Lead, Incident Operations
$100k - $166kJetBlue
Position Summary: At JetBlue, cyber security operates across a complex IT environment, encompassing traditional data centers, Software as a Service (SaaS) services, multiple cloud providers, e-commerce platforms, and a diverse end-user environment. We are seeking an Incident Operations Lead to support the Cyber Security Incident Response function through incident coordination, stakeholder communication, readiness, documentation, and post-incident follow-through. The ideal candidate is security-fluent, highly organized, comfortable operating during high-pressure events, and able to translate technical findings into clear actions and leadership-ready updates. This role works closely with technical Incident Response analysts, but is focused on continuous improvement of and leading the operational execution of Incident Response and supporting the technical investigators. Essential Responsibilities: Lead the operational coordination of cybersecurity incidents, including bridge management, stakeholder communication, action tracking, handoffs, documentation, and leadership-ready status updates. Coordinate response activity across Incident Response, Threat Intelligence, Detection Engineering, Security Monitoring, IT Operations, Identity, Infrastructure, application teams, Legal, Communications, vendors, and other stakeholders as needed. Support incident declaration, escalation, severity alignment, communication cadence, and response workflow execution in accordance with established incident response procedures. Translate technical findings, timelines, risks, containment actions and remediation status into clear summaries for leadership and non-technical stakeholders. Maintain accurate incident records, including timelines, key decisions, attendees, action items, evidence references, follow-up owners, and closure documentation. Drive post-incident follow-through by converting lessons learned, gaps, and corrective actions into tracked issues with owners, due dates, updates, and closure evidence. Identify gaps in incident readiness, including access, tooling, logging, escalation paths, contact lists, documentation, playbooks, templates, evidence handling, and cross-team dependencies. Develop, maintain, and improve incident response procedures, bridge guidance, communication templates, after-action processes, tabletop materials, and response readiness documentation. Coordinate tabletop exercises, readiness reviews, control tests and follow-up tracking to improve the organization’s ability to respond to cybersecurity incidents. Support operational prioritization during high-volume periods or active incidents by helping organize response activity, reduce coordination friction, and maintain visibility into outstanding work. Provide guidance to analysts and stakeholders on incident documentation, communication expectations, escalation hygiene, and action tracking during response activities. Other duties as assigned. Minimum Experience and Qualifications: Bachelor’s Degree in Cyber Security, Information Technology, Computer Science, Business, Emergency Management, or other relevant discipline; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience in cyber security operations, incident response, technology incident management, enterprise IT operations, or a related field. Four (4) years of experience coordinating or supporting cybersecurity incidents, technology incidents, security operations, or similar high-priority operational response activities. Demonstrated security fluency, including the ability to understand incident response concepts, common security events, severity/risk, containment, remediation, evidence handling, and escalation needs. Experience managing incident calls, operational bridges, action trackers, status updates, stakeholder communications, or cross-team response coordination. Strong written and verbal communication skills, including the ability to summarize complex technical information clearly for technical and non-technical audiences. Ability to organize ambiguous information into clear priorities, owners, actions, timelines, risks, and decisions during time-sensitive events. Ability to work effectively with technical responders without micromanaging investigation steps, while ensuring response activity remains structured, documented, and moving forward. Strong problem-solving, judgment, ownership, and follow-through skills in a fast-paced operational environment. Ability to manage multiple priorities, stakeholders, issues, and deadlines at once. Ability to pass a live scenario-based interview or skills demonstration with JetBlue Crew Members. Available and willing to participate in periodic on‑call duties and off‑hours Incident Response as required. Available for occasional overnight travel (10%). Must pass a pre‑employment drug test. Must be legally eligible to work in the country in which the position is located. Authorization to work in the United States is required. This position is not eligible for visa sponsorship. Must be eligible to hold a US government security clearance if JetBlue deems it relevant to the role. Preferred Experience and Qualifications: Five (5) or more years of experience in cybersecurity operations, incident response, security operations, technology incident management, crisis management, or a similar operational leadership function. Experience serving as an Incident Commander, Incident Manager, Cyber Incident Coordinator, Response Lead, Major Incident Manager, CSIRT Coordinator, or similar role. Experience working in or closely with a SOC, Incident Response team, Threat Detection team, managed security provider, or enterprise cyber security organization. Familiarity with SIEM, EDR, SOAR, case management, ticketing, identity, email security, cloud security, endpoint security, and network security concepts. Experience with platforms such as Splunk, Microsoft Defender, SentinelOne, XSOAR, ServiceNow, Jira, or similar investigation, response, and work tracking tools. Experience developing or maintaining incident response playbooks, runbooks, communication templates, after‑action reports, tabletop exercises, metrics, dashboards, or process documentation. Familiarity with cybersecurity incident response frameworks or practices such as NIST SP 800‑61, CSIRT operating models, MITRE ATT&CK, ITIL Major Incident Management, or similar guidance. Experience coordinating legal, communications, executive leadership, vendor, or external partner involvement during significant incidents or operational events. Experience tracking corrective actions, remediation items, issue backlogs, control gaps, or cross‑team dependencies to closure. Airline, transportation, critical infrastructure, or large‑enterprise experience in Security Operations, Incident Response, Threat Detection, Technology Operations, or Crisis Management. Relevant certifications such as Security+, CISSP, GCIH, GCIA, GCFA, PMP, ITIL, or similar security, incident management, or project management credentials. Strong sense of urgency, professionalism, ownership, and desire to continuously improve incident response readiness and execution. Crewmember Expectations: Regular attendance and punctuality. Potential need to work flexible hours and be available to respond on short notice. Able to maintain a professional appearance. When working or traveling on JetBlue flights, and if time permits, all capable crewmembers are asked to assist with light cleaning of aircraft. Organizational fit for the JetBlue culture, that is, exhibit JetBlue's values of Safety, Caring, Integrity, Fun and Passion. Promote JetBlue's #1 value of safety as a Safety Ambassador, supporting JetBlue's Safety Management System (SMS) components, Safety Policy and behavioral standards. Must fulfill safety accountabilities as prescribed by JetBlue's Safety Management System. Responsible for adhering to all applicable laws, regulations (FAA, OSHA, DOT, etc.) and Company policies, procedures and risk controls. Responsible for ensuring crewmembers have requisite training, resources and support to achieve safety objectives. Identify safety and security concerns, issues, incidents or hazards that should be reported and report them whenever possible and by any means necessary including JetBlue's confidential reporting systems (Aviation Safety Action Program (ASAP) or Safety Action Report (SAR)). The use of ChatGPT or any other automated tool during the interview process will disqualify a candidate from being considered for the position. Equipment: Computer and other office equipment. Work Environment: Traditional office environment. Physical Effort: Generally not required, or up to 10 pounds occasionally, 0 pounds frequently. (Sedentary) Compensation: The base pay range for this position is between $100,000 and $166,000 per year. Base pay is one component of JetBlue's total compensation package, which may also include access to healthcare benefits, a 401(k) plan and company match, crewmember stock purchase plan, short-term and long-term disability coverage, basic life insurance, free space available travel on JetBlue, and more.
#LI-AC1
- LI-Hybrid
- J-18808-Ljbffr JetBlue
- ...analyst L3 is responsible for the daily operations of IR alerts/tickets, triaging, investigating... ..., and escalating security alerts and incidents, managing IR tools and services, and... ...tools and services. Act as the Incident Lead during significant security events....OperationsLocal areaWorldwide
$10k
...What You’ll Do Respond and assist with security requests and incidents submitted by Ramp team members Review logging, alerting, and audit... ...Security Incident Response Center (CSIRC) or a Security Operations Center (SOC) Experience with query-based log management solutions...OperationsFull timeWork experience placementWork at officeHome officeRelocation packageFlexible hours2 days per week- ...Incident & Crisis Management Lead The Incident & Crisis Management Lead is responsible for overseeing and coordinating the organization's enterprise... ...from unforeseen events that threaten the organization's operations, reputation, or stakeholders. Responsibilities...Operations
- ...ensure alignment with customer experiences, and collaborate with Product Operations and Engineering to drive root-cause analysis and platform improvements. You will build diagnostic tooling, guide incident response, and mentor teams while operating in a global follow-the-...Operations
- ...experienced IT Administrator in New York to own and advance the DLP program, supervise endpoint operations, and manage identity and access tools. You will triage incidents, tune policies, and collaborate with Security and IT teams to safeguard data and infrastructure....Operations
$100k - $120k
...and a minimum of 8 years of IT experience, including 4 years specifically in incident response. An active Secret clearance is also essential. The role involves overseeing incident operations, ensuring compliance with standards, managing documentation, and conducting post...OperationsRemote job- ...casino Surveillance Supervisor to oversee day-to-day surveillance operations and ensure regulatory compliance in a fast-paced gaming... ...staff, review footage, and coordinate with management to address incidents. The ideal candidate has proven supervisory skills, strong analytical...OperationsWork at office
- DoorDash is seeking a Safety Strategy & Operations leader to join the Safety Customer Experience team in New York. You will collaborate... ...for preventing, identifying, and responding to high‑risk safety incidents. This role requires a detail‑oriented operator who can own...Operations
- ...expertise 8-12 years in IT, with strong Guidewire expertise (PolicyCenter, BillingCenter, ClaimCenter) and Incident Management experience. Lead technical operations for incident management in Guidewire environments, ensuring SLA compliance, service restoration, and...OperationsPermanent employmentContract work
- Madison Square Garden Entertainment Corp. is looking for a Security Operations Center (SOC) Lead Operator to oversee a team during shifts and manage incident responses. The role requires hands-on leadership to ensure effective incident handling and communication with security...OperationsShift work
- Keyloop’s 24/7 Security Operations Center seeks an experienced L2 SOC Analyst to investigate, analyze, and respond to security alerts and incidents. You’ll act as the escalation point from L1 analysts and drive containment, remediation, and post-incident improvements. You...Operations
$34 - $39 per hour
MSG Entertainment Holdings, LLC is searching for a Lead Security Operations Center Operator in New York City, NY. This role involves leading SOC operations, managing incidents, and mentoring team members. The selected candidate will oversee security technology monitoring...OperationsHourly pay- CTS - IT & Cybersecurity Services is seeking an experienced SOC Supervisor to lead our Security Operations Center operations and drive continuous improvement. The role combines tactical incident command with strategic people leadership in a fast-paced managed services...OperationsRemote job
- Eliassen Group is seeking a Lead Support Analyst to oversee the reliability of mission... ...applications across global media operations. You will lead a team of Application Support... ...coordinate cross-regional triage to ensure incident, problem, and change management aligns...OperationsRemote job
- Andersen is looking for a Senior Associate, Security Operations to join its expanding team in New York. This role is pivotal in managing... ...5 years of experience in security operations, proficiency in incident response, and strong communication skills. A comprehensive benefits...Operations
$60k - $70k
...Harvard Protection Services, LLC. is seeking a Security Operations Manager in New York, NY. This critical role involves overseeing daily... ...operations, ensuring compliance with regulations, and leading a team of security personnel. The ideal candidate will have a...Operations- Kairós busca un IT Service Operations Lead para garantizar la estabilidad, disponibilidad y resiliencia de una plataforma fintech de alta criticidad, coordinando 9 equipos técnicos y definiendo la gobernanza operativa para cumplir normas como PCI DSS y DORA. El rol exige...OperationsRemote job
- RTX, a leading aerospace and defense company, seeks a senior leader to direct global incident response coordination across all businesses and regions. You will ensure timely... ...incident management to protect employees and operations. This role requires a university degree and...Operations
$234k - $300k
...environments. As a Group Product Manager, you will define and lead the vision for our Threat Detection and Incident Response (TDIR) capabilities, with direct impact on... ...our customers automate and scale their security operations. You’ll guide product strategy across detection...OperationsWork at office- Cloud Incident Responder (Vice President) Apply (opens in new window) Job Req Id: 2696302... ...Responder (VP) to own and strategically lead security incident response within Citi's... ...objectives with the wider Cyber Security Operations priorities at Citi, driving the...OperationsFull time
$250k - $350k
...decision making and enhance how we build and operate our platforms and applications.As a... ...health across environments and enable rapid incident detection and responseInstrument... ...match and moreAbout Point72Point72 is a leading global alternative investment firm led by...OperationsFor contractorsWork experience placement$10k
...revenue 16% in their first year - far in excess of businesses operating without Ramp. We believe every ambitious company deserves the... ...weekWhat You’ll DoRespond and assist with security requests and incidents submitted by Ramp team membersReview logging, alerting, and...OperationsFull timeWork experience placementWork at officeHome officeFlexible hours$150k - $160k
...in a collaborative environment? As an experienced ServiceNow Operate Lead you will have the ability to share new ideas and collaborate on... ...relationships and act as a strategic advisor to key stakeholders.Support incident, problem, change, and release management activities related to...Operations$111k - $180k
...transformation, and a proven history of successfully leading complex, enterprise-wide mainframe... ...and guidance to mainframe development, operations, and modernization teams. Collaborate... ...such as Release/Change approvals, Incident/Problem resolution.Proven experience resolving...OperationsFull timeTemporary workWork at officeLocal areaWorldwideRelocation package3 days per week$130k - $200k
...for people with unmet medical needs. As a leading innovator of Digital Therapeutics, Click... ....Lead and mature the company's Security Operations Center (SOC) capabilities, including... ...Performance Indicators (KPIs) of threats and incidents, including incident response timeliness...OperationsPermanent employmentTemporary workWork at officeLocal areaVisa sponsorshipFlexible hours- ...Job Details: SOC Team Lead * Oversee day-to-day SOC operations ensuring effective detection, investigation, and response to cybersecurity threats.... ...advice and guidance on response action plans based on incident type and severity. * Develop and refine incident response...OperationsRemote work
$155k - $200k
...Latency Engineer to deploy, build, and operate ultra-low latency network infrastructure... ...performanceConduct root cause analysis for production incidents impacting market data/trading systemsLow... ...clients first, doing the right thing, leading with exceptional ideas, committing to...OperationsTemporary work$100k
...Communications, focused on business resiliency, incident response, crisis management and security... ...within Corporate Communications you will operate confidently across complex, time-... ...matrixed organization. Job Responsibilities: Lead corporate, internal firmwide...Operations$22 per hour
...Overview The Shift Leader at NAYA is responsible for leading daily operations, supervising staff, ensuring high-quality customer service... ...and submit administrative tasks promptly, including guest incidents, workers comp claims, manager checklists, cashier/deposit...OperationsCasual workShift work$26 - $29 per hour
...Summary It is the responsibility of the Lead PT Freight Ops to performs a lead role on... ...perform work to be done. Adhere to safe operations practices to reduce and control safety... ...protective gear properly to prevent injuries and incidents. Perform other duties as assigned....OperationsHourly payPart timeWork at officeLocal areaImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead, Incident Operations. Be the first to apply!
- hotel operations intern New York, NY
- operations support technician New York, NY
- aviation operations New York, NY
- vice president hotel operations New York, NY
- senior operations technician New York, NY
- cannabis operations New York, NY
- venue operations New York, NY
- special operations New York, NY
- operations processor New York, NY
- import operations New York, NY

