Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Incident Responder

$70k - $84.5k

Canopius

The Role Canopius is a market‑leading cyber insurer with an in‑house Cyber Incident Management Team (CIMT) that delivers immediate, expert support to our policyholders during their most critical moments. As an Incident Manager, you’ll be the first point of contact when a client faces a cyber event—whether business email compromise, ransomware, social engineering, data theft, or other attacks. You will triage and lead the response, mobilize our expert panel (forensics, legal, PR, and specialist advisors), and project‑manage recovery from containment through restoration, providing calm, clear communication throughout. Operating in a global, follow‑the‑sun model across Sydney, London, and Chicago, you’ll ensure true 24/7 coverage for new notifications, collaborate closely with our Claims team to support timely coverage assessment, and help clients navigate local legal and regulatory obligations. Sitting at the coal face of live incidents, you’ll also capture structured insights and trends that inform our underwriting, analytics, and ongoing service evolution, all while meeting and exceeding internal SLAs. Responsibilities Own the incident from notification to closure Be the first point of contact for policyholder incident notifications. Rapidly triage, assess severity, and set the response plan and cadence. Orchestrate specialist vendors (IR firms, forensics, legal, PR, ransom advisors), ensuring right‑sized support at the right time. Maintain clear timelines, decisions, and next steps. Deliver best in class customer service Provide calm, empathetic guidance under pressure; translate technical issues into clear business impact and options. Set and manage expectations on milestones (containment, restoration, notifications) and costs. Conduct welcome/onboarding calls; explain how to notify, what to expect, and how the IR panel operates. Capture and act on policyholder feedback to continuously improve service. Hit internal SLAs (acknowledgement, triage, vendor mobilization, comms cadence). Operate within a global, 24/7 team model Participate in rota/on call coverage to ensure true follow‑the‑sun response. Perform structured handovers across regions; maintain accurate case notes and status. Evolve the service offering Contribute to playbook/runbook enhancements and decision trees (e.g., ransomware, BEC, DDoS, data exfil). Recommend panel/vendor improvements and measure vendor SLAs and outcomes. Support content development (guides, FAQs, tabletop scenarios). Collaborate with Claims, Underwriting and Insights & Analytics Partner with the Claims team to ensure smooth coverage confirmation and claim handling. Surface material facts, costs, and causation signals; ensure incident files are complete and timely. Escalate complex matters promptly and appropriately. Sit “at the coal face” of live incidents and distil timely, high‑quality insights (threat vectors, controls efficacy, vendor performance, and industry signals). Provide structured post‑incident summaries and trend themes for underwriters and leadership. Ensure precise, consistent capture of incident metadata and outcomes (e.g., root cause, initial access, controls in place, dwell time, MTTA/MTTR, costs). Champion data quality standards; work with Analytics to refine taxonomies and dashboards. Collaborate in delivery of incident preparedness sessions, tabletops, and executive simulations for insureds. Feed real‑world lessons learned into control uplift recommendations. Skills and Experience A minimum of two years working in the cybersecurity field, ideally with hands‑on involvement in incident handling or response activities. Strong foundational knowledge of cyber‑attack methods, threat behaviors, and the end‑to‑end lifecycle of incident response. Demonstrate ability to solve complex problems and make sound judgements quickly, especially when operating in high‑pressure or fast‑moving situations. Excellent organisational habits with a focus on accuracy and thoroughness in all tasks. Clear and confident communication skills—both written and verbal—with the capability to explain technical issues in an accessible way for non-technical audiences. Basic data skills to partner with Analytics (e.g., Excel/Power BI; familiarity with SQL/Python advantageous). High empathy, composure under pressure, and a service mindset. Salary Range: $70,000 - 84,500 #J-18808-Ljbffr Canopius

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber Incident Responder in Chicago, IL vacancy
  • $70k - $84.5k

     ...Job Description The Role Canopius is a market-leading cyber insurer with an in-house Cyber Incident Management Team that supports clients during highly stressful and time-critical situations. Our role is to bring clarity, coordination, and reassurance when a cyber... 
    Cyber
    Flexible hours
    Rotating shift

    Canopius

    Chicago, IL
    1 day ago
  • $77k - $202k

     ...Cybersecurity Incident Management Senior Associate At PwC, our people in cybersecurity...  ...focus on protecting organizations from cyber threats through advanced technologies and...  ...management at PwC, you will focus on effectively responding to, and mitigating, cyber threats,... 
    Cyber

    PwC (US)

    Chicago, IL
    5 days ago
  • $77k - $202k

     ...cybersecurity focus on protecting organisations from cyber threats through advanced technologies and...  ...to safeguard sensitive data. In cybersecurity incident management at PwC, you will focus on effectively responding to, and mitigating, cyber threats, maintaining the... 
    Cyber
    H1b

    PricewaterhouseCoopers

    Chicago, IL
    2 days ago
  • $100k - $126.5k

     ...Consulting Associate/Cybersecurity & Incident Response CRA's Forensic Services practice...  ...them and their counsel in independently responding to allegations of fraud, waste, abuse,...  ...guidance to clients on the adequacy of cyber security controls in accordance with cybersecurity... 
    Cyber
    Work at office
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    5 days ago
  • $77k - $202k

     ...our cybersecurity team protects organisations from cyber threats through advanced technologies and...  ...sensitive data. As a member of the Cybersecurity Incident Management team, you will focus on effectively responding to and mitigating cyber threats, maintaining the... 
    Cyber
    H1b

    PwC South Africa

    Chicago, IL
    1 day ago
  • $140k - $170k

     ...Associate Principal/Cybersecurity & Incident Response Boston, MA, United States; Chicago...  ...them and their counsel in independently responding to allegations of fraud, waste, abuse,...  ...an experienced leader in the forensic & cyber investigations space, your responsibilities... 
    Cyber
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    3 days ago
  • $130k - $152.5k

     ...Senior Associate/Cybersecurity & Incident Response (Forensic Services Practice) Boston...  ...them and their counsel in independently responding to allegations of fraud, waste, abuse, misconduct...  ...guidance to clients on the adequacy of cyber security controls in accordance with... 
    Cyber
    Work at office
    Local area
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    4 days ago
  • $100k

    Lyra Technology Group is seeking an L2 Cyber Security Analyst for their Managed Security Services department. The role requires 2-4...  ...responsibilities include monitoring security alerts, conducting analysis, and incident response. Ideal candidates will be knowledgeable in Microsoft... 
    Cyber
    Remote job

    Lyra Technology Group

    Chicago, IL
    3 days ago
  • A leading cyber insurance provider is seeking an Incident Manager in Chicago to lead responses to cyber events such as ransomware and data theft. The role involves ensuring client communication, managing the incident lifecycle, and collaborating with teams to support policyholders... 
    Cyber

    Canopius Group

    Chicago, IL
    3 days ago
  •  ...3 Response Analyst to fortify its cybersecurity measures. You will monitor security operations, analyze network threats, and lead incident response efforts within a dynamic team. The ideal candidate will have over 5 years of experience in security operations and a background... 
    Cyber

    McDonald's Corporation

    Chicago, IL
    5 days ago
  • RSM US LLP in Chicago is seeking a DFIR Manager to guide organizations through critical cyber events. This role requires strong incident command authority and deep expertise in ransomware investigations and cross-functional leadership. The successful candidate will oversee... 
    Cyber

    RSM US LLP

    Chicago, IL
    5 days ago
  • $77k - $202k

    PwC South Africa is looking for a cybersecurity professional to join their Cybersecurity Incident Management team. The successful candidate will focus on identifying, analyzing, and resolving security incidents to protect client systems and sensitive data. The position... 
    Cyber

    PwC South Africa

    Chicago, IL
    1 day ago
  • $87.7k - $164k

    Ernst & Young Oman is seeking a Cyber Triage and Forensics Incident Analyst based in Chicago, IL. This role involves investigating and resolving security incidents while working with a dedicated team to enhance digital security practices. The ideal candidate will have a... 
    Cyber
    Flexible hours

    Ernst & Young Oman

    Chicago, IL
    2 days ago
  •  ...researching and improving the awareness program based on current cyber security risk levels. Stay up-to-date on the latest...  ...Conduct security awareness training for employees. Respond to security incidents and investigations. Stay up-to-date on emerging security... 
    Cyber

    Samprasoft

    Chicago, IL
    1 day ago
  •  ...opportunities. Role Overview We are seeking a highly motivated Incident Response Manager to lead our client’s security operations. In...  ...and remediation. Hunt for, detect, and neutralize sophisticated cyber threats across the enterprise environment. Monitor and... 
    Cyber
    Contract work
    Immediate start
    Shift work

    66degrees Inc.

    Chicago, IL
    1 day ago
  •  ...partner is launching a state-of-the-art Cyber Range in partnership with IBM X-Force to...  ...training programs for industry partners, first responders, and students • Support grant...  ...related areas • Strong understanding of incident response, red/blue team exercises, and cybersecurity... 
    Cyber

    Vantage Point Consulting Inc.

    Chicago, IL
    1 day ago
  •  ...Cyber Security Apprentice IBM Apprenticeship Program is an official registered apprenticeship recognized by the Department...  .../systems for potential security violations/anomalies and respond to all such incidents Work with all teams to investigate potential security... 
    Cyber
    Full time
    Apprenticeship
    Work at office

    Navstar

    Chicago, IL
    5 days ago
  •  ...tasks for cybersecurity programs such as incident response, application cybersecurity, vulnerability...  ...and entities to measure and evaluate cyber security threat assessments. Provide...  ...Maintain technical documentation. Respond to security related incidents. Measure... 
    Cyber
    For contractors
    Work experience placement

    Samprasoft

    Chicago, IL
    1 day ago
  •  ...Development Security Framework Program within Bank of America's Cyber Security Assurance Offensive Security group. The program...  ...assessors in technical tradecraft and soft skills. Respond to security incidents and provide technical assistance to leadership across the... 
    Cyber
    Work at office
    Shift work
    Day shift

    Bank of America

    Chicago, IL
    2 days ago
  •  ...at Swoon Swoon is actively seeking a Sr. Cyber Security Engineer/Architect to join the team...  ...cloud and on-premise environments Lead incident response, threat modeling, risk...  ...management initiatives Monitor, detect, and respond to security incidents Key role in threat... 
    Cyber
    Permanent employment
    Contract work
    Remote work

    Swoon

    Chicago, IL
    8 days ago
  • $98.4k - $160k

    Security Incident Response Orchestration Lead The Security Incident Response Orchestration Lead is responsible for defining, scoping, and...  ...Access and Identity Management Critical Thinking Cyber Security Information Systems Management Risk Management Collaboration... 
    Cyber
    Shift work
    Day shift

    Bank of America

    Chicago, IL
    4 days ago
  • $130k - $144k

     ...Are you driven to detect, analyze, and stop emerging cyber threats before they impact the business? As a Cybersecurity...  ...Firm's technology environment by monitoring, triaging, and responding to security incidents within the organization including analysis of threat... 
    Cyber
    Work at office
    Worldwide
    Flexible hours

    Kirkland & Ellis

    Chicago, IL
    4 days ago
  •  ...CISSP), or Certified Information Security Manager (CISM). Cyber Work Force (CWF) Certification: This position is...  ...analytical and problem‑solving skills with the ability to respond effectively to security incidents. Excellent written and verbal communication skills, with... 
    Cyber
    Contract work
    For contractors

    JMark Services Inc.

    Chicago, IL
    3 days ago
  •  ...capabilities, then consider a career in Advisory. We are currently seeking a Manager, Incident Response to join our Advisory practice. Responsibilities Lead and manage cyber incident response activities, including triage, containment, eradication, and recovery... 
    Cyber
    Work experience placement
    H1b
    Local area

    KPMG

    Chicago, IL
    4 days ago
  • $107k - $214.5k

     ...no one like you and that's why there's nowhere like RSM. The RSM Cyber Response team leads organizations through some of their most consequential cyber events. The DFIR Manager serves as both incident commander and engagement leader, overseeing multiple complex... 
    Cyber
    Work experience placement
    Internship
    Local area

    RSM Global

    Chicago, IL
    4 days ago
  • $100k - $120k

     ...infrastructure, implement best practices, and respond to technical issues to maintain secure...  ...to protect against unauthorized access, cyber threats, and data breaches. Conduct...  ...Respond to network emergencies and security incidents to minimize downtime. Requirements... 
    Cyber
    Local area

    Clarity Partners, LLC

    Chicago, IL
    3 days ago
  • $112k - $139k

    A national law firm is seeking a SOC/Incident Report Engineer for its Chicago office. This hybrid position involves detecting and responding to cybersecurity incidents, focusing on threat detection and digital forensics. The ideal candidate will have solid experience in... 
    Work at office

    Benesch, Friedlander, Coplan & Aronoff

    Chicago, IL
    3 days ago
  • $145k - $210k

     ...Senior Cyber Security Engineer Cooley is seeking a Senior Cyber Security Engineer to join the Security team. Position...  ...event monitoring (SIEM) systems As a member of the Incident Response team respond to alerts, warnings, incidents, and help desk tickets to ensure... 
    Cyber
    Full time
    Temporary work
    Work at office
    Flexible hours
    Weekend work

    Cooley

    Chicago, IL
    5 days ago
  • $90k - $100k

     ...Successful completion of the FedRAMP Baltimore Cyber Range. ~ Knowledge of the Software...  ...Analyst (CySA+) GIAC Certified Incident Handler (GCIH) GIAC Systems and...  ...Security Officer (CISSO) CyberSec First Responder (CFR) CompTIA Advanced Security... 
    Cyber
    Remote work
    Relocation

    Motorola Solutions

    Chicago, IL
    3 days ago
  • $120k

     ...administration for all client issues while responding to Level 1 and 2 service tickets. You...  ...the troubleshooting process Resolve incidents and requests related to, but not limited...  ...these systems Basic understanding of cyber-security concepts and technologies, such... 
    Cyber
    Work at office
    Remote work
    Worldwide
    Flexible hours

    ECI

    Chicago, IL
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Incident Responder. Be the first to apply!