Cybersecurity Incident Manager - Lead
$142.32k - $273.93kUSAA
Why USAA?
At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
We are proud to support active-duty military spouses. USAA roles may offer remote or hybrid flexibility for active-duty military spouses consistent with applicable policy and business needs.
The Opportunity
As a dedicated Cybersecurity Incident Manager - Lead , the candidate selected for this position serves as a Lead within the Cyber Threat Monitoring and Response (CTMR) team, responsible for leading and coordinating cybersecurity incident response activities throughout the incident lifecycle across security, technology, business, and third-party partner organizations. Acts as an Incident Commander during active cybersecurity incidents by establishing response objectives, maintaining situational awareness, coordinating cross-functional response teams, and communicating incident status, business impact, and response actions to stakeholders and senior leadership.
This role also supports the ongoing development and maturity of the Cyber Threat Operations Center by driving improvements to incident response processes, operating models, playbooks, training, metrics, and after-action review practices. The successful candidate will identify opportunities to enhance response effectiveness, operational readiness, and cyber resilience through continuous improvement, operational excellence, and the application of industry best practices.
Investigates, analyzes, and responds to security anomalies and events (e.g. suspicious behavior, attacks, and security breaches) within USAA's environments using a variety of cyber defense tools to detect and respond to threats. Conducts vulnerability, security configuration, and/or penetration testing assessments of systems and networks. Identifies cyber threats, analyzes operational impacts, and communicates to appropriate stakeholders. Stays current with latest information security threats, exploits, trends, and intelligence
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ or Colorado Springs, CO. Relocation assistance is not available for this position.
What you'll do
- Influences and leads efforts across the Information Security department and enterprise as a subject matter expert in their domain.
- Leads research efforts and analysis of the latest information security vulnerabilities, threats, exploits, trends and intelligence. Shares intelligence with the enterprise. Collaborates in the Intelligence community with external organizations.
- Serves as subject matter expert, leads, and improves the vulnerability management, security configuration assessment, and/or penetration testing programs.
- Develops analysts through training and knowledge sharing activities.
- Monitors internal and external networks, systems, and applications for advanced security anomalies and events (e.g.suspicious behavior attacks, and security breaches). Trains analysts in incident detection and response.
- Leads and improves the incident response program.
- Leads and responds to cyber incidents, performing detailed analysis using complex security tools to determine root cause and impact by using a broad range of demonstrated experience (e.g.forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures.
- Acts as leader for cyber incidents.
- May testify as expert witness in court.
- Incorporates discoveries from the incident response process to substantially improve the existing detection capabilities, operational processes, security controls, and overall program.
- Prepares and delivers written and verbal briefs with recommendations to senior leadership and external parties on latest threats, alerts, incidents, and improvements.
- Drives and directs quality work efforts. Serves as the primary resource for cross-functional team members on escalated issues of a unique nature.
- Maintains expert level knowledge of USAA Information Security standards as well as industry information security best practices, frameworks, laws, and regulations.
- Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.
What you have:
- Bachelor's degree OR 4 years of relevant education and/or experience.
- 8 years of related experience in Information Security, Cybersecurity and/or Information Technology with a security focus to include accountability for complex tasks and/or projects.
- 6 years of related experience in one of the following domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security.
- Expert level of business acumen in the areas of business operations, risk management, industry practices and emerging trends.
- Experience performing security reviews to identify gaps, resulting in recommendations for inclusion in risk mitigation strategies.
- Experience investigating potentially malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information.
What sets you apart:
- Experience leading technical investigations and response activities during cybersecurity incidents, including coordinating responders, prioritizing actions, and validating containment efforts.
- Experience across multiple incident response disciplines, including security monitoring, alert triage, incident investigation, case disposition, malware analysis, digital forensics, threat intelligence, endpoint security, network security, identity security, and incident containment.
- Demonstrated ability to coordinate cross-functional teams and maintain situational awareness during complex or high-severity cybersecurity incidents.
- Experience responding to ransomware, credential compromise, insider threats, data exfiltration, cloud compromise, advanced malware, or other large-scale cyber threats.
- Familiarity with proactive cybersecurity activities such as threat hunting, detection engineering, cyber threat intelligence, purple teaming, red teaming, or adversary emulation.
- Experience developing and maturing incident response programs, processes, playbooks, operating models, and after-action review programs to improve response capabilities and operational effectiveness.
- Experience communicating technical findings, business impact, and response recommendations to senior leadership and stakeholders during active cybersecurity incidents.
- Experience coordinating cybersecurity response activities across security, technology, business, and third-party partner organizations.
Compensation range: The salary range for this position is: $142,320 - $273,930 .
USAA does not provide visa sponsorship for this role. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).
Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location.
Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.
The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.
Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.
For more details on our outstanding benefits, visit our benefits page on USAAjobs.com.
Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.
USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
- ...brands, Toyota is growing and leading the future of mobility... ...experienced and proactive Post Incident Review Lead t o oversee and... ...incident review process for cybersecurity events and incidents. This leadership... ...role is responsible for managing the PIR team, ensuring...SuggestedH1b
- Incident Response Team Lead The Incident Response Team Lead supports day‑to‑day security incident investigations... ...between individual contributors and management, combining hands‑on incident... ...s degree in Information Technology, Cybersecurity, Computer Science, or a related...SuggestedLocal areaImmediate start
- ...Analyst II to investigate escalated alerts, perform root-cause analysis, and mentor Tier 1 analysts. You will lead containment and remediation actions for incidents across multi-tenant government client environments, coordinating with client contacts under defined...Suggested
- ...security, and observability. Establish and manage SLOs/SLIs and error budgets; ensure they... ...and support readiness confirmed. Lead operational readiness reviews and triage... ...toil. Lead and participate in critical incident response (including outside business hours...Suggested
$286.2k - $392k
...Director, Cyber Security Product Manager Capital One is seeking a technical Senior Director, Cybersecurity Product Manager to deliver... ...Recruit, motivate, mentor, and lead those around you to be their best... ...~ Ability to perform security incident analysis and assist with...SuggestedFull timePart timeH1bLocal area- ...Distribution Center Lead The Distribution Center Lead is responsible for training... ...transparent communication across team members and management. Lead clear shift handovers and keep all... ...a strong safety culture by monitoring incident rates, conducting safety walks,...Immediate startShift work
$14 per hour
...Team Lead Position At Sky Zone Frisco The Team Lead is an entry-level leadership position designed to give employees delegation and... ...perform janitorial duties throughout the shift. Complete any incident reports that happened during the shift. Assist with...Hourly payPart timeWork experience placementShift workNight shiftWeekend work- ..., is hiring an Emergency Response Center Lead Operator. The Emergency Response Center (... ...responsible for overseeing emergency monitoring, incident response, and officer dispatch operations... ...response to client needs. The Team Lead manages the ERC staff, coordinates with...Contract workFor subcontractorWork at officeLocal area
- Overview The Lead of Cybersecurity Operations is a hands-on, strategic leader responsible for managing day-to-day cybersecurity operations. This role focuses on threat detection, incident response, vulnerability management, and third-party patching within a hybrid cloud...
$120k - $140k
...Description Onshore Migration Assurance Lead / CBG ServiceNow Migration Business Validation... ...of Service Assurance and Fault Management concepts. Familiarity with OSS/BSS environments... .... Experience analyzing logs, alarms, incidents, and performance metrics. Roles &...- ...security frameworks, spanning campus, cloud, and inter‑cloud environments. You will drive standards, automate deployment patterns, and lead incident response to improve reliability. The role emphasizes collaboration with Cloud, Security, and SRE teams, plus mentoring engineers...
- JPMorganChase in Plano, TX seeks a Technology Support Lead for Infrastructure Platform to drive operational stability and performance of production services. You will lead incident responses, coordinate with distributed teams, and guide MQ connectivity and security practices...
- ...service technician, engineer, or project manager, you’ll discover rewarding opportunities... ...hiring a Security Intervention Specialist Lead. The Security Intervention Specialist Lead... ..., and vulnerabilities Completes incident reports QUALIFICATIONS (MUST HAVE):...Work at officeLocal areaShift work
$70.12 - $77.6 per hour
...continued support is essential. - DevOps - CI/CD Pipeline, Jenkins - SRE - Observability - Readiness for On-call - Incident Management (TOC) - Software Engineering - Some prog exp & understanding of IDE qualifications: - DevOps - CI/CD Pipeline,...Hourly payContract workTemporary workWork experience placement$132.2k - $262.4k
...Overview This role leads the emerging technology space for IAM, evaluating multiple products and capabilities in support of business... ...solutions and technology evolution for Identity and Access Management (IAM) services across the Enterprise. This role requires evaluating...Temporary workWork experience placement- ...is leveraged across one of the world's leading financial institutions. In this role, you... ...environments Deep expertise across data management architecture areas, including relational... ...workflows integrated with ticketing and incident management processes Experience with enterprise...Work at office
$65.9 - $73.9 per hour
...identifying, evaluating, prioritizing, managing, and resolving technology... ...recovery controls Help lead implementation of engineering... ..., information systems, cybersecurity, engineering, or equivalent practical... ..., patching, change control, incident/problem management, and...Hourly payContract workWork at office- ...apply now.We are currently seeking a SAP S4 HANA PP/QM Functional Lead to join our team in Plano, Texas (US-TX), United States (US).... ....Integrate PP with related modules including MM (Materials Management), QM (Quality Management), and SD (Sales & Distribution).Support...Work at officeRemote workFlexible hours
$124k - $233k
...oversight of direct handled and follow market claims in alignment with lead market recommendations, claims handling agreement(s), aviation... ....Preferred Work Experience includes:Significant exposure to managing high risk and/or high value claims.Involvement with relevant...Full timePart timeWork experience placementWork from home- ...now.We are currently seeking a Middleware and OIPA Application Lead to join our team in Plano, Texas (US-TX), United States (US).We... ...seeking an experienced Middleware and OIPA Application Lead, to manage the deployment, automation, and operational stability of our core...Full timeTemporary workWork at officeRemote workFlexible hours
$209k - $238.5k
...Overview Sr. Manager, Cyber Security - Information Security Office Consultant... ...opportunity to be on the forefront of driving cybersecurity governance, capability maturation, and... ...programs ~ Ability to perform security incident analysis and assist with resolution,...Full timePart timeH1bWork at officeLocal areaShift work- ...Store Shift Lead | Murphy Oil USA As one of the largest national gasoline and convenience retailers with more than 1,700 stores in... ...advancement opportunities - promotion from Shift Lead to Assistant Manager can be done in as quickly as 6 months Diverse and inclusive...Daily paidPart timeLocal areaImmediate startShift work
- ...Russell Tobin is seeking a strategic Senior Brand Content Lead to join their fast-growing Marketing organization in Plano, TX. This part-time role involves creating impactful content across multiple channels and leveraging AI tools for efficient production while supporting...Part timeRemote work
- ...Lead Structured Cabling Technician The Lead Structured Cabling Technician is responsible for overseeing the installation, maintenance... ...-Fi Access Point (AP) installation projects. This role involves managing a team of two assistant technicians, ensuring adherence to...For contractorsLocal area
- ...The Senior Lead of Carrier Engagement is responsible for the end‑to‑end performance, satisfaction, and operational excellence of the company’s carrier network. This role develops, manages, and strengthens strategic carrier relationships while ensuring accuracy, compliance...Full time
- ...our operations and contribute to the success of our clients and the firm. You will engage with both internal and external clients, managing expectations and ensuring compliance with credit and asset conditions. Your strategic planning and problem-solving skills will be...
- ...Job Title: Dynamics CRM Functional Lead Work Location: Richardson, TX 75082 Duration: Long Term Must Have: Strong experience... ...Identify, document, track, and verify defects using defect management tools. Collaborate with required stakeholders to clarify...Full time
- ...Quality Inspector. Stop line and escalate the quality incident to the Manager as necessary. Review contents in the Quality... ...company's rules / procedures. Ability to effectively lead, manage, train and motivate employees (Quality Support 1-3)....Local areaShift work
- ...Job Description Job Description Lead the Way at Bruster's Real Ice Cream – Shift Lead Opportunity! Are you ready to take the next... ...in ensuring our store runs smoothly during your shift. From managing daily operations to leading your team, you’ll be the go-to person...Shift work
- ...If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a GTM Lead for Anthropic Partnership to join our team in Plano, Texas (US-TX), United States (US). GTM Lead for Anthropic Partnership NTT...Work experience placementWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Incident Manager - Lead. Be the first to apply!
- remote cyber security Plano, TX
- cyber security Plano, TX
- cybersecurity policy and compliance analyst Plano, TX
- cybersecurity Plano, TX
- cybersecurity certificate Plano, TX
- cyber security architect Plano, TX
- cybersecurity software engineer Plano, TX
- cybersecurity administrator Plano, TX
- senior cybersecurity engineer Plano, TX
- cyber security sales Plano, TX



