The Incident Commander serves as the senior operational leader during cybersecurity incidents and is responsible for directing, coordinating, and managing all response activities throughout the incident lifecycle. This position acts as the central decision-maker during major cyber events, ensuring that technical teams, business stakeholders, executive leadership, and external partners operate in a coordinated and effective manner. The Incident Commander leads incident response efforts involving ransomware, data breaches, cloud compromises, insider threats, business email compromise, advanced persistent threats, and other high-impact security incidents. The role is responsible for establishing response priorities, coordinating technical investigations, managing escalation activities, directing containment and recovery actions, and ensuring timely communication with executive leadership and stakeholders. The Incident Commander serves as the bridge between technical teams and organizational leadership by translating complex technical findings into actionable business information. The position oversees incident status reporting, executive briefings, operational decision-making, forensic coordination, threat intelligence integration, and post-incident reviews. The Incident Commander is ultimately accountable for ensuring incidents are managed efficiently, risks are minimized, and business operations are restored as quickly and safely as possible.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed