Senior Manager - Cyber Operations & Assurance- Incident Response
$123k - $215.25kAmerican Express
Job ID: 26012722Posted: 2026-08-19Location: Phoenix, AZ, United States; Atlanta, GA, United States; Palo Alto, CA, United States; Salt Lake City, UT, United States; Sunrise, FL, United States; Charlotte, NC, United States; New York, NY, United StatesSalary: $123000 - $215250 annually + bonus + benefitsJob Function: CybersecuritySchedule: Full timeShift: DayWorkplace: HybridCareer Area: TechnologyCompany: American ExpressDescriptionJoining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.At American Express, our mission is to deliver the world’s best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage—empowering you to innovate, grow, and help shape the future of a Fortune 100 company.Trust. Service. Security.American Express seeks to recruit a passionate and experienced Leader for its Incident Response team. This is a senior-level, hands-on, highly technical role performing incident response activities ranging from pre-incident preparation, active incident response, and post-incident analysis and recovery. You will be a key technical resource conducting investigations, performing advanced analysis, identifying attacker TTPs, building attack narratives, and executing response actions.As part of our evolution toward a Next Generation Agentic SOC, this role will also help drive the adoption of AI-enabled security operations, intelligent automation, and autonomous analyst workflows. The ideal candidate combines deep incident response expertise with curiosity and practical experience in AI-assisted detection, security automation, and modern SOC engineering practices.You are a motivated leader who will directly manage, mentor, and develop a team of SOC analysts while driving the people, processes, and technology that empower the team to investigate sophisticated threats at scale. This role requires critical thinking, innovative problem solving, technical leadership, people leadership, and effective communication across both technical and executive audiences.ResponsibilitiesPeople Leadership & Team Development Directly lead and manage a team of SOC analysts, including hiring, onboarding, day-to-day supervision, performance management, and career development, fostering a high-performing and engaged team culture.Conduct regular 1:1s, performance reviews, and goal-setting with direct reports; provide timely, constructive feedback and coaching to accelerate individual and team growth.Mentor and develop junior and mid-level analysts, building technical skills, investigative rigor, and professional capabilities across the team; create clear career progression pathways from Tier 1 through senior roles.Manage shift schedules, on-call rotations, and workload distribution to ensure 247 operational coverage while proactively mitigating analyst burnout and maintaining team morale.Drive a culture of continuous learning by identifying training opportunities, encouraging pursuit of industry certifications (e.g., GCIH, GCFA, GCIA), facilitating hands-on exercises (e.g., Immersive Labs, tabletop exercises), and championing knowledge-sharing across the team.Recruit and retain top talent by partnering with HR and hiring managers to define role requirements, conduct interviews, and build a diverse and skilled analyst pipeline.Incident Response & Technical Operations Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations and escalations from junior analysts across Windows, Mac, Linux, Cloud, SaaS, and hybrid environments.Participate in incident response, cyber crisis management, and enterprise-wide security events.Advise leadership on containment, eradication, and recovery strategies during incident response.Fully scope incidents through proper identification of all affected systems, identities, applications, and/or accounts.Recognize attacker tactics, techniques, and procedures (TTPs) as well as Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) applicable to current and future investigations.Serve as a technical escalation point for the analyst team, providing real-time guidance on complex or high-severity investigations and ensuring quality and consistency of investigative outputs.Contribute to team projects, process improvement, and development of new security operations capabilities.Help curate a world-class security operations and incident response program with a relentless focus on innovation, intelligent automation, and continuous improvement.Assess and develop incident response best practices to help mature the overall security operations and AI-assisted defense capabilities of the organization.Produce high-quality written and verbal reports, recommendations, executive briefings, and technical findings.Participate in on-call rotation and provide after-hours support on an as-needed basis.AI-Enabled Security Operations & Automation Partner with detection engineering, threat intelligence, data science, and security engineering teams to operationalize AI-driven detection and response capabilities.Assist in the design, tuning, and oversight of AI-enabled SOC workflows, analyst copilots, and autonomous or semi-autonomous response agents.Develop and optimize prompts, workflows, and guardrails for large language model (LLM) and AI-agent-assisted investigations and triage processes.Evaluate and validate AI-generated investigative outputs to ensure operational accuracy, reliability, explainability, and security.Help identify opportunities to leverage AI/ML, orchestration, and automation technologies to reduce analyst toil and accelerate response times.Participate in development and integration of SOAR playbooks, AI-assisted enrichment pipelines, and security automation frameworks.Contribute to AI governance and operational risk management efforts related to AI-enabled security tooling and workflows.Champion AI adoption within the team by training analysts on AI-assisted tools and workflows, gathering analyst feedback to drive iterative improvements, and ensuring responsible use aligned with organizational governance.Stay current on industry trends, attack techniques, AI-enabled threats, adversarial AI risks, mitigation techniques, and emerging security technologiesQualifications3+ years of experience in information security, security operations, incident response, threat hunting, or cyber defense.Experience with host, network, and/or memory forensics.Experience with various network and/or host-based security tools used to detect and respond to security events (e.g., SIEM, EDR, NDR, SOAR, web proxy, IDS/IPS, cloud-native security platforms, etc.).Theoretical and practical security knowledge and investigation experience with Mac, Linux, Windows, and cloud environments.Strong understanding of incident response lifecycles, attacker methodologies, and cyber kill chain concepts.Experience performing analysis of complex security incidents in enterprise environments.Familiarity with scripting or programming languages such as Python, PowerShell, Go, or similar.Ability to convey complex technical concepts to audiences with varying levels of technical expertise.Strong analytical, investigative, documentation, and communication skills.Demonstrated curiosity and adaptability toward emerging AI-enabled security technologies and workflows.Demonstrated ability to lead, motivate, and develop technical teams in high-tempo, operationally demanding environments.Strong interpersonal and conflict-resolution skills, with the ability to foster a collaborative, inclusive, and psychologically safe team environment.Preferred:1+ years of experience in a people leadership, team lead, or supervisory role, including direct responsibility for coaching, mentoring, or managing technical staff.Experience working within a modern SOC leveraging AI-assisted analysis, security automation, and/or SOAR technologies.Familiarity with AI/ML concepts and practical applications within cybersecurity operations.Experience with prompt engineering, LLM-assisted workflows, or AI copilots for security investigations and operational efficiency.Understanding of AI agent architecture, orchestration frameworks, retrieval-augmented generation (RAG), vector databases, or autonomous workflow concepts.Experience integrating APIs, automation pipelines, or AI-enabled tooling into SOC workflows.Knowledge of adversarial AI threats, prompt injection risks, model misuse, or AI security governance principles.Experience building or operationalizing automated detection, enrichment, triage, or response capabilities.Knowledge and investigation experience in a global, multi-cloud environment.Experience with detection engineering, threat hunting, or behavioral analytics.Familiarity with cloud-native security technologies and telemetry sources.Multiple applicable certifications (GSE, GDAT, GCIA, GCIH, GCFA, GNFA, GCFE, GREM, CCSP, CISSP, CEH, etc.).AI-related certifications or hands-on experience with enterprise AI platforms, orchestration frameworks, or automation tooling.Experience managing performance cycles, conducting calibrations, and building talent development plans within a security operations or SOC environment.Experience managing geographically distributed or shift-based teams supporting 247 operations.Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.
- ...opportunity for a full time Senior Engineer, Cyber Security Threat Management reporting to the Senior... ...mature detection and response controls.Execute phishing... ...while strengthening incident detection and response processes... ...insights.Mentor junior operators, provide technical...CyberSeniorFull time
$90.4k - $168.2k
...currently seeking a Senior Associate, Content Development... ...organization.Responsibilities:Execute the end-to-end... ..., SOC, and Incident Response teams to map... ...while designing and managing scalable security data... ...tracesSupport and streamline Cyber Operations by actively automating...CyberSeniorH1bLocal area- ...Description Job Summary : TEAM SCG is hiring a senior operations leader to oversee the systems and processes... ...combine e-commerce storefronts, inventory management, and warehouse fulfillment. This role is responsible for ensuring those programs operate reliably...SeniorTemporary workMonday to Friday
- ...Job Description: As a Senior Manager in Healthcare Revenue Cycle Management, you will be responsible for leading a team of specialists in analyzing, resolving, and preventing claim denials. Your expertise will directly contribute to improved revenue integrity and financial...SeniorLocal areaRemote work
- ...and brightest minds in cyber security who are... ...and we think adding a Senior Consulting Engineer will... ..., and secure management at scale using Microsoft... ...advisory consulting responsibilities with hands-on client... ...outcomes that reduce operational friction while improving...CyberSeniorImmediate startRemote work
- ...policies and procedures. Responsibilities Provide network support and... ...via external networks. Manage, install, and administer all... ...network administration and cyber security roles; or an equivalent... ...that affect business operations to a substantial degree....CyberSeniorWork at officeShift work
- ...Insurance (BSI) provides management and professional liability, cyber, crime insurance, and... ...First-Party Claim Team is responsible for handling first-party... ...privacy and security breach incident response, computer crime... ...What Will You Do?Follow operational policies to analyze,...CyberSeniorFull timeContract workWork experience placementFor subcontractorWork at officeLocal area
- ...reporting across a complex and evolving operating environment.What you'll do: Prepare and... ...performing account reconciliations. and responses to tax authority inquiries and audits.Assist... ...Fraudulent job postings may be used by cyber criminals to target your personally...CyberSeniorFull timeTemporary workH1bWork at officeLocal areaMonday to Friday
$106.9k - $147k
...our caring communityThe Senior Storage Engineer responsible for the architecture, configuration... ...deployment, and ongoing management of large-scale production... ..., implementation, operation, and continuous... ...enterprise backup, recovery, cyber resilience, and data protection...CyberSeniorFull timeTemporary workFor contractorsApprenticeshipWork at officeRemote workWork from homeHome office- ...evolving to better support our community. The Quality Assurance / Improvement Manager recognizes, respects, and values the role and expertise... ..., person-centered services. As such, this position is responsible for supporting the coordination, implementation, and...Work at office
- ...INFORMATION Position Title Senior Quality Engineer Department Quality Assurance Reports to VP of Quality Assurance... ...related to the Quality Management System and process improvement... ...listing of all activities, duties or responsibilities that are required by the...SeniorWork experience placementFlexible hours
- ...Bowman has an opportunity for a Senior Civil Project Manager to join our team in Sunrise, FL... ...sustainable communities. Responsibilities Leadership and Direction ~... ...produced by staff for quality assurance. At The Operational And Company Level Assist with...SeniorFull timeContract workFor subcontractorWork at office
- ...will have overall for Operational Excellence will lead... ...organization. This position is responsible for leading the team... ...for the management and execution of the... ...section operators, quality assurance, the impression of... ...implementation.Collaborate with senior management team to...Temporary workWorldwide
$121.13k - $193.8k
...innovation and best practices within the software development team.Responsibilities listed are not intended to be all-inclusive and may be... ...affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information...CyberSeniorFull time- ...Cybersecurity Counter Threat Management reporting to the Senior Manager,... ...seasoned Lead Engineer, Cyber Security Counter... ...architect, build, and operate AI-driven automation... ..., accelerate threat response, and strengthen our... ...including threat detection, incident response,...CyberFull time
$169.01k - $370.53k
...Security to join our Managed Services practice. Responsibilities: Provide... ...and oversight of Cyber Managed Services delivery... ...teams. Leads operational governance managed... ..., including incident, problem, and service... ...ability to influence senior stakeholders, lead...CyberH1bLocal area- ...support the delivery and operations of technology, digital... ..., our team is responsible for the company’s technology... ...also provide product management for core enterprise platforms... ...to prevent future incidents and minimize damage... ...research on emerging cyber threats, security technologies...CyberFull timeInternshipSummer internship
$100k - $135k
...environments. This senior-level field role... ...day-to-day field operations, direct junior... ...leader capable of managing multiple workstreams... ...tasks, responsibility for site readiness... ...Perform quality assurance checks and advanced... ...Cloud Solutions, Cyber Security, and IT...CyberSeniorFull timeFor subcontractorLocal areaVisa sponsorshipFlexible hoursShift workAfternoon shift- ...join our team.KPMG is currently seeking a Manager, Data Operations - Azure Data Lake to join our Digital Nexus organization.Responsibilities:Lead and manage Managed Service Provider... ...through proactive monitoring, effective incident response, and timely resolution of...H1bLocal area
- ...Celebration. Position Overview As a Store Operations Supervisor at Ralph Lauren, your role... ...from delivery to display. Your responsibilities encompass several critical areas:... ...leadership and daily interactions Operations Management * Coordinate processes between Back...Seasonal workWork at officeFlexible hoursWeekend workAfternoon shift
- ...Job Description Job Description Senior Director of Operations POSITION OVERVIEW The Senior Director of Operations is responsible for the growth, profitability and service... ..., coaches and mentors the Operations Management team. Additionally, the Senior Director...SeniorTemporary workCasual workWork at officeLocal areaFlexible hours
- ...between 2 – 4 times per month RESPONSIBILITIES: As a rapidly growing... ...are looking for a full-time Operations Director (OD) with strong... ...orthodontic exam performance, managing pediatric dental productivity... ...performance reviews Assure compliance for federal, state...Full timeWork at office
$75k - $95k
...Description Job Description Senior Systems Engineer – Advance... ...of our team, you will be responsible for providing remote and on-... ...Monitor the remote monitoring and management system alerts and... ...required: keeping them informed of incident progress, notifying them of...SeniorRemote work$89.25k - $150.25k
...Full timeWorkplace: HybridCareer Area: Operational Risk Management and Control ManagementCompany:... ...Support & Intelligence Manager will be responsible for providing data, queries, and analytical... .../Suspicious Activity Reporting, Cyber Security, Fraud Investigations, or Law...CyberWork experience placement$71.96k - $128.5k
Join to apply for the Senior Operations Specialist (Water) role at HDR. Join to apply for the Senior... ...is more than a resource, it's a shared responsibility. As part of our Water Business Group, you’ll help shape how communities manage water for generations to come. From...SeniorFull timeTemporary workFor contractorsFor subcontractorWork at officeLocal areaWeekend work- ...seeks an experienced Project Manager to lead our Industry 4.0... ...security implementations. Key Responsibilities: Program Leadership &... ...partnership integration with operations and key technology partners... ...differentiation Quality Assurance & Compliance Oversee security...SeniorRemote work
- ...client that is seeking a Senior Cloud Security Engineer... ...the technical expert responsible for securing multi-cloud... ..., risk reduction, and operational efficiency. The ideal candidate... ...to cloud security incidents while driving remediation efforts ~ Manage cloud vulnerability...SeniorTemporary work
- ...KPMG is currently seeking a Manager, Project Management to join... ...Security Services organization.Responsibilities:Lead and implement multiple... ...as physical, personnel, and cyber security along with... ...trustworthiness, and safeguard business operations and company reputation....CyberWork experience placementH1bLocal area
- ...Position Summary DHL Group is seeking a Senior Director, Human Resources Business... ...organization. This role will lead talent management, succession planning, organizational... ...business growth across the region. Key Responsibilities Partner with senior leaders on...Senior
$95k - $180k
...description:Arcadis is looking for a Senior Water Design Manager to join our Resilience Water Team... ...meetings, team meetings, conferences, etc.Responsibilities include:Serve as lead designer and/... ...culture by performing quality assurance and control reviews of water...SeniorFull timeContract workPart time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Manager - Cyber Operations & Assurance- Incident Response. Be the first to apply!
- srs Sunrise, FL
- senior performance tester Sunrise, FL
- senior manager legal Sunrise, FL
- senior mainframe developer Sunrise, FL
- senior leadership Sunrise, FL
- senior activities Sunrise, FL
- senior operations technician Sunrise, FL
- senior application security Sunrise, FL
- senior performance engineer Sunrise, FL
- senior Sunrise, FL




