Director, Cyber Incident Response

Direct TravelRemote,
Remote

About The Position

The Director of Incident Response is responsible for leading the organization's cyber incident response program, ensuring the timely detection, containment, eradication, and recovery from cybersecurity incidents. This role develops and executes the enterprise Incident Response strategy, manages a high-performing Security Operations and Incident Response team, and partners closely with IT, Legal, Privacy, Compliance, Communications, Risk, and executive leadership to minimize business impact from cyber threats. The Director will drive operational excellence across incident response, digital forensics, threat intelligence integration, cyber crisis management, and continuous improvement while ensuring compliance with regulatory and contractual obligations.

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related discipline.
  • 15+ years of cybersecurity experience.
  • 5+ years leading Security Operations or Incident Response teams.
  • Experience leading enterprise-scale cyber incident response.
  • Experience working with executive leadership during cyber crises.
  • Deep knowledge of cloud security (Microsoft 365, Azure).
  • Experience managing enterprise SIEM and EDR platforms.
  • Strong understanding of Identity and Access Management.
  • Experience with threat intelligence and threat hunting.

Nice To Haves

  • CISSP
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Certified Enterprise Defender (GCED)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Manager (CISM)
  • CrowdStrike Falcon
  • Microsoft Entra ID
  • SOAR platforms
  • Threat Intelligence Platforms (TIP)
  • Digital Forensics tools
  • Network Detection & Response (NDR)
  • Email security platforms
  • Cloud-native security tools
  • Executive presence
  • Strategic thinking
  • Decision-making under pressure
  • Crisis leadership
  • Strong communication and presentation skills
  • Cross-functional collaboration
  • Coaching and mentoring
  • Budget and vendor management
  • Continuous improvement mindset

Responsibilities

  • Lead and manage the enterprise Cyber Incident Response (IR) program.
  • Direct response activities for high-severity security incidents, including ransomware, business email compromise, insider threats, cloud attacks, third-party compromises, and data breaches.
  • Serve as Incident Commander during major cyber incidents.
  • Coordinate cross-functional response efforts across IT Infrastructure, Cloud, Identity, Legal, HR, Privacy, Communications, and executive leadership.
  • Ensure rapid containment, eradication, recovery, and lessons learned activities.
  • Oversee operational effectiveness of Security Monitoring, SIEM, EDR/XDR, SOAR, Threat Detection, and Threat Hunting.
  • Establish incident severity models, response playbooks, escalation procedures, and SLAs.
  • Drive improvements in detection engineering and automation.
  • Lead forensic investigations involving endpoints, cloud environments, SaaS platforms, identity systems, and email.
  • Ensure proper evidence preservation and chain of custody.
  • Coordinate with outside forensic firms when necessary.
  • Develop and maintain Cyber Crisis Management plans.
  • Conduct tabletop exercises with executive leadership.
  • Coordinate crisis communications during major incidents.
  • Provide executive briefings and Board-level updates during cyber events.
  • Integrate threat intelligence into detection and response operations.
  • Oversee proactive threat hunting across enterprise environments.
  • Identify emerging threats targeting the organization and industry.
  • Develop and mature the Incident Response program aligned with NIST CSF, NIST SP 800-61, MITRE ATT&CK, and ISO 27035.
  • Maintain incident response policies, standards, procedures, and playbooks.
  • Measure program maturity and drive continuous improvement initiatives.
  • Ensure incident response activities support PCI DSS, HIPAA (where applicable), GDPR, and CCPA.
  • Produce executive dashboards and metrics including Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), Incident trends, Root cause analysis, Detection coverage, and Lessons learned.
  • Build, mentor, and develop global Incident Response and Security Operations personnel.
  • Foster a culture of continuous learning and operational excellence.
  • Participate in hiring, budgeting, workforce planning, and performance management.

Benefits

  • Medical
  • Dental
  • Vision
  • Retirement Plans
  • Wellness
  • Rewards and Recognition
  • Sustainability
  • DE&I initiatives
  • Mental Health Support
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service