Senior Manager - Cyber Operations & Assurance- Incident Response
$123k - $215.25kAmerican Express
Job ID: 26012722Posted: 2026-08-19Location: Phoenix, AZ, United States; Atlanta, GA, United States; Palo Alto, CA, United States; Salt Lake City, UT, United States; Sunrise, FL, United States; Charlotte, NC, United States; New York, NY, United StatesSalary: $123000 - $215250 annually + bonus + benefitsJob Function: CybersecuritySchedule: Full timeShift: DayWorkplace: HybridCareer Area: TechnologyCompany: American ExpressDescriptionJoining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.At American Express, our mission is to deliver the world’s best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage—empowering you to innovate, grow, and help shape the future of a Fortune 100 company.Trust. Service. Security.American Express seeks to recruit a passionate and experienced Leader for its Incident Response team. This is a senior-level, hands-on, highly technical role performing incident response activities ranging from pre-incident preparation, active incident response, and post-incident analysis and recovery. You will be a key technical resource conducting investigations, performing advanced analysis, identifying attacker TTPs, building attack narratives, and executing response actions.As part of our evolution toward a Next Generation Agentic SOC, this role will also help drive the adoption of AI-enabled security operations, intelligent automation, and autonomous analyst workflows. The ideal candidate combines deep incident response expertise with curiosity and practical experience in AI-assisted detection, security automation, and modern SOC engineering practices.You are a motivated leader who will directly manage, mentor, and develop a team of SOC analysts while driving the people, processes, and technology that empower the team to investigate sophisticated threats at scale. This role requires critical thinking, innovative problem solving, technical leadership, people leadership, and effective communication across both technical and executive audiences.ResponsibilitiesPeople Leadership & Team Development Directly lead and manage a team of SOC analysts, including hiring, onboarding, day-to-day supervision, performance management, and career development, fostering a high-performing and engaged team culture.Conduct regular 1:1s, performance reviews, and goal-setting with direct reports; provide timely, constructive feedback and coaching to accelerate individual and team growth.Mentor and develop junior and mid-level analysts, building technical skills, investigative rigor, and professional capabilities across the team; create clear career progression pathways from Tier 1 through senior roles.Manage shift schedules, on-call rotations, and workload distribution to ensure 247 operational coverage while proactively mitigating analyst burnout and maintaining team morale.Drive a culture of continuous learning by identifying training opportunities, encouraging pursuit of industry certifications (e.g., GCIH, GCFA, GCIA), facilitating hands-on exercises (e.g., Immersive Labs, tabletop exercises), and championing knowledge-sharing across the team.Recruit and retain top talent by partnering with HR and hiring managers to define role requirements, conduct interviews, and build a diverse and skilled analyst pipeline.Incident Response & Technical Operations Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations and escalations from junior analysts across Windows, Mac, Linux, Cloud, SaaS, and hybrid environments.Participate in incident response, cyber crisis management, and enterprise-wide security events.Advise leadership on containment, eradication, and recovery strategies during incident response.Fully scope incidents through proper identification of all affected systems, identities, applications, and/or accounts.Recognize attacker tactics, techniques, and procedures (TTPs) as well as Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) applicable to current and future investigations.Serve as a technical escalation point for the analyst team, providing real-time guidance on complex or high-severity investigations and ensuring quality and consistency of investigative outputs.Contribute to team projects, process improvement, and development of new security operations capabilities.Help curate a world-class security operations and incident response program with a relentless focus on innovation, intelligent automation, and continuous improvement.Assess and develop incident response best practices to help mature the overall security operations and AI-assisted defense capabilities of the organization.Produce high-quality written and verbal reports, recommendations, executive briefings, and technical findings.Participate in on-call rotation and provide after-hours support on an as-needed basis.AI-Enabled Security Operations & Automation Partner with detection engineering, threat intelligence, data science, and security engineering teams to operationalize AI-driven detection and response capabilities.Assist in the design, tuning, and oversight of AI-enabled SOC workflows, analyst copilots, and autonomous or semi-autonomous response agents.Develop and optimize prompts, workflows, and guardrails for large language model (LLM) and AI-agent-assisted investigations and triage processes.Evaluate and validate AI-generated investigative outputs to ensure operational accuracy, reliability, explainability, and security.Help identify opportunities to leverage AI/ML, orchestration, and automation technologies to reduce analyst toil and accelerate response times.Participate in development and integration of SOAR playbooks, AI-assisted enrichment pipelines, and security automation frameworks.Contribute to AI governance and operational risk management efforts related to AI-enabled security tooling and workflows.Champion AI adoption within the team by training analysts on AI-assisted tools and workflows, gathering analyst feedback to drive iterative improvements, and ensuring responsible use aligned with organizational governance.Stay current on industry trends, attack techniques, AI-enabled threats, adversarial AI risks, mitigation techniques, and emerging security technologiesQualifications3+ years of experience in information security, security operations, incident response, threat hunting, or cyber defense.Experience with host, network, and/or memory forensics.Experience with various network and/or host-based security tools used to detect and respond to security events (e.g., SIEM, EDR, NDR, SOAR, web proxy, IDS/IPS, cloud-native security platforms, etc.).Theoretical and practical security knowledge and investigation experience with Mac, Linux, Windows, and cloud environments.Strong understanding of incident response lifecycles, attacker methodologies, and cyber kill chain concepts.Experience performing analysis of complex security incidents in enterprise environments.Familiarity with scripting or programming languages such as Python, PowerShell, Go, or similar.Ability to convey complex technical concepts to audiences with varying levels of technical expertise.Strong analytical, investigative, documentation, and communication skills.Demonstrated curiosity and adaptability toward emerging AI-enabled security technologies and workflows.Demonstrated ability to lead, motivate, and develop technical teams in high-tempo, operationally demanding environments.Strong interpersonal and conflict-resolution skills, with the ability to foster a collaborative, inclusive, and psychologically safe team environment.Preferred:1+ years of experience in a people leadership, team lead, or supervisory role, including direct responsibility for coaching, mentoring, or managing technical staff.Experience working within a modern SOC leveraging AI-assisted analysis, security automation, and/or SOAR technologies.Familiarity with AI/ML concepts and practical applications within cybersecurity operations.Experience with prompt engineering, LLM-assisted workflows, or AI copilots for security investigations and operational efficiency.Understanding of AI agent architecture, orchestration frameworks, retrieval-augmented generation (RAG), vector databases, or autonomous workflow concepts.Experience integrating APIs, automation pipelines, or AI-enabled tooling into SOC workflows.Knowledge of adversarial AI threats, prompt injection risks, model misuse, or AI security governance principles.Experience building or operationalizing automated detection, enrichment, triage, or response capabilities.Knowledge and investigation experience in a global, multi-cloud environment.Experience with detection engineering, threat hunting, or behavioral analytics.Familiarity with cloud-native security technologies and telemetry sources.Multiple applicable certifications (GSE, GDAT, GCIA, GCIH, GCFA, GNFA, GCFE, GREM, CCSP, CISSP, CEH, etc.).AI-related certifications or hands-on experience with enterprise AI platforms, orchestration frameworks, or automation tooling.Experience managing performance cycles, conducting calibrations, and building talent development plans within a security operations or SOC environment.Experience managing geographically distributed or shift-based teams supporting 247 operations.Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.
- Richemont is seeking a Senior Associate in Cyber Incident Response to protect against cyber threats and analyze security events in New York. The role involves incident management, detailed analysis of cybersecurity threats, and collaboration with IT and security teams to...CyberSenior
- Wilson Elser is seeking a Senior Cyber Incident Response Attorney to lead complex cybersecurity breach responses and privacy matters for clients nationwide. This fully remote role emphasizes defending cybersecurity-related cases and advising on regulatory obligations....CyberSeniorRemote job
$110k - $125k
Fox Rothschild in Atlantic City is seeking a Senior Analyst for Cybersecurity Operations & Response. This role involves supporting the execution and improvement... ..., and a bachelor’s degree. Duties include incident response, monitoring security tools, and collaborating...CyberSenior- Fox Rothschild is seeking a Senior Analyst for Cybersecurity Operations & Response to enhance the Firm's security initiatives. You... ...operations, administer programs, and engage in incident response activities to protect firm assets from cyber threats. The ideal candidate will...CyberSenior
- New York Life is seeking a Security Operations Center (SOC) Analyst to protect our enterprise... ..., detect, investigate, and respond to cyber threats using SIEM, EDR/XDR, and cloud... ...and remediation. You will develop incident response playbooks, conduct threat hunting, and...CyberSenior
$155k - $200k
Wilson Elser is recruiting a Senior Cyber Incident Response Attorney for a fully remote role. Though based in New Orleans, we welcome applicants nationwide and may place to other regional offices. You will lead breach response, coordinate with clients and carriers, and...CyberSeniorRemote job$155k - $200k
...valued and empowered, then we invite you to apply to our Senior Cyber Incident Response Attorney position. While the position is based in our New... ...response work by AssociatesInteraction with senior level management and technical personnel at client companiesAnalysis of state...CyberSeniorFull timeWork at officeRemote workFlexible hours- ...legal entity. Responsibilities In this role,... ...lead high-impact incident response work in... ...Communications, Support, and senior leadership to... ...You’ll directly manage a team of 5-8 in... ..., and documented operating procedures.What... ...high-severity cyber incidents will help...CyberSeniorWork at officeLocal area
$155k - $200k
...valued and empowered, then we invite you to apply to our Senior Cyber Incident Response Attorney position. While the position is based in our New... ...response work by Associates Interaction with senior level management and technical personnel at client companies Analysis of...CyberSeniorFull timeWork at officeRemote workFlexible hours- Andersen is looking for a Senior Associate, Security Operations to join its expanding... ...This role is pivotal in managing day-to-day security operations... ...managed detection and response provider. The ideal candidate... ..., proficiency in incident response, and strong communication...Senior
- Senior Manager, Cybersecurity Operations New York, New York, United States The NFL Cybersecurity... ...Operations team is responsible for safeguarding the organization... ...monitoring, rapid incident response, and proactive... ...enterprise against an evolving cyber threat landscape. We are...CyberSenior
- A leading fitness technology company is seeking a Senior Cyber Analyst. You will support their Security Program, perform in-depth intelligence analysis, and develop incident response protocols. The ideal candidate will have at least 5 years of experience in Information...CyberSenior
- ...Companies Inc. in New York City is seeking a CTR Lead to coordinate incident response, investigate threats, and guide containment, remediation,... ...active security events. You will collaborate with Security Operations, IT, Legal, Privacy, and external partners to ensure timely...Cyber
$25 - $30 per hour
Dormont Manufacturing Co is seeking an Incident Response and Threat Intelligence Analyst in New York to enhance cybersecurity and respond to... ...analysis, ensuring the organization is protected against fraud and cyber incidents. This role offers an hourly pay range of $25.00-$30...CyberHourly pay$72k - $184.44k
...people in audit and assurance focus on providing independent... ...governance and risk management processes and related... ...and controls, cyber security measures, data... ...our clients. As a Senior Associate, you will leverage... ...-edge digital assets.Responsibilities- Build and nurture...CyberSeniorFull timeH1bWork at office- Resilience is a cybersecurity company delivering integrated cyber risk solutions. A Claims Specialist will own investigations and manage Cyber, Tech E&O, and Miscellaneous Professional Lines claims, connecting incident response with risk management. In this role you collaborate...Cyber
$119k - $299.93k
...people in audit and assurance focus on providing... ...governance and risk management processes and... ...processes and controls, cyber security measures,... ...reporting, compliance, and operational processes. As a Senior Manager you will... .... You will be responsible for managing financial...CyberSeniorFull timeH1b- ...Attorney to serve as the firm’s lead legal advisor on cybersecurity matters, incident response, data protection laws, and cyber governance across broker‑dealer and investment advisory operations. The ideal candidate will bring deep financial services experience, strong...Cyber
$75k - $100k
The Incident Response Analyst is responsible for monitoring, investigating... ...investigating and remediating cyber events. Comprehend current... ...of Windows, Mac, and Linux operating systems. iOS and Android mobile... ...peers, partner teams, and management. Enjoys thinking analytically...CyberFull time- ...Overview As our IT/OT Security Engineer & Incident Response Lead, you'll be a hands-on security... ...engineering and incident coordination, while our managed 24×7 SOC handles monitoring and first... ...lead and Incident Commander during cyber events. Validate and authorize SOC-...CyberRemote work
$250k - $400k
...the delivery of complex cyber incident response cases in the Americas, and... ...commercial, financial, and operational management for CIR in the Americas.... ..., Advisory, and Assurance teams to drive deeper market... ...eradication and recovery and senior stakeholders through key...CyberWork at officeRemote workFlexible hours- BCG Attorney Search in New York City seeks an Incident Response Associate for its Privacy and Cyber practice. The ideal candidate will have 4-6 years of incident... ...and regulators, advise on privacy programs, and manage client relationships with minimal supervision. This...Cyber
- Cloud Incident Responder (Vice President) Apply (opens in new window... .... Citi's Cloud Incident Response (Cloud IR) team seeks a... ...incidents and strategically managing security risks in a timely... ...objectives with the wider Cyber Security Operations priorities at Citi, driving...CyberFull time
$200k - $220k
A technology solutions provider is seeking a Head of Cyber Incident Response & Threat Mitigation to lead incident response teams and design proactive strategies. The ideal candidate has over 7 years of technology experience and strong leadership in cybersecurity, particularly...CyberFull time- Job OverviewA law firm seeks an Incident Response Associate to join their Privacy and Cyber practice group in New York City, NY. The ideal candidate will have 4... ...Strong analytical and communication skills. Ability to manage caseloads and client relationships independently....Cyber
- A cybersecurity consulting firm in the United States is seeking a Senior Technical Project Manager. This role involves leading restoration efforts for large-scale cybersecurity incidents, managing multiple complex dependencies, and serving as a strategic point of contact...CyberSenior
- ...wherever global businesses operate. Transforming into a technology... ...Systems. Summary: The Senior Detection and Response Analyst role will provide ongoing... ...for all security incidents; provide expert level feedback... ...perform in-depth analysis using Cyber Threat Intelligence,...CyberSeniorWork at officeWorldwideShift work
$92.5k - $105k
...critical strategy and operational issues to become... ...- economic and management consulting - are delivered... ...of, and in response to, data security... ...threat analysis, incident response and malware... ...on the adequacy of cyber security controls... ...from an assigned senior colleague. Additional...CyberWork experience placementWork at officeImmediate startWork from home3 days per week£60k per year
Senior Cyber Security Analyst | ISO 27001 | £60,000 per annum | Remote... ...security activities across incident response, risk and vulnerability management, third-party assurance, and regulatory compliance aligned... .... Beyond day-to-day operations, you will actively shape and...CyberSeniorRemote job- ...We are currently seeking a Manager, Incident Response to join our Advisory practice... ...and manage cyber incident response activities... ...effectively—including presenting to senior executivesDemonstrated professionalism... ..., and safeguard business operations and company reputation....CyberWork experience placementH1bLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Manager - Cyber Operations & Assurance- Incident Response. Be the first to apply!
- strategy & operations manager New York, NY
- program operations manager New York, NY
- operations manager supervisor New York, NY
- web operations manager New York, NY
- partner operations manager New York, NY
- managing director of operations New York, NY
- hvac operations manager New York, NY
- senior director of operations New York, NY
- network operations center manager New York, NY
- associate director clinical operations New York, NY
