Lead, Cyber Threat Response

Estée Lauder Companies, NY
$105,100 - $172,600Onsite

About The Position

The Cyber Threat Response (CTR) Lead is a junior leadership role supporting incident coordination, security event investigation, and security operations. The CTR Lead coordinates triage, containment, remediation, recovery, and closure activities during active security events while keeping stakeholders informed and documenting actions, findings, and outcomes. The CTR Lead partners with Security Operations, IT, Legal, Privacy, and external partners to support timely decisions, consistent execution, and continuous improvement of response readiness. This position is based in NYC and collaborates with global teams across the company.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Digital Forensics, or a related field; equivalent experience will be considered.
  • 3–5 years of experience in threat management, cybersecurity, security operations, incident response, threat hunting, digital forensics, vulnerability management, or related technical work.
  • Working knowledge of cybersecurity frameworks, standards, and incident response best practices.
  • Ability to assess event criticality and business impact with attention to detail and operational context.
  • Knowledge of incident response, threat detection, security monitoring, and cyber investigations.
  • Experience with SIEM, EDR, SOAR, case management, and digital forensic tools.
  • Familiarity with MITRE ATT&CK, the NIST Cybersecurity Framework, and incident response methodologies.
  • Knowledge of operating systems, cloud, networking, identity, endpoint security, and logging concepts.
  • Ability to explain findings, risks, and recommended actions to technical and non-technical audiences.
  • Analytical, organized, detail-oriented, and able to follow structured processes.
  • Communicates clearly with technical and non-technical audiences.
  • Collaborates effectively across technical, business, and vendor teams.
  • Demonstrates developing leadership, sound judgment, accountability, and ownership.
  • Manages priorities, remains calm during active events, and escalates appropriately.

Nice To Haves

  • GCIH, GCFA, GCIA, GCTI, OSCP, CHFI, or other relevant cybersecurity certifications

Responsibilities

  • Investigate threat activity by reviewing evidence, assessing impact, and documenting findings.
  • Coordinate incident response activities across triage, containment, remediation, recovery, and closure.
  • Lead response efforts for emerging threats, including zero-day vulnerabilities, third-party breaches, and threat hunting findings.
  • Collaborate with internal teams and external partners for timely decision-making, escalation, and resolution.
  • Maintain playbooks, workflows, and response documentation to support consistent execution.
  • Support tabletop exercises, lessons learned, and after-action reviews to improve response readiness.
  • Lead or support on-call emergency cyber incident response activities outside normal business hours, including nights and weekends during active incidents.
  • Support insider threat reviews, threat hunting, and executive protection activities by analyzing security data and presenting findings.
  • Assist with digital forensics and eDiscovery through evidence collection, preservation, analysis, and documentation.
  • Contribute to projects and assessments that strengthen security operations and response maturity.
  • Support forensics lab maintenance and case management improvements.

Benefits

  • health insurance coverage (medical, dental, and vision insurance)
  • wellness and family support programs
  • life and disability insurance
  • retirement savings plans
  • education-related programs
  • paid holidays and vacation time
  • incentive compensation programs
  • Commission/Bonus Plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service