Cyber Incident Manager
The Salvation Army Eastern Territory
Overview
The Salvation Army, an international movement, is an evangelical part of the universal Christian Church. Its message is based on the Bible. Its ministry is motivated by the love of God. Its mission is to preach the gospel of Jesus Christ and to meet human needs in His name without discrimination.
We are the largest non-governmental provider of social services in America and every year, we help over 30 million Americans overcome poverty, homelessness, addiction, economic hardships, loneliness, and exploitation through a wide range of programs and services.
Our Eastern Territorial Headquarters' Information Technology Department has an opening for a Cyber Incident Manager. This position will lead the response to cyber incidents, ensuring they are handled promptly and efficiently to minimize damage and reduce recovery time and costs. They play a pivotal role in coordination with various internal and external stakeholders to manage the incident lifecycle from preparation to post-incident review through identification, containment, eradication, recovery, and lessons learned. This position is integral to the cybersecurity framework, serving as the frontline defense against incidents that can compromise sensitive data, disrupt business operations, and damage the organization's reputation. The Cyber Incident Manager is not just a technical role. The role is a strategic position that requires a blend of technical acumen, leadership skills, and business understanding to appropriately address incidents while maintaining customer engagement. This individual is critical in ensuring the organization's resilience against ever-evolving cyber threats.
This position requires approximately 35 hours of work per week and is eligible for a hybrid work arrangement (3 days onsite/ 2 days remote) after three months of employment.
Responsibilities
- Incident Leadership: The Cyber Incident Manager is responsible for taking command during cybersecurity events, orchestrating response efforts, and promptly addressing incidents. This involves quick decision-making, prioritizing tasks, and directing response teams effectively.
- Strategic Planning and Preparedness: Beyond reactive measures, this role demands proactive planning and preparedness. This includes developing, maintaining, and regularly updating incident response plans, ensuring the organization is equipped to handle various cyber incidents. It also involves conducting risk assessments and scenario planning (tabletop exercises) to anticipate potential threats and vulnerabilities.
- Coordination and Collaboration: The position requires extensive coordination with various internal departments (e.g., IT, Legal, HR, and public relations) and external entities (such as law enforcement, cybersecurity firms, and regulatory bodies). This coordination is crucial for a holistic approach to incident management, encompassing technical response, legal compliance, internal and external communications, and post-incident recovery.
- Technical Expertise and Analysis: The Cyber Incident Manager should deeply understand the cyber threat landscape, including the latest trends in cyber-attacks and defense strategies. They are expected to analyze incident patterns and weaknesses, offering insights that drive improvements in the organization’s cybersecurity posture.
- Stakeholder Engagement: Effective communication with stakeholders, including executive leadership, is a key aspect of this role. The Cyber Incident Manager must be able to translate complex technical incidents into understandable terms, advising on the impact, necessary actions, and implications for the business.
- Continuous Improvement and Learning: Post-incident analysis is a critical function. Learning from incidents to improve systems, processes, and training is essential. This role involves regularly reviewing and refining incident response strategies, staying informed about new technologies and methodologies in cybersecurity, and integrating these into the organization’s practices.
- Regulatory Compliance and Documentation: Ensuring that incident response activities adhere to legal and regulatory requirements is paramount. The Cyber Incident Manager maintains comprehensive records of incidents, responses, and outcomes for compliance purposes, audits, and continuous improvement.
- Risk Mitigation: By effectively managing cyber incidents, this role directly contributes to reducing the risk and impact of cyber threats on the organization.
- Operational Continuity: Ensuring rapid and efficient response to incidents minimizes downtime and maintains business operations, which is crucial for the organization’s success and reputation.
- Compliance and Trust: Adherence to compliance standards and effective incident handling enhances the organization's credibility and trust among clients, partners, and regulatory bodies.
Qualifications
- Bachelor's degree from four-year college or university.
- 3-5 years of related experience.
- Technical Skills: • Digital Forensics & Incident Response (DFIR)• Security Information and Event Management (SIEM) (e.g., Splunk, Sentinel, QRadar)• Intrusion Detection/Prevention Systems (IDS/IPS)• Endpoint Detection & Response (EDR) (e.g., CrowdStrike, Darktrace, SentinelOne)• Network Traffic Analysis & Packet Capture (Wireshark, etc.)• Malware Analysis & Reverse Engineering (basic to intermediate)• Log Correlation and Threat Hunting• Firewall, Proxy, and IDS Log Analysis (e.g., Fortinet, Meraki)• Threat Intelligence Integration and Analysis• Email Header and Phishing Analysis• Security Orchestration, Automation, and Response (SOAR) platforms (e.g., Palo Alto XSOAR, Swimlane)• Forensics Tools: EnCase, FTK, Autopsy, Volatility• Threat Intel Platforms: Recorded Future, ThreatConnect, MISP• Ticketing Systems: ZenDesk, ServiceNow, Jira, Remedy
- Framework Proficiency: • Incident Response Lifecycle (NIST SP 800-61, PICERL model)• Knowledge of MITRE ATT&CK Framework• Vulnerability Management & Prioritization• Disaster Recovery & Business Continuity Planning (e.g., DR/BC, BIA)• Risk Assessment & Gap Analysis• Change Control and Root Cause Analysis (RCA)
- Regulatory, Compliance, and Privacy Awareness: • HIPAA, PCI-DSS, NY SHIELD, GDPR, CCPA, CJIS, etc.• SOX ITGC Controls and Audit Support• Cyber Insurance (CLI) & Legal Considerations in Breach Response• Chain of Custody and Evidence Handling
- Leadership and Management Skills: • Relevant certifications (e.g., CISSP, CISM, GCIH, GCFA, CRISC).• Collaboration: Confluence, MS Teams, Slack, Monday.com, Telegram (war room coordination)• Strong leadership and decision-making.• Excellent communication and interpersonal skills.• Deep understanding of cybersecurity frameworks and standards.• Ability to work under pressure and handle crises effectively.
What We Offer
- Generous Medical, Dental, Vision Benefits
- TSA paid Life Insurance for Employees
- Additional life insurance options for employees
- On-site cafeteria
- Paid Time Off – Vacation, Sick, Personal day
- 403(b) retirement savings plan
- Non-contributory Pension Plan
- Professional Development
- Free, on-site Fitness Center
- Federal holidays
- Opportunities to give back and support our communities
All qualified applicants will receive consideration for employment without regard to race, color, sex, national origin, disability or protected veteran status.
- ...the noise to reach and convert the best candidates. Our unified platform uses data and automated technology to help you efficiently manage applications and connect with quality talent - regardless of which recruitment systems you already use. Finally, all the pieces of...SuggestedFor contractors
- ...to work for. If you're as passionate about your future as we are, consider joining our team. KPMG is currently seeking a Cyber Assessment Manager (Penetration Testing) to be part of our Digital Security Group. Responsibilities Conduct comprehensive network and web application...SuggestedLocal areaVisa sponsorshipWork visa
- KPMG is looking for a Cyber Assessment Manager to join their Digital Security Group in Montvale, New Jersey. This role involves conducting penetration tests, leading security assessments, and mentoring team members. Candidates should have extensive experience in cybersecurity...Suggested
$115k - $135k
...Position Overview The Privacy Manager is a member of the FUJIFILM Holdings America Corporation reporting to the Privacy Officer and Data... ...covering critical privacy topics. Support the Fujifilm’s incident and breach response program, ensuring timely intake, assessment...SuggestedRemote workFlexible hours$72.8k
Cyber Store Business Manager (Stony Point RTC) POSITION TITLE: Cyber Store Business Manager STATUS: Exempt DEPARTMENT: 5231 - ShopGoodwill REPORTS TO: Director of Stores SAFETY SENSITIVE: HIGH - Position is subject to pre-employment physical and drug & alcohol screening...SuggestedFlexible hours- ...is hiring for the following full-time direct hire position. POSITION OVERVIEW As a Cyber Security Director , your roles and responsibilities will include: Management of a team of Cyber Security engineers Proficient in conducting risk vs business impact...Permanent employmentFull timeFor contractorsRelocation
$185k - $215k
...Group) is a SOC 2 Type II certified MSSP and cyber advisory firm headquartered in Mahwah, NJ... ...a concentration in Metro NY/NJ, across managed security, GRC, and advisory services. Our... ..., IR readiness) and support active incident response when needed. Brief executive and...Full timeRemote work$72.8k
Goodwill Industries of the Redwood Empire is seeking a Cyber Store Business Manager in Stony Point, NY. This role involves overseeing all operations of the cyber store, managing personnel, and ensuring financial targets are met through effective leadership and customer...- Job Title Cyber Security Analyst Location White plains, NY Job Overview We are seeking... ...through advanced firewall management, implementing Zero Trust security principles... ...Splunk for log analysis, threat hunting, and incident response to identify and neutralize security...Remote work
$105k - $120k
A leading company in health and wellness products is looking for a Cyber Security Analyst to safeguard its digital assets and IT infrastructure. This role involves monitoring security incidents, ensuring compliance with policies, and implementing protective measures. Candidates...$105k - $120k
POSITION PURPOSE The purpose of the Cyber Security Analyst role is to protect the organization... ..., analyzing, and responding to security incidents, ensuring compliance with security... ...SIEM (Security Information and Event Management). Detect, analyze, and respond to potential...Temporary workSummer workWork at officeFlexible hours- ...cybersecurity firm in Woodcliff Lake, New Jersey, is looking for a Cyber Security Analyst to protect their IT infrastructure and digital... ...involves monitoring network traffic, responding to security incidents, and ensuring compliance with regulations. The ideal candidate...Flexible hours
$90k
...Technology, or related discipline, or equivalent practical experience. ~3-5 years of experience in security operations, vulnerability management, or endpoint protection analysis. ~ Exceptional communication and follow-through - keeps others informed and initiates...$75 - $85 per hour
...Akkodis is seeking an IT Project Manager- Cyber Security (Pharma Domain) for a Contract with a client in Tarrytown, NY (Hybrid). The ideal candidate will lead enterprise cyber resilience initiatives by driving delivery of network segmentation, Active Directory transformation...Hourly payContract workTemporary workLocal area- Standing position, Full-Time, NYC Metro, Secret. The next role we open will be filled from the inbox. Reviewed by Founder's desk Quarterly Cybersecurity Analyst (SOC) About the role Monitor and respond to security events in our 24/7 SOC supporting federal and state government...Full timeContract work
- IT Custom Solution is seeking a Cybersecurity Analyst in New City, NY. The role involves monitoring and responding to security events in a 24/7 SOC supporting federal and state government clients. Candidates should have over 3 years of SOC/SIEM experience and relevant certifications...
- ...with 5+ years in security operations. You'll design and implement security detections, conduct vulnerability assessments, and drive incident responses in a dynamic environment. The ideal candidate has experience with various security tools and a strong foundation in...Full time
$135.5k - $183k
...cybersecurity operations and defense including threat assessment, incident handling, and managing vulnerabilities against Atlas Air Global Technology... ...& controls, and procedures. Here is what you will do: Cyber Defense Design, implement, and leverage advanced detections...Local areaWorldwide$115k - $135k
...FUJIFILM Holdings America Corporation is seeking a Privacy Manager to oversee the organization’s enterprise privacy program and ensure compliance across various operations. The successful candidate will manage day-to-day privacy operations while developing policies and...Remote work$168.75k - $281.25k
...and DevOps. You will work across multiple Cyber Fusion Engineering functions including... ...Security Analytics Engineering, Attack Surface Management, and Cyber Threat Intelligence and... ...on disciplines like threat detection, incident response, and risk mitigation. ~ Experience...Full timeWork experience placementWork at officeFlexible hours2 days per week- Ampcus, Inc is seeking a Cyber Security Analyst in White Plains, NY, to protect digital assets through network security management. The role includes implementing Zero Trust models and managing firewalls and VPNs. Ideal candidates will have 3-5 years of experience in cybersecurity...
$185k - $215k
...STIGroup, Ltd. in Mahwah, NJ is looking for a Principal Consultant with extensive experience in cyber security and client engagement. This role requires managing security assessments, GRC engagements, and maintaining strong client relationships. Ideal candidates should...$185k - $215k
Secure Technology Integration Group is looking for a Principal Consultant to oversee engagements in cyber security and GRC advisory. This individual will work closely with clients to enhance their security programs and is expected to identify growth opportunities while...Full time- ...scripts, designing Azure environments, and serving as a Cloud DevOps expert. Ideal candidates have experience in Cloud environment management and must possess a bachelor's degree or equivalent. Our comprehensive benefits package supports your well-being and includes...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Incident Manager. Be the first to apply!

