Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Global Cyber Incident Response Lead

$70k - $84.5k

Canopius

The Role Canopius is a market ‑ leading cyber insurer with an in ‑ house Cyber Incident Management Team (CIMT) that delivers immediate, expert support to our policyholders during their most critical moments. As an Incident Manager, you’ll be the first point of contact when a client faces a cyber event—whether business email compromise, ransomware, social engineering, data theft, or other attacks. You will triage and lead the response, mobilize our expert panel (forensics, legal, PR, and specialist advisors), and project ‑ manage recovery from containment through restoration, providing calm, clear communication throughout. Operating in a global, follow ‑ the ‑ sun model across Sydney, London, and Chicago, you’ll ensure true 24/7 coverage for new notifications, collaborate closely with our Claims team to support timely coverage assessment, and help clients navigate local legal and regulatory obligations. Sitting at the coal face of live incidents, you’ll also capture structured insights and trends that inform our underwriting, analytics, and ongoing service evolution, all while meeting and exceeding internal SLAs. Responsibilities Own the incident from notification to closure Be the first point of contact for policyholder incident notifications. Rapidly triage, assess severity, and set the response plan and cadence. Orchestrate specialist vendors (IR firms, forensics, legal, PR, ransom advisors), ensuring right‑sized support at the right time. Maintain clear timelines, decisions, and next steps Deliver best in class customer service‑in‑class customer service Provide calm, empathetic guidance under pressure; translate technical issues into clear business impact and options. Set and manage expectations on milestones (containment, restoration, notifications) and costs. Conduct welcome/onboarding calls; explain how to notify, what to expect, and how the IR panel operates. Capture and act on policyholder feedback to continuously improve service. Hit internal SLAs (acknowledgement, triage, vendor mobilization, comms cadence). Operate within a global, 24/7 team model Participate in rota/on call coverage to ensure true follow the sun response. ‑call coverage to ensure true follow‑the‑sun response. Perform structured handovers across regions; maintain accurate case notes and status. Evolve the service offering Contribute to playbook/runbook enhancements and decision trees (e.g., ransomware, BEC, DDoS, data exfil). Recommend panel/vendor improvements and measure vendor SLAs and outcomes. Support content development (guides, FAQs, tabletop scenarios). Collaborate with Claims, Underwriting and Insights & Analytics Partner with the Claims team to ensure smooth coverage confirmation and claim handling. Surface material facts, costs, and causation signals; ensure incident files are complete and timely. Escalate complex matters promptly and appropriately. Sit “at the coal face” of live incidents and distil timely, high-quality insights (threat vectors, controls efficacy, vendor performance, and industry signals). ‑quality insights (threat vectors, controls efficacy, vendor performance, Provide structured post incident summaries and trend themes for underwriters and leadership. ‑incident summaries and trend themes for underwriters and leadership. Ensure precise, consistent capture of incident metadata and outcomes (e.g., root cause, initial access, controls in place, dwell time, MTTA/MTTR, costs). Champion data quality standards; work with Analytics to refine taxonomies and dashboards. Collaborate in delivery of incident preparedness sessions, tabletops, and executive simulations for insureds. ‑deliver incident preparedness sessions, tabletops, and executive simulations for insureds. Feed real world lessons learned into control uplift recommendations. ‑world lessons learned into control uplift recommendations. Skills and Experience A minimum of two years working in the cybersecurity field, ideally with hands ‑ on involvement in incident handling or response activities. Strong foundational knowledge of cyber ‑ attack methods, threat behaviors, and the end ‑ to ‑ end lifecycle of incident response. Demonstrate ability to solve complex problems and make sound judgements quickly, especially when operating in high pressure or fastmoving situations. ‑pressure or fast‑moving situations. Excellent organisational habits with a focus on accuracy and thoroughness in all tasks. Clear and confident communication skills—both written and verbal—with the capability to explain technical issues in an accessible way for non-technical audiences. ‑technical audiences. Basic data skills to partner with Analytics (e.g., Excel/Power BI; familiarity with SQL/Python advantageous). High empathy, composure under pressure, and a service mindset. Salary Range: $70,000 - 84,500 #J-18808-Ljbffr Canopius

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Global Cyber Incident Response Lead in Chicago, IL vacancy
  • A leading cyber insurance provider is seeking an Incident Manager in Chicago to lead responses to cyber events such as ransomware and data theft. The role involves ensuring client communication, managing the incident lifecycle, and collaborating with teams to support policyholders... 
    Cyber

    Canopius Group

    Chicago, IL
    4 days ago
  • $98.4k - $160k

     ...Security Incident Response Orchestration Lead The Security Incident Response Orchestration Lead is responsible for defining, scoping, and guiding the...  ...Development Access and Identity Management Critical Thinking Cyber Security Information Systems Management Risk Management... 
    Cyber
    Shift work
    Day shift

    Bank of America

    Chicago, IL
    3 days ago
  •  ...A leading global food service company in Chicago is seeking an L3 Response Analyst to fortify its cybersecurity measures. You will monitor security operations, analyze network threats, and lead incident response efforts within a dynamic team. The ideal candidate will... 
    Cyber

    McDonald's Corporation

    Chicago, IL
    4 days ago
  • The University Of Chicago is seeking a Cyber Defense Security Architect to implement...  ...infrastructure, and respond to cybersecurity incidents. This position is integral to enhancing...  ...the Biological Sciences Division. With responsibilities spanning from vulnerability management... 
    Cyber

    The University Of Chicago

    Chicago, IL
    2 days ago
  • $110k - $125k

     ...improving the Firm's Cybersecurity Operations and Response program, managing threat and vulnerability initiatives, and leading incident response efforts. The ideal candidate should...  ...to protect the Firm’s systems and data from cyber threats while enjoying a collaborative work... 
    Cyber

    Fox Rothschild LLP

    Chicago, IL
    3 days ago
  • $84.63k - $112.84k

     ...us today. The Role Cybersecurity Incident Response Team (CIRT) Engineers at Lumen are on the...  ...of protecting the systems that power global connectivity. In this role, you’ll respond...  ...Support Security projects to improve Cyber Defense Team or Lumen's security... 
    Cyber
    Full time
    Temporary work
    Remote work
    Shift work

    Lumen

    Chicago, IL
    3 days ago
  • $77k - $202k

     ...cybersecurity team protects organisations from cyber threats through advanced technologies...  ...data. As a member of the Cybersecurity Incident Management team, you will focus on...  ...of client systems and data. You will be responsible for identifying, analysing, and resolving... 
    Cyber
    H1b

    PwC South Africa

    Chicago, IL
    4 days ago
  • $130k - $160k

    A prominent financial institution is seeking a Cybersecurity Incident Manager to lead the response and management of escalated incidents, ensuring cybersecurity threats are effectively contained. The ideal candidate will possess extensive experience in forensics, incident... 

    Wintrust Financial Corporation

    Chicago, IL
    3 days ago
  •  ...seeking a Senior Cybersecurity Operations Analyst in Chicago, Illinois. In this role, you will analyze security events, coordinate incident responses, and develop documentation to enhance security processes. A bachelor's degree in a related field and a minimum of five years... 

    Illinois Attorney General (IL)

    Chicago, IL
    2 days ago
  • $87.7k - $164k

     ...Ernst & Young Oman is seeking a Cyber Triage and Forensics Incident Analyst based in Chicago, IL. This role involves investigating and resolving security...  ...field and over 5 years of experience in incident response, with a focus on digital forensics. A robust understanding... 
    Cyber
    Flexible hours

    Ernst & Young Oman

    Chicago, IL
    4 days ago
  • $107k - $214.5k

    We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world...  ...’s nowhere like RSM.The RSM Cyber Response team leads organizations through...  ...DFIR Manager serves as both incident commander and engagement... 
    Cyber
    Work experience placement
    Internship
    Local area

    Rsm Us Llp.

    Chicago, IL
    4 days ago
  • Accenture is looking for a Security Transformation Senior Analyst to support the end-to-end delivery of Incident Response (IR) readiness engagements. You will develop crisis readiness deliverables and assist in simulations and exercises. The ideal candidate brings a solid... 
    Cyber

    Accenture

    Chicago, IL
    2 days ago
  •  ...opportunities, a world-class training facility, and leading market tools, we help our people continue...  .... We are currently seeking a Manager, Incident Response to join our Advisory practice. Responsibilities Lead and manage cyber incident response activities, including... 
    Cyber
    Full time
    Work experience placement
    H1b
    Local area

    KPMG

    Chicago, IL
    2 hours ago
  •  ...Charles River Associates CRA is a leading global consulting firm that provides...  ...leader in the forensic & cyber investigations space, your responsibilities as a Principal may include (but...  ...breach detection, threat analysis, incident response and malware analysis;... 
    Cyber
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    more than 2 months ago
  •  ...Charles River Associates CRA is a leading global consulting firm that provides...  ..., in preparation of, and in response to, data security matters, which...  ...of trade secret investigations, cyber breach detection, threat analysis, incident response and malware analysis;... 
    Cyber
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    more than 2 months ago
  • RSM US LLP in Chicago is seeking a DFIR Manager to guide organizations through critical cyber events. This role requires strong incident command authority and deep expertise in ransomware investigations and cross-functional leadership. The successful candidate will oversee... 
    Cyber

    RSM US LLP

    Chicago, IL
    1 day ago
  • $117.6k - $161.7k

     ...Nashville. The Senior Digital Forensics and Incident Response Engineer provides forensics technical...  ...an impact Role Requirements 5+ years Cyber Security Experience 3+ years Digital...  ...Humana: Humana Inc. (NYSE: HUM) is a leading U.S. healthcare company. Through our Humana... 
    Cyber
    Full time
    Temporary work
    For contractors
    Apprenticeship
    Remote work
    Work from home
    Relocation
    Home office

    Humana Inc

    Chicago, IL
    5 days ago
  • $114.5k - $194.7k

     ...Fortune 500 company, is a globally recognized, award-...  ...sophisticated clients using leading technology and...  ...Engineering team. This role is responsible for designing,...  ...equivalent experience in cyber security, engineering,...  ...with ServiceNow incident and change management... 
    Cyber
    Flexible hours

    Northern Trust

    Chicago, IL
    3 days ago
  • $83.1k - $141.3k

     ...a Fortune 500 company, is a globally recognized, award‑winning financial...  ...sophisticated clients using leading technology and exceptional...  ...and adherence to cyber rules and regulations, controls...  ...stakeholder‑management skills. Key Responsibilities Support the operation and... 
    Cyber
    Visa sponsorship
    Work visa

    Koitecc Solutions

    Chicago, IL
    3 days ago
  •  ...Security Engineer, Group Lead provides technical...  ...resiliency, visibility, and cyber posture. What You'll Do...  ...Endpoint Detection & Response (EDR), Network Detection...  ...for OT SOC operations Incident Response Act as a technical...  ...US Kraft Heinz is a global food company with a... 
    Cyber
    Full time
    Flexible hours

    The Kraft Heinz Company

    Chicago, IL
    17 hours ago
  • $110k - $130k

    Epiq is seeking a Review Manager for its Cyber Incident Response group in Chicago, Illinois. The role demands a minimum of 2 years of project or review management experience, and expertise in database administration, particularly with Relativity. You will act as the primary... 
    Cyber
    Remote job

    Epiq

    Chicago, IL
    2 days ago
  • $226k - $339.7k

    ## Vice President, Global Cyber Exposure Management & Cyber Engineering and ArchitectureApplyremote...  ...and highly technical Vice President to lead our global Cyber Exposure Management /...  ...leaders.**Essential Duties and responsibilities****Strategic Leadership*** Define and execute... 
    Cyber
    Work at office

    Wolters Kluwer N.V.

    Chicago, IL
    3 days ago
  • $100k - $115k

     ...Senior Analyst, Cybersecurity Operations & Response supports the execution and continuous...  ...for assisting with security operations, incident response activities, and threat and vulnerability...  ...’s systems, applications, and data from cyber threats. ESSENTIAL FUNCTIONS Support the... 
    Cyber
    Full time
    Contract work
    Work at office

    Fox Rothschild

    Chicago, IL
    4 days ago
  • A leading financial services firm is seeking a Senior Director for their Technology Solutions Department in Chicago. This role emphasizes cybersecurity management, threat assessment, and project leadership. Candidates must hold a Bachelor's degree and have over 15 years... 

    Golub Capital BDC Inc

    Chicago, IL
    5 days ago
  •  ...industry leader in building products based in Chicago, is seeking a Senior Cybersecurity Engineer to lead advanced cybersecurity operations focusing on incident response and forensic investigation. The role is critical in designing secure recovery environments and... 

    Usg

    Chicago, IL
    4 days ago
  • Readiness, Response & Recovery Security AI Developer Security Transformation Team Lead/Consultant | Mid-Level | Full time A cybersecurity...  ...before, during, and after an incident. We design and run high‑...  ...have a strong foundation in cyber readiness and recovery concepts... 
    Cyber
    Full time

    Accenture

    Chicago, IL
    1 day ago
  • $114.5k - $194.7k

     ...a Fortune 500 company, is a globally recognized, award-winning financial...  ...sophisticated clients using leading technology and exceptional...  ...individual contributor responsible for modernizing how the firm...  ...partnering across functions (e.g., Cyber Security, Data Governance, business... 
    Cyber
    H1b
    Flexible hours

    Koitecc Solutions

    Chicago, IL
    3 days ago
  • $114.5k - $194.7k

    ## Sr Lead, Cyber Sec IT RiskMApplylocations: Chicago, ILtime type: Full timeposted on: Posted...  ...Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution...  ...a high‐impact individual contributor responsible for modernizing how the firm manages... 
    Cyber
    H1b
    Flexible hours

    Northern Trust Corp

    Chicago, IL
    3 days ago
  •  ...for top achievers. As a Senior Lead Cybersecurity Architect at...  ...multiple technology domains. Job responsibilities You will guide the evaluation...  ...of 6 years of experience in cyber security architecture....  ...diverse talents they bring to our global workforce are directly linked... 
    Cyber
    For contractors

    慨正橡扯

    Chicago, IL
    2 days ago
  •  ...role involves enhancing the organization's cybersecurity posture and safeguarding data through strategic security measures and incident response. The ideal candidate will have a Bachelor's Degree in a technical field, along with at least three years of cybersecurity... 
    Full time

    Edward Elmhurst Health

    Skokie, IL
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Global Cyber Incident Response Lead. Be the first to apply!