Global Cyber Incident Response Lead
$70k - $84.5kCanopius
The Role Canopius is a market ‑ leading cyber insurer with an in ‑ house Cyber Incident Management Team (CIMT) that delivers immediate, expert support to our policyholders during their most critical moments. As an Incident Manager, you’ll be the first point of contact when a client faces a cyber event—whether business email compromise, ransomware, social engineering, data theft, or other attacks. You will triage and lead the response, mobilize our expert panel (forensics, legal, PR, and specialist advisors), and project ‑ manage recovery from containment through restoration, providing calm, clear communication throughout. Operating in a global, follow ‑ the ‑ sun model across Sydney, London, and Chicago, you’ll ensure true 24/7 coverage for new notifications, collaborate closely with our Claims team to support timely coverage assessment, and help clients navigate local legal and regulatory obligations. Sitting at the coal face of live incidents, you’ll also capture structured insights and trends that inform our underwriting, analytics, and ongoing service evolution, all while meeting and exceeding internal SLAs. Responsibilities Own the incident from notification to closure Be the first point of contact for policyholder incident notifications. Rapidly triage, assess severity, and set the response plan and cadence. Orchestrate specialist vendors (IR firms, forensics, legal, PR, ransom advisors), ensuring right‑sized support at the right time. Maintain clear timelines, decisions, and next steps Deliver best in class customer service‑in‑class customer service Provide calm, empathetic guidance under pressure; translate technical issues into clear business impact and options. Set and manage expectations on milestones (containment, restoration, notifications) and costs. Conduct welcome/onboarding calls; explain how to notify, what to expect, and how the IR panel operates. Capture and act on policyholder feedback to continuously improve service. Hit internal SLAs (acknowledgement, triage, vendor mobilization, comms cadence). Operate within a global, 24/7 team model Participate in rota/on call coverage to ensure true follow the sun response. ‑call coverage to ensure true follow‑the‑sun response. Perform structured handovers across regions; maintain accurate case notes and status. Evolve the service offering Contribute to playbook/runbook enhancements and decision trees (e.g., ransomware, BEC, DDoS, data exfil). Recommend panel/vendor improvements and measure vendor SLAs and outcomes. Support content development (guides, FAQs, tabletop scenarios). Collaborate with Claims, Underwriting and Insights & Analytics Partner with the Claims team to ensure smooth coverage confirmation and claim handling. Surface material facts, costs, and causation signals; ensure incident files are complete and timely. Escalate complex matters promptly and appropriately. Sit “at the coal face” of live incidents and distil timely, high-quality insights (threat vectors, controls efficacy, vendor performance, and industry signals). ‑quality insights (threat vectors, controls efficacy, vendor performance, Provide structured post incident summaries and trend themes for underwriters and leadership. ‑incident summaries and trend themes for underwriters and leadership. Ensure precise, consistent capture of incident metadata and outcomes (e.g., root cause, initial access, controls in place, dwell time, MTTA/MTTR, costs). Champion data quality standards; work with Analytics to refine taxonomies and dashboards. Collaborate in delivery of incident preparedness sessions, tabletops, and executive simulations for insureds. ‑deliver incident preparedness sessions, tabletops, and executive simulations for insureds. Feed real world lessons learned into control uplift recommendations. ‑world lessons learned into control uplift recommendations. Skills and Experience A minimum of two years working in the cybersecurity field, ideally with hands ‑ on involvement in incident handling or response activities. Strong foundational knowledge of cyber ‑ attack methods, threat behaviors, and the end ‑ to ‑ end lifecycle of incident response. Demonstrate ability to solve complex problems and make sound judgements quickly, especially when operating in high pressure or fastmoving situations. ‑pressure or fast‑moving situations. Excellent organisational habits with a focus on accuracy and thoroughness in all tasks. Clear and confident communication skills—both written and verbal—with the capability to explain technical issues in an accessible way for non-technical audiences. ‑technical audiences. Basic data skills to partner with Analytics (e.g., Excel/Power BI; familiarity with SQL/Python advantageous). High empathy, composure under pressure, and a service mindset. Salary Range: $70,000 - 84,500 #J-18808-Ljbffr Canopius
- A leading cyber insurance provider is seeking an Incident Manager in Chicago to lead responses to cyber events such as ransomware and data theft. The role involves ensuring client communication, managing the incident lifecycle, and collaborating with teams to support policyholders...Cyber
$98.4k - $160k
Security Incident Response Orchestration Lead The Security Incident Response Orchestration Lead is responsible for defining, scoping, and guiding the... ...Development Access and Identity Management Critical Thinking Cyber Security Information Systems Management Risk...CyberShift workDay shift- A leading global food service company in Chicago is seeking an L3 Response Analyst to fortify its cybersecurity measures. You will monitor security operations, analyze network threats, and lead incident response efforts within a dynamic team. The ideal candidate will have...Cyber
$140k - $170k
...Associate Principal/Cybersecurity & Incident Response Boston, MA, United States; Chicago,... ...Washington, DC, United States CRA is a leading global consulting firm that provides... ...experienced leader in the forensic & cyber investigations space, your responsibilities...CyberWork at officeLocal areaRemote workWork from home3 days per week$130k - $152.5k
...Senior Associate/Cybersecurity & Incident Response (Forensic Services Practice) Boston, MA... ...Washington, DC, United States CRA is a leading global consulting firm that provides... ...guidance to clients on the adequacy of cyber security controls in accordance with cybersecurity...CyberWork at officeLocal areaWork from home3 days per week$100k
Lyra Technology Group is seeking an L2 Cyber Security Analyst for their Managed Security Services... ...-4 years of experience in cybersecurity and responsibilities include monitoring security alerts, conducting analysis, and incident response. Ideal candidates will be...CyberRemote job- ...growing areas of our business, and our global Cyber Investigation and Forensic Response (CIFR) practice is at the heart... ...the most consequential cyber incidents. Within CIFR, our Cyber Recovery... ...0 About Accenture Accenture is a leading global professional services company...CyberFull timeWork experience placementLive inWork at officeLocal area
$77k - $202k
...Cybersecurity Incident Management Senior Associate At PwC, our... ...protecting organizations from cyber threats through advanced technologies... ...and data. You will be responsible for identifying, analyzing, and... ...and experiences you need to lead and deliver value at this...Cyber- ...seeking a Senior Cybersecurity Operations Analyst in Chicago, Illinois. In this role, you will analyze security events, coordinate incident responses, and develop documentation to enhance security processes. A bachelor's degree in a related field and a minimum of five years...
$107k - $214.5k
...We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world... ...nowhere like RSM. The RSM Cyber Response team leads organizations... ...DFIR Manager serves as both incident commander and engagement leader...CyberWork experience placementInternshipLocal area$77k - $202k
...protecting organisations from cyber threats through advanced... ...sensitive data. In cybersecurity incident management at PwC, you will... ...and data. You will be responsible for identifying, analysing, and... ...and experiences you need to lead and deliver value at this level...CyberH1b$100k - $126.5k
...Consulting Associate/Cybersecurity & Incident Response CRA's Forensic Services practice supports companies' commitment to integrity by assisting... ...assessment/audit and guidance to clients on the adequacy of cyber security controls in accordance with cybersecurity frameworks...CyberWork at officeWork from home3 days per week$77k - $202k
...cybersecurity team protects organisations from cyber threats through advanced technologies... ...data. As a member of the Cybersecurity Incident Management team, you will focus on... ...of client systems and data. You will be responsible for identifying, analysing, and resolving...CyberH1b$87.7k - $164k
Ernst & Young Oman is seeking a Cyber Triage and Forensics Incident Analyst based in Chicago, IL. This role involves investigating and resolving security... ...field and over 5 years of experience in incident response, with a focus on digital forensics. A robust understanding...CyberFlexible hours- ...opportunities. Role Overview We are seeking a highly motivated Incident Response Manager to lead our client’s security operations. In this dual role, you... .... Hunt for, detect, and neutralize sophisticated cyber threats across the enterprise environment. Monitor and maintain...CyberContract workImmediate startShift work
- RSM US LLP in Chicago is seeking a DFIR Manager to guide organizations through critical cyber events. This role requires strong incident command authority and deep expertise in ransomware investigations and cross-functional leadership. The successful candidate will oversee...Cyber
- ...opportunities, a world-class training facility, and leading market tools, we help our people continue... .... We are currently seeking a Manager, Incident Response to join our Advisory practice. Responsibilities Lead and manage cyber incident response activities, including...CyberWork experience placementH1bLocal area
$77k - $202k
PwC South Africa is looking for a cybersecurity professional to join their Cybersecurity Incident Management team. The successful candidate will focus on identifying, analyzing, and resolving security incidents to protect client systems and sensitive data. The position...Cyber$140k - $180k
The Information Security Lead for the Cyber Security & Operations function is responsible for providing continuous threat monitoring and incident response services. This individual is responsible... ...Employer. Sidley is an elite global law firm with a known reputation of...CyberFull time$130.61k - $187.87k
...seeking a Privacy Compliance Leader in Chicago, IL. This role will lead the organization’s privacy compliance efforts, ensuring... ...operationalize privacy programs, drive awareness, and support incident response across the enterprise. The ideal candidate will have...$1,000 per month
...SECURITY / CYBER SECURITY SALES ENGINEER (for Enterprise clients... ...area, IL Company : Global Leader in Security Solutions... ...on technical experience with Incident Response (IR) Must have excellent... ...part of the MRI Network, a leading global search firm with over...CyberPermanent employmentFull timeWork from homeWorldwide$83.1k - $141.3k
...a Fortune 500 company, is a globally recognized, award-winning financial... ...sophisticated clients using leading technology and exceptional... ...of and adherence to cyber rules and regulations, controls... ...leaders across the firm. The key responsibilities of the role include: This...CyberH1bFlexible hours$107.7k - $188.5k
...colocation environment. The Network Deployment Manager will be responsible for growing a team within a geographic region and oversee... ...above PREFERRED QUALIFICATIONS - Cloud+ or GICSP (Global Industrial Cyber Security Professional) or GSEC (GIAC Security Essentials)...CyberFlexible hours$152.7k - $294k
Key Responsibilities Strategic Program Development: Define and drive the development... ...& Adoption: Work across global business and technology teams... ...skills. Proven ability to lead cross‑functional initiatives... ...and access management (IAM), incident response, and emerging threat...Summer holidayFlexible hoursShift work- 66degrees Inc. is looking for a motivated Incident Response Manager to lead security operations in Chicago. In this role, you’ll manage a dedicated team of five security professionals and oversee incident response workflows. The ideal candidate has over 3 years of experience...
$107k - $214.5k
...We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world... ...organizations identify their cyber risk, and design and... .... Examples of candidate's responsibilities include: Perform analysis...CyberWork experience placementLocal area$52 - $74 per hour
...Services client is seeking a Lead Security Architect to join their... .... Core Responsibilities Lead Security Architecture... ...integrations, audit logging, alerting, incident response planning, and... ...SaaS governance and third-party cyber risk management...CyberWork at officeLocal area3 days per week$226k - $339.7k
...Vice President, Cyber Exposure Management / Cyber Engineering & Architecture We... ...and highly technical Vice President to lead our global Cyber Exposure Management / Cyber... ...business leaders. Essential Duties and Responsibilities Define and execute the global strategy...CyberWork at office- ...we're at the forefront of a global technology revolution, transforming... ...for a Security Practice Lead to join our Cybersecurity National... .... This individual's primary responsibility is to act as subject matter... ...and frameworks like the cyber kill-chain. Ability to listen...CyberFor contractorsLocal area
$200k - $220k
...Are you looking to lead a global team that focuses on protecting people... ...that integrates physical, cyber, HR, and legal perspectives... ...technical or physical security incidents. Enterprise Alignment:... ...Shift the program from reactive response to predictive prevention by...CyberFull timeTemporary workPart timeLocal areaShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Global Cyber Incident Response Lead. Be the first to apply!

