Incident Response Manager
Fortuna Cysec
Company Overview Fortuna Cysec delivers unified cybersecurity operations through TheFense platform—our integrated MDR, SIEM, EDR, and response ecosystem designed for regulated industries, nonprofits, healthcare, education, and mission-driven organizations. Our global SOC/NOC operates 24×7×365, providing real-time visibility, rapid containment, and deep technical expertise across diverse customer environments. Description We are expanding our Incident Response leadership team with a hands‑on technical manager who thrives in fast-moving investigations and can guide customers through their most critical security events. Role Summary The Cybersecurity Incident Response Manager leads and directly participates in high‑severity investigations across Fortuna Cysec’s customer base. This role blends technical depth, operational leadership, and customer‑facing communication. You will serve as the senior escalation point for complex incidents, drive containment and remediation, and strengthen TheFense platform’s detection and response capabilities. Requirements Lead and Execute Incident Response Command all phases of incident response—triage, investigation, containment, eradication, and recovery—while performing hands‑on technical analysis. Analyze EDR telemetry, SIEM alerts, network logs, cloud audit logs, and identity events across Microsoft, AWS, and hybrid environments. Execute containment actions including endpoint isolation, identity disablement, MFA resets, OAuth token revocation, and firewall/network segmentation changes. Conduct forensic acquisition and analysis using Velociraptor, KAPE, FTK, EnCase, and Volatility. Reverse‑engineer or sandbox suspicious binaries/scripts to determine behavior and impact. Lead hypothesis‑driven threat hunts mapped to MITRE ATT&CK using TheFense’s unified telemetry. Strengthen IR Operations Oversee daily IR operations across global SOC/NOC teams, ensuring SLA adherence and seamless follow‑the‑sun handoffs. Review and enhance IR playbooks, runbooks, and automated response actions within TheFense. Ensure high‑quality incident documentation, evidence handling, and customer‑ready reporting. Conduct root‑cause analysis and deliver technically detailed post‑incident reviews. Partner with engineering to refine detection logic, reduce false positives, and improve automation. Engage Directly with Customers Serve as the technical authority during active breaches, guiding CISOs, IT directors, and executive stakeholders. Deliver clear, concise briefings that include attack path analysis, forensic findings, and prioritized remediation steps. Support customer teams with hands‑on remediation across identity, cloud, endpoint, and email ecosystems. Provide strategic recommendations aligned with NIST, CIS Controls, and Fortuna Cysec best practices. Advance Threat Intelligence and Detection Translate emerging threat intelligence into new detection rules, response playbooks, and threat‑hunting queries. Validate detection logic through lab testing, simulated attacks, and historical telemetry review. Identify detection gaps and collaborate with TI teams to enrich investigations with IOCs and adversary behavior patterns. Build Team and Platform Maturity Mentor analysts across global SOC/NOC teams in IR, forensics, cloud investigations, and threat hunting. Develop internal tooling and automation using Python or PowerShell. Participate in tabletop exercises, purple‑team engagements, and breach simulations. Contribute to the evolution of TheFense platform by evaluating new telemetry sources and response capabilities. Required Qualifications 5–10+ years of hands‑on experience in incident response, threat hunting, SOC operations, or digital forensics. Deep technical expertise with EDR platforms (Microsoft Defender, SentinelOne, CrowdStrike, Carbon Black). Strong SIEM experience with log parsing, correlation, and custom detection creation (Wazuh, Microsoft Sentinel, Elastic, Splunk). Strong Windows Servers, Office 365 & Azure EntraID / Intune Experience. Hands‑on experience with cloud IR in Azure, AWS, and hybrid environments. Proficiency with forensic tools (Velociraptor, KAPE, FTK, EnCase) and memory analysis frameworks (Volatility). Strong understanding of identity security (Entra ID, Okta), email security (M365, Proofpoint), and SaaS compromise patterns. Familiarity with MITRE ATT&CK, NIST 800-61, CIS Controls, ISO 27035. Ability to communicate complex technical findings to both technical and executive audiences. Relevant certifications: GCIA, GCFA, GCIH, GNFA, CISSP, or equivalent experience. Preferred Qualifications Experience in an MDR, MSSP, or IR consulting environment. Scripting/automation skills in Python or PowerShell. Experience with malware analysis, cloud forensics, or identity compromise investigations. Experience supporting regulated industries (HIPAA, FERPA, PCI‑DSS, SOX, CJIS) and mission‑driven organizations. Fortuna Cysec is an equal opportunity employer. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, pregnancy, age, sexual orientation, transgender status, gender identity, disability, alienage or citizenship status, marital status or partnership status, genetic information, veteran status or any other characteristic protected under applicable law. #J-18808-Ljbffr Fortuna Cysec
$142.9k - $266k
Cyber Incident Response Business Development Senior ManagerThe Opportunity:Join a team to contribute to Booz Allen's growth efforts for its... ...relationships, and growing revenueExperience developing and managing strategic relationships across cyber insurance carriers,...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- Acrisure is seeking a Director of Security Operations to lead enterprise security operations, threat detection, and incident response. You will manage teams responsible for detecting, investigating, containing, and responding to cybersecurity threats, while driving automation...Suggested
- ...find new areas of inspiration and expand your capabilities, then consider a career in Advisory.We are currently seeking a Manager, Incident Response to join our Advisory practice.ResponsibilitiesLead and manage cyber incident response activities, including triage,...SuggestedWork experience placementH1bLocal area
$123k - $215.25k
...seeks to recruit a passionate and experienced Leader for its Incident Response team. This is a senior-level, hands-on, highly technical role... ...engineering practices.You are a motivated leader who will directly manage, mentor, and develop a team of SOC analysts while driving the...SuggestedShift work- ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates... ...by enterprise ITSM governance and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness...SuggestedContract workWork experience placementWork at officeShift work
- ...The Incident Response Coordinator supports the end‑to‑end response to IT incidents and service disruptions, helping restore normal operations... ...activities, ensuring alignment with established incident management processes, service incident models, and enterprise IT objectives...Contract workWork experience placementWork at officeShift work
$62.2k - $105.7k
...An Accenture Federal Services Company in Atlanta seeks an Incident Manager to oversee the end-to-end lifecycle of IT incidents. This role... ...teams to ensure minimal disruption to critical systems. Responsibilities include leading incident response, conducting reviews, and...$52.5k
...decision-making skills and an acute attention to detail. The GCS Incident Response Coordinator is a critical role in addressing immediate large... ...-7:30pm) Monday-Friday 11:30-8pm What You'll Do Monitor and manage global event-level issues, providing timely responses and...Full timeImmediate startWorldwideMonday to FridayWeekend workAfternoon shift- ...Cyber Defense to lead a global security operations program and shape the defense posture across the enterprise. You will own the incident response lifecycle, drive threat intelligence-driven defense decisions, and ensure continuous validation of detection content. The role...
- ...Murata Electronics is seeking an Operations Incident Specialist to manage operational incidents impacting demand management and ensure timely resolutions. This role requires strong problem-solving abilities and experience in a fast-paced environment. Candidates should...
- StubHub is seeking a GCS Incident Response Coordinator to monitor and manage global event-level issues, delivering timely responses and clear updates to stakeholders across teams. This role supports our mission to provide safe, reliable customer experiences. Candidates...Flexible hours
- Google is seeking experienced Security Engineers to drive incident response and forensics. The ideal candidate will have extensive experience in managing incident response operations and will collaborate to enhance security for Google's services. This role requires a Bachelor...
- CBRE Group, Inc. seeks a specialist to manage the end-to-end incident response lifecycle and conduct thorough root cause analyses. You will coordinate site incident management, enabling structured post-mortems and continuous reliability improvements across multiple buildings...Remote job
- Fortuna Cysec in Atlanta, GA, seeks a Cybersecurity Incident Response Manager to lead investigations and manage critical security events. The ideal candidate will have 5-10+ years in incident response, possess deep expertise with EDR and SIEM platforms, and be adept in...
$80.2k - $111.3k
...Company in Atlanta, Georgia is seeking a Senior Cybersecurity Incident Response Engineer to lead incident response efforts for critical... ...a Bachelor’s degree, focusing on ITIL principles, incident management, and advanced threat analysis. The position involves mentoring...- A technology services company in Atlanta is seeking an IT Manager Senior to manage incident response efforts. This role requires strong leadership and communication skills, as well as a minimum of 5 years of relevant experience. The ideal candidate will drive strategies...Full time
$142.9k - $266k
Phase2 Technology in Atlanta, Georgia is seeking a Cyber Incident Response Business Development Senior Manager to lead business development initiatives for its Incident Response business. This role requires expertise in sales strategies, maintaining strategic relationships...- Overview IT Manager Senior, Incident Response & Continuity Manager reports to the Director of Service Delivery, with matrix responsibility to the Director of the Office of Infrastructure and Technology. This position is accountable for managing and coordinating incident...Full timeWork at office
- Wilson Elser Moskowitz Edelman & Dicker LLP is seeking a Senior Cyber Incident Response Attorney for a full-remote role based in the United States. The position focuses on leading incident response for cybersecurity and data privacy incidents, guiding breach response, and...Remote job
$62.2k - $105.7k
...Position Overview The Incident Manager oversees the end‑to‑end lifecycle of IT incidents in an enterprise environment, ensuring rapid... ...reporting in a highly regulated federal IT environment. Key Responsibilities Lead coordination of incident response across infrastructure...Contract workWork experience placementWork at office- Southern Arkansas University in Atlanta, GA seeks a Supervisory Emergency Management Specialist to coordinate multi‑agency emergency response activities and lead logistical planning for swift incident response. The role directs development and implementation of protocols,...Contract work
$134.5k - $265.1k
...vulnerabilities. Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end... ...team, who will have extensive experience in Cyber Incident Response. This role involves supporting our client teams in defining,...Local areaVisa sponsorship- ...ve come to the right place.JOB SUMMARY -The Senior Manager is an experienced technology leader responsible for managing enterprise services for Finance, Accounting... ...adherence.Oversee production support requests, and incidents; manage risks and serve as escalation point for...Full timeWork at office
- TechDigital Group is seeking an experienced Incident Manager with 8+ years in ITSM to own end-to-end incident lifecycle, drive major incident... ...analytics, and collaboration with AI-enabled capabilities. Responsibilities include leading incident bridges, developing dashboards,...
- ...across the Americas region. The team is responsible for delivering high-quality customer... ...success, Sales and the Global service management function to support service delivery, customer... ...responses to customer impacting incidents, The role will lead regional teams and...Full timeFlexible hours
- The Coca-Cola Company is seeking a Manager, Cyber OT SecOps to lead OT security monitoring, detection, and response for industrial control systems across Coca-Cola manufacturing... ...through OT-focused playbooks and rapid incident handling. You will guide MSSP SOC analysts, foster...
- ...was also one of Google's earliest product managers and co-creator of Google Maps. Before... ...identity and access management, detection and response, vulnerability management, and secure... ..., logging and detection baselines, incident readiness, and secure defaults that future...Full timeFlexible hours
$67.98k
...This Job Opportunity The Operations Incident Specialist is a frontline operational... ...execution. This position supports demand management, planning, and operational teams when... ...CA. What To Expect (Essential Job Responsibilities) Incident Investigation & Resolution...Temporary workImmediate startFlexible hours- ...security operations capabilities, including threat detection, incident response, threat hunting, security monitoring, operational security... ..., and cyber defense processes. This role is accountable for managing teams responsible for detecting, investigating, containing,...Full timeImmediate startFlexible hours
- ...programs, supporting the Legal Operations Manager in executing compliance processes and... ...and global privacy operations. Key Responsibilities Administer and manage OneTrust privacy... ...SharePoint and Aptean Assembly) Support incident management processes and vendor due diligence...Full timeCasual workInternshipFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Response Manager. Be the first to apply!
- dunkin manager Atlanta, GA
- phlebotomy manager Atlanta, GA
- machining manager Atlanta, GA
- press printing manager Atlanta, GA
- manager special events Atlanta, GA
- instrumentation manager Atlanta, GA
- mill manager Atlanta, GA
- senior preconstruction manager Atlanta, GA
- parks and recreation manager Atlanta, GA
- car wash manager Atlanta, GA


