Senior Manager - Cyber Operations & Assurance- Incident Response
$123k - $215.25kAmerican Express
Job ID: 26012722Posted: 2026-08-19Location: Phoenix, AZ, United States; Atlanta, GA, United States; Palo Alto, CA, United States; Salt Lake City, UT, United States; Sunrise, FL, United States; Charlotte, NC, United States; New York, NY, United StatesSalary: $123000 - $215250 annually + bonus + benefitsJob Function: CybersecuritySchedule: Full timeShift: DayWorkplace: HybridCareer Area: TechnologyCompany: American ExpressDescriptionJoining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.At American Express, our mission is to deliver the world’s best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage—empowering you to innovate, grow, and help shape the future of a Fortune 100 company.Trust. Service. Security.American Express seeks to recruit a passionate and experienced Leader for its Incident Response team. This is a senior-level, hands-on, highly technical role performing incident response activities ranging from pre-incident preparation, active incident response, and post-incident analysis and recovery. You will be a key technical resource conducting investigations, performing advanced analysis, identifying attacker TTPs, building attack narratives, and executing response actions.As part of our evolution toward a Next Generation Agentic SOC, this role will also help drive the adoption of AI-enabled security operations, intelligent automation, and autonomous analyst workflows. The ideal candidate combines deep incident response expertise with curiosity and practical experience in AI-assisted detection, security automation, and modern SOC engineering practices.You are a motivated leader who will directly manage, mentor, and develop a team of SOC analysts while driving the people, processes, and technology that empower the team to investigate sophisticated threats at scale. This role requires critical thinking, innovative problem solving, technical leadership, people leadership, and effective communication across both technical and executive audiences.ResponsibilitiesPeople Leadership & Team Development Directly lead and manage a team of SOC analysts, including hiring, onboarding, day-to-day supervision, performance management, and career development, fostering a high-performing and engaged team culture.Conduct regular 1:1s, performance reviews, and goal-setting with direct reports; provide timely, constructive feedback and coaching to accelerate individual and team growth.Mentor and develop junior and mid-level analysts, building technical skills, investigative rigor, and professional capabilities across the team; create clear career progression pathways from Tier 1 through senior roles.Manage shift schedules, on-call rotations, and workload distribution to ensure 247 operational coverage while proactively mitigating analyst burnout and maintaining team morale.Drive a culture of continuous learning by identifying training opportunities, encouraging pursuit of industry certifications (e.g., GCIH, GCFA, GCIA), facilitating hands-on exercises (e.g., Immersive Labs, tabletop exercises), and championing knowledge-sharing across the team.Recruit and retain top talent by partnering with HR and hiring managers to define role requirements, conduct interviews, and build a diverse and skilled analyst pipeline.Incident Response & Technical Operations Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations and escalations from junior analysts across Windows, Mac, Linux, Cloud, SaaS, and hybrid environments.Participate in incident response, cyber crisis management, and enterprise-wide security events.Advise leadership on containment, eradication, and recovery strategies during incident response.Fully scope incidents through proper identification of all affected systems, identities, applications, and/or accounts.Recognize attacker tactics, techniques, and procedures (TTPs) as well as Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) applicable to current and future investigations.Serve as a technical escalation point for the analyst team, providing real-time guidance on complex or high-severity investigations and ensuring quality and consistency of investigative outputs.Contribute to team projects, process improvement, and development of new security operations capabilities.Help curate a world-class security operations and incident response program with a relentless focus on innovation, intelligent automation, and continuous improvement.Assess and develop incident response best practices to help mature the overall security operations and AI-assisted defense capabilities of the organization.Produce high-quality written and verbal reports, recommendations, executive briefings, and technical findings.Participate in on-call rotation and provide after-hours support on an as-needed basis.AI-Enabled Security Operations & Automation Partner with detection engineering, threat intelligence, data science, and security engineering teams to operationalize AI-driven detection and response capabilities.Assist in the design, tuning, and oversight of AI-enabled SOC workflows, analyst copilots, and autonomous or semi-autonomous response agents.Develop and optimize prompts, workflows, and guardrails for large language model (LLM) and AI-agent-assisted investigations and triage processes.Evaluate and validate AI-generated investigative outputs to ensure operational accuracy, reliability, explainability, and security.Help identify opportunities to leverage AI/ML, orchestration, and automation technologies to reduce analyst toil and accelerate response times.Participate in development and integration of SOAR playbooks, AI-assisted enrichment pipelines, and security automation frameworks.Contribute to AI governance and operational risk management efforts related to AI-enabled security tooling and workflows.Champion AI adoption within the team by training analysts on AI-assisted tools and workflows, gathering analyst feedback to drive iterative improvements, and ensuring responsible use aligned with organizational governance.Stay current on industry trends, attack techniques, AI-enabled threats, adversarial AI risks, mitigation techniques, and emerging security technologiesQualifications3+ years of experience in information security, security operations, incident response, threat hunting, or cyber defense.Experience with host, network, and/or memory forensics.Experience with various network and/or host-based security tools used to detect and respond to security events (e.g., SIEM, EDR, NDR, SOAR, web proxy, IDS/IPS, cloud-native security platforms, etc.).Theoretical and practical security knowledge and investigation experience with Mac, Linux, Windows, and cloud environments.Strong understanding of incident response lifecycles, attacker methodologies, and cyber kill chain concepts.Experience performing analysis of complex security incidents in enterprise environments.Familiarity with scripting or programming languages such as Python, PowerShell, Go, or similar.Ability to convey complex technical concepts to audiences with varying levels of technical expertise.Strong analytical, investigative, documentation, and communication skills.Demonstrated curiosity and adaptability toward emerging AI-enabled security technologies and workflows.Demonstrated ability to lead, motivate, and develop technical teams in high-tempo, operationally demanding environments.Strong interpersonal and conflict-resolution skills, with the ability to foster a collaborative, inclusive, and psychologically safe team environment.Preferred:1+ years of experience in a people leadership, team lead, or supervisory role, including direct responsibility for coaching, mentoring, or managing technical staff.Experience working within a modern SOC leveraging AI-assisted analysis, security automation, and/or SOAR technologies.Familiarity with AI/ML concepts and practical applications within cybersecurity operations.Experience with prompt engineering, LLM-assisted workflows, or AI copilots for security investigations and operational efficiency.Understanding of AI agent architecture, orchestration frameworks, retrieval-augmented generation (RAG), vector databases, or autonomous workflow concepts.Experience integrating APIs, automation pipelines, or AI-enabled tooling into SOC workflows.Knowledge of adversarial AI threats, prompt injection risks, model misuse, or AI security governance principles.Experience building or operationalizing automated detection, enrichment, triage, or response capabilities.Knowledge and investigation experience in a global, multi-cloud environment.Experience with detection engineering, threat hunting, or behavioral analytics.Familiarity with cloud-native security technologies and telemetry sources.Multiple applicable certifications (GSE, GDAT, GCIA, GCIH, GCFA, GNFA, GCFE, GREM, CCSP, CISSP, CEH, etc.).AI-related certifications or hands-on experience with enterprise AI platforms, orchestration frameworks, or automation tooling.Experience managing performance cycles, conducting calibrations, and building talent development plans within a security operations or SOC environment.Experience managing geographically distributed or shift-based teams supporting 247 operations.Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.
- ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize... ...and the Senior Incident Manager, integrates with cyber defenders when needed, and champions... ...major incidents and produce operational and executive reporting. ~ Excellent...CyberSeniorContract workWork experience placementWork at officeShift work
- ...an Information Security Analyst to coordinate and report on cyber incidents affecting clients. You will implement policies, analyze... ...secure systems and infrastructure across the organization. Responsibilities include incident response design, threat analysis, API integration...Cyber
$105.4k - $207.8k
...Summary Deloitte’s Cyber Services help our... ...with the management of information and technology... ...secure, and reliable operations across the enterprise... ...experience in Cyber Incident Response. This role involves supporting... ...-level employees to senior leaders, we believe...CyberSeniorLocal areaVisa sponsorship- ...The Incident Response Coordinator supports the end‑to‑end response... ...restore normal operations quickly and reduce impact... ...established incident management processes, service... ...escalations to Senior Coordinators and the... ...incidents; engage infra/app/cyber/vendor dependencies....CyberContract workWork experience placementWork at officeShift work
$90.4k - $168.2k
...is currently seeking a Senior Associate, Cyber Operations to join our Enterprise Security... ...Services organization.Responsibilities:Utilize your expertise... ...operations, and incident response to build, operate... ...tasks such as incident management, threat hunting, forensic...CyberSeniorH1bLocal area- ...Contract position for a Senior Network Systems... ...Engineer will be responsible for the... ...include high-rate, assured, and optical communications... ..., and to manage subcontractors. They... ...design, integrate, and operate secure, military communications... ...to meet cyber-security...CyberSeniorContract workFor subcontractorWork at office
- ...proactively guard against cyber threats, and... ...Engineering team operates at the... ...landscape. Our team is responsible for designing, developing... ..., helps the firm manage risk and comply... ....We are seeking a senior engineer who can lead... ...deployment and incident response. Being the...CyberSeniorFull timeTemporary workPart timeImmediate startRemote work
$163.4k - $322.1k
Position Summary Cyber Security Architecture Senior Manager - Strategy, Growth and Transformation Deloitte... ...and application security, and operating model decisions while leading teams... ...Enterprise Security team, you will be responsible for… Leading client engagements...CyberSeniorLocal areaVisa sponsorship- ...the space, air, land, sea and cyber domains in the interest of... ...Description: This role is responsible for supporting production goals... ...lines. The role also supports operational coordination by maintaining... ...requirements, and equipment layout. Assures product and process quality...CyberSeniorLocal area
$100k - $145k
...degree. Must currently possess a DoD security clearance. Responsibilities: Assist in the organization and execution of technical... ...customers across various fields such as space, air, land, sea, and cyber realms, prioritizing national security. Our Salt Lake City,...CyberSeniorFull timeFor subcontractor$105.6k - $132k
...banking with intuitive spend management, bill pay, and travel... ...finance teams to accelerate operations, gain real-time visibility,... ...frameworks for onboarding, quality assurance, escalation management, and... ...QA reviews, reporting, or incident response.Strong judgment around AI...Work at officeRemote workWork from home$113.1k - $208.3k
...within Deloitte, is seeking a Senior Manager to lead the Vendor... ...serves as a strategic leader responsible for defining and executing the... ...technology partners. This role operates at the intersection of technology... ..., Finance, Legal, Cyber, Risk, and Technology to strengthen...CyberSeniorContract workWork at officeRemote workWork from home$93k - $191k
...and driving growth. The Tax Innovation Senior Consultant manages incoming innovation requests end-to-... ...review teams (e.g., Risk, Legal, Cyber, Independence, Procurement), and proactively... ...Technology Services team is responsible for the enablement of standard technology...CyberSeniorWork at officeLocal areaVisa sponsorship$93k - $191k
...encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an... ...Risk Review teams. Key responsibilities include managing a... ..., Legal (OGC), Vendor Cyber, Confidentiality & Privacy... ...and alliance program operations.A successful candidate...CyberSeniorWork at officeLocal areaVisa sponsorshipShift work- Job Summary:The Assurance Experienced Senior will be responsible for coordinating the day-to-day "in-charge" duties of planning, fieldwork, and "wrap-up" to... ...Auditor in charge is responsible to the engagement manager for the day-to-day conduct of the audit work and in particular...SeniorWork at office
- ...solutions for unmet patient needs. Our Senior Manager, Quality Engineering & Quality Assurance position is a unique career... ...ensure smooth and continuous operations of site quality system, quality... ...and may have some budgetary responsibilities. Develop a robust talent development...SeniorFull timeWork experience placement
$93k - $191k
...and driving growth. The Tax Innovation Senior Consultant manages incoming innovation requests end-to-... ...(OGC), Privacy and Confidentiality, Cyber Security, Information Security, and various... ...Technology Services team is responsible for the enablement of standard technology...CyberSeniorContract workWork at officeLocal areaVisa sponsorship- Job Summary:The Assurance Senior Manager is responsible for developing suggestions to improve client internal controls and accounting procedures as well as advising the client on various economic and regulatory risks in a specific industry field of expertise by identifying...SeniorWork at office
$160k - $185k
...companies continuously rated, operating in 64 countries. Founded... ..., third‑party risk management, board reporting, and cyber insurance underwriting;... ...looking for an experienced Senior Engineer to join our... ...infrastructure, and automation. Responsibilities Architect, design, and...CyberSenior- ..., air, land, sea and cyber domains in the interest... .... Job Title: Senior Specialist, Electronic... ...requirements analysis and management, technical... ...technical support during the operational life cycle of the system. Essential Responsibilities: Assist in the planning...CyberSeniorFor subcontractorLocal area
$120k - $150k
...for this Job Click HereJob Description: Cyber Analyst- Forensics/Insider... ...forensics capabilities within a security operations environment. This role blends hands-on... ...operational workflows.Mentor teammates on incident response practices, investigation methods, and tool...Cyber$71.2k - $166.1k
...seeking a skilled Federal Senior Engineer/Architect (... ...role, you will be responsible for leading engineering... ...EHR, and be comfortable operating within a secure and... ...• 3rd party vendor management and engineering project... ...experience • Federal Cyber understanding/experience...CyberSeniorTemporary workFlexible hours$75k - $90k
...Job Title: Senior Manager of Digital Product & Operations Job Level: Senior Level Job Type: Full-Time, Exempt Job Location: Cotopaxi HQ... ...people to explore, adventure, and do good. Job Responsibilities (How You’ll Make An Impact): Digital Product Strategy...SeniorFull timeTemporary workSummer workLive outLocal areaRemote work- ...corporate wide security assurance program that... ...business continuity management, incident management, security... ...strategies, and plans. Responsibilities As a senior subject matter... ...that technology and cyber security plans... ...of information and operational technology terms, equipment...CyberWork experience placement
- ...innovative healthcare accreditation / assurance programs that support trust, transparency, operational excellence, and industry best... ...emerging industry needs. Responsibilities Lead development of new... ...policies, and quality management processes. Monitor emerging...Full timeRemote workFlexible hours
$173.08k - $276.47k
...exciting time to join our team of employee-owners. This opportunity entails being responsible for the project’s contract and change management, workplan, project controls and profitable operations of charge order work on medium size Mega projects. Responsibilities include...SeniorFull timeContract workFor contractors$130k - $150k
Senior Manager, HR Operations (Project Management) The Senior Manager, HR Operations, reporting to the Vice President of HR Operations and Payroll, is responsible for building and leading a scalable HR operations function supporting the post-onboarding employee lifecycle...SeniorContract workWork at officeRelocation packageFlexible hours- ...this role, you will drive the operational excellence behind analytics... ..., improving knowledge management, measuring business impact,... ...manager, product owner, or senior individual contributor within... ...nature, essential duties, and responsibilities of work performed by...SeniorFull timeContract workWork at officeFlexible hours
$128.6k - $192.9k
...Business Development Professional and Senior Project Manager working across the Mountain Region (... ..., and ordinances).Provide quality assurance and quality control for all final products... ...listing of activities, duties or responsibilities that may be required of the employee...SeniorFull timeTemporary workPart timeFor subcontractorCasual workLocal areaFlexible hours- ...solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Senior Specialist, Program Scheduler Job Code: 3... ...Critical Path analysis and the Earned Value Management System and supporting Program Management...CyberSeniorContract workFor subcontractor
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Manager - Cyber Operations & Assurance- Incident Response. Be the first to apply!
- operations manager supervisor Salt Lake City, UT
- hvac operations manager Salt Lake City, UT
- senior director of operations Salt Lake City, UT
- network operations center manager Salt Lake City, UT
- landscape operations manager Salt Lake City, UT
- full time operations manager Salt Lake City, UT
- operations manager Salt Lake City, UT
- elevator operation manager Salt Lake City, UT
- director of corporate operations Salt Lake City, UT
- operations officer Salt Lake City, UT



