber defense, with a player/coach mindset. Strong command of incident response methodologies, digital forensics principles, and evidence handling. Knowledge and experience in threat hunting, malware analysis, attacker techniques, and common vulnerabilities. Practical experience working with NIST CSF, MITRE ATT&CK, and related security frameworks. Hands‑on experience with SIEM and log analytics platforms including logging, monitoring, insider threat, and UBA concepts. Ability to translate cyber threat intelligence into actionable detections, mitigations, and response strategies. Experience operating in regulated environments, preferably financial services or insurance, with understanding of U.S. privacy regulations. Proven ability to lead, mentor, and develop high‑performing technical teams. Strong written and verbal communication skills, with experience engaging technical teams, executives, and cross‑functional partners. Analytical, curious, and resilient under pressure; able to think structurally and creatively during incidents. BS or MS in cyber security, digital forensics, or equivalent experience and/or industry certifications preferred. Continuous, lifelong learner with a desire to grow into broader cyber leadership. Responsibilities Lead and mentor a team of incident response and forensics professionals. Serve as senior escalation point within the team responsible for investigating complex, high‑impact cyber incidents advanced from the SOC. Act as incident commander or technical lead, coordinate response actions with leadership across cybersecurity teams while collaborating with legal, enterprise technology, engineering, and other internal teams. Manage the organization’s Corporate Cyber Incident Response capability, including coordination and execution. Develop, maintain, and test incident response plans, playbooks, quick‑reference guides, and crisis communication procedures. Partner with first‑line SOC teams to build muscle memory, clarify containment authorities, and standardize response actions. Coordinate with business continuity/disaster recovery teams to ensure an integrated response to large‑scale cyber events. Drive continuous improvement of logging, monitoring, detection coverage, and UBA capabilities, proactively identifying gaps. Ensure incidents are tracked, reported, and reviewed, with high‑quality after‑action reports and meaningful metrics. Manage third‑party incident response retainers, readiness exercises, and periodic simulations. Collaborate across teams through hosting of cross‑functional incident response training events and debriefs to align on threats, trends, and lessons learned. Champion risk mitigation initiatives and improvements to security control effectiveness. Collaborate with cybersecurity leadership on strategy, roadmap development, vendor management, and talent planning. Contribute to enterprise programs such as DLP and insider risk management. Support internal and external audits, regulatory requests, and due diligence activities. Continuously identify opportunities to enhance incident response maturity, automation, and cyber defense capabilities. Drive user behavior analytics (UBA) program working with the business to develop and improve appropriate logging monitoring. Develop standard operating procedures for the 1st line SOC based on threats/observed incidents. Location and Travel Three days a week at a Guardian office in New York, NY or Holmdel, NJ. 20% travel to other Guardian offices as needed. Salary Range $152,290.00 – $250,195.00. The salary range reflected above is a good faith estimate of base pay for the primary location of the position. The salary for this position ultimately will be determined based on the education, experience, knowledge, and abilities of the successful candidate. In addition to salary, this role may also be eligible for annual, sales, or other incentive compensation. Equal Employment Opportunity and Accommodations Guardian is an equal opportunity employer. All qualified applicants will be considered for employment without regard to age, race, color, creed, religion, sex, affectional or sexual orientation, national origin, ancestry, marital status, disability, military or veteran status, or any other classification protected by applicable law. Guardian is committed to providing access, equal opportunity and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. Guardian also provides reasonable accommodations to qualified job applicants (and employees) to accommodate the individual’s known limitations related to pregnancy, childbirth, or related medical conditions, unless doing so would create an undue hardship. Visa Sponsorship Guardian is not currently or in the foreseeable future sponsoring employment visas. In order to be a successful applicant you must be legally authorized to work in the United States, without the need for employer sponsorship. #J-18808-Ljbffr
- ...A leading cybersecurity consultancy is seeking a strategic leader to head Cyber Incident Response in the Americas. Candidates must have over 15 years of experience and a proven track record with C-level executives in Fortune 500 companies. The role involves delivering...Cyber
- 600 Mobility Tech Solutions LLC is seeking a Cyber Security Engineer to join its Information Security & Cyber Security team. The ideal candidate will have strong experience in incident response, digital forensics, and threat detection, ensuring robust security measures...Cyber
- ...Ashland Inc. seeks a Cyber Security Manager: Incident Detection and Response for a remote role. The successful candidate will lead a blended team and oversee cyber incident investigations while ensuring compliance with robust security operations. Candidates must have 7...CyberRemote work
- ...Richemont is seeking a Senior Associate in Cyber Incident Response to protect against cyber threats and analyze security events in New York. The role involves incident management, detailed analysis of cybersecurity threats, and collaboration with IT and security teams...Cyber
- ...Neier Inc. is looking for a Manager of Cyber Defense to lead their team based in the United States. This role includes responsibilities such as supporting the company’s security... ...posture by handling cybersecurity threats and incidents, leading incident response activities,...CyberRemote work
$164.18k - $196k
...Remote Jobs is seeking a Lead Analyst, Cyber Defense to enhance cybersecurity at the University of Southern... ...-time remote role focuses on cyber detection, response, and threat-informed defense. The candidate will lead incident investigations, manage security breaches, and...CyberFull timeRemote work- ...Carlsbad Tech is seeking an experienced Cyber Security Engineer to work onsite in Franklin or Madison County, Ohio. The role demands... ...0 years of experience in network security, threat detection, incident response, and vulnerability management. Responsibilities include...Cyber
- ...collaboration with cross-functional teams within the organization. This leader will oversee critical cybersecurity functions including incident response, threat detection, and team accountability, while providing insights into security metrics to enhance Alkami's defensive...Cyber
- ...mSupply is searching for a Manager of Cyber Security to execute the organization’s security program while leading a team... ...requiring strong technical execution and compliance experience. Responsibilities include incident response and management of security tools to ensure the...CyberRemote work
- ...A cybersecurity firm is hiring an Emergency Response Team (ERT) Security Analyst in the United States. This role involves direct client interaction during cyber incidents, requiring a strong understanding of network security and troubleshooting skills. You will work in...CyberRemote work
- ...A leading global financial institution is seeking a VP for Incident Response Planning and Operations in Jersey City, NJ. This role will lead the cyber security wargaming and incident readiness program, ensuring teams are well-prepared for incidents. Key qualifications...Cyber
- ...A global cybersecurity consultancy is seeking an Incident Response Engagement Lead to manage cyber incidents and lead a team of experts. The role involves project management, relationship building, and effective incident response. Ideal candidates should possess strong...Cyber
$150k - $185k
...Summary The Cybersecurity Incident Response Team Lead is a leadership role responsible for leading and enhancing the bank’s Security Operations... ...business objectives. Provide thought leadership on emerging cyber risks and recommend proactive measures to mitigate them....Cyber- ...Rapid Strategy, a leading cybersecurity provider, is seeking a mid-level resource to support Cyber Operations with a non-profit client. This role demands expertise in incident response and vulnerability management using tools like CrowdStrike and Microsoft Security suite....Cyber
$120k - $135k
A global multi-manager hedge fund is seeking a Cybersecurity Analyst to enhance security controls and manage incident response. The ideal candidate will have 2-3 years of experience and a strong background in vulnerability management, incident response, and security operations...Cyber- A governmental services provider is seeking a Cyber Command Forensic Analyst to investigate network intrusions and cyber incidents. Responsibilities include developing forensic techniques, managing analysis labs, and ensuring evidence integrity. Ideal candidates will have...Cyber
- Aegistech is seeking a Cyber Incident Response Analyst to enhance their security program. This role involves detecting and responding to security incidents, collaborating with Security Operations and Threat Intelligence teams to ensure comprehensive incident management....Cyber
- A leading cybersecurity firm in Kentucky seeks an experienced L2 Cyber Security Analyst to manage incident response and conduct advanced threat hunting. The ideal candidate will have a bachelor's degree in Computer Science or a related field, with proven experience in...Cyber
- ...seeking a skilled cybersecurity professional to serve as a senior technical escalation point for high-profile incidents. You will lead complex incident responses, mentor CERT Specialists, and drive the development of actionable strategies for improving cybersecurity...CyberWork at office
- ...cybersecurity professional with strong digital forensics and incident response experience to support a 24x7 operations environment. The role... ...0.00 to $90.00/hr. w2 Responsibilities Support a 24x7 cyber operations center through cyber incident investigation, triage...Cyber
- ...Job Summary Ashland Inc. seeks a Cyber Security Manager: Incident Detection and Response for a remote role, reporting to the Cyber Security Director. Responsibilities Lead, mentor, and develop a blended IDR team (IR, SOC operations, threat detection, and security tooling...CyberRemote work
- ...Geneva, Lisbon, Porto and Casablanca. Context: Our client (International Investment Bank) is strengthening its Cybersecurity Incident Response capabilities by seeking a CSIRT Consultant. The consultant will play a key role in managing and responding to security...Cyber
$99k - $232k
...focus on protecting organisations from cyber threats through advanced technologies and... ...safeguard sensitive data. In cybersecurity incident management at PwC, you will focus on... ...of client systems and data. You will be responsible for identifying, analysing, and...CyberFull timeH1b- ...Title: Junior Third-Party Incident Response Analyst & Digital Forensics Analyst Location: New York, NY 10004 Duration: 12 Months... ...is a part of the IT Threat Intelligence group within the Cyber Security Operations Center and will be expected to provide direct...CyberContract work
- ...We have a new and exciting role available within our Cyber Security division for an Incident Response Engagement Lead in the United States. S-RM is a global intelligence and cybersecurity consultancy. Since 2005, we’ve helped some of the most demanding clients in the...CyberImmediate startFlexible hours
- ...The Guardian Life Insurance Company of America is seeking a Head of Cyber Incident Response to lead incident response efforts and mentor a team of professionals. This pivotal role requires a candidate with extensive experience in cybersecurity, particularly in incident...Cyber
$100k - $185k
...A global intelligence firm is seeking a Cyber Incident Response Analyst to join its Cyber Defence team. The successful candidate will coordinate cybersecurity responses, integrate threat intelligence, and develop operational playbooks. Candidates should have a solid grasp...Cyber$80k - $95k
...to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what... ..., this is the right place to build a fulfilling career. Cyber Incident Response - Sr Analyst Background: The Cyber Incident...CyberLocal area$122.3k - $269.5k
...role involves providing expert skills in digital forensics and incident response to support TMHCC insureds. The ideal candidate will have a... ...leading DFIR teams, including incident response and complex cyber investigations. Work is remote with overtime as needed. Compensation...CyberRemote work- ...A leading global financial services firm is seeking a VP for Incident Response Planning and Operations in Jersey City, NJ. The ideal candidate will lead the cyber security wargaming and incident readiness program, ensuring robust incident response capabilities. Responsibilities...Cyber
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Head of Cyber Incident Response. Be the first to apply!
- head of rewards New York, NY
- head of seo New York, NY
- head New York, NY
- head of portfolio management New York, NY
- head of copy New York, NY
- head of architecture New York, NY
- head golf professional New York, NY
- head credit administration New York, NY
- head coach New York, NY
- cyber threat intelligence analyst New York, NY


