Lead Service Manager - Incident Response Analyst

Open Text CorporationWaterloo, ON
$86,800 - $130,200

About The Position

As a global leader in secure information management, OpenText empowers businesses to stay ahead of the ever-evolving cyber threats. Our Cybersecurity Enterprise portfolio is formidable, offering innovative solutions that safeguard organizations from malicious attacks, data breaches, and cyber vulnerabilities. By joining our team, you'll be at the forefront of developing and implementing state-of-the-art security technologies, protecting critical assets and sensitive information for clients worldwide. The Lead Service Manager is a senior technical practitioner within the MSS SOC and CSIRT function, responsible for leading and delivering incident response engagements across the organization’s multi-tenant managed security client base. This role provides dedicated capacity for the Incident Response retainer service, ensuring clients receive rapid, expert-led containment, investigation, and remediation when security incidents occur. Operating within an MSS environment serving SMB clients, the Senior IR Analyst works alongside the existing CSIRT and DFIR capability to ensure retainer commitments are met without degrading day-to-day detection and response operations. The role demands a practitioner who can operate independently under pressure, communicate clearly with client stakeholders, and contribute to the continuous improvement of the MSS incident response capability. This role is critical to maintaining client trust and delivering high-confidence incident response outcomes across the MSS portfolio.

Requirements

  • 5+ years of progressive cybersecurity experience, including 3+ years in hands-on Incident Response (IR), DFIR, or senior SOC analyst roles.
  • Proven experience leading incidents through the full IR lifecycle, including preparation, detection, analysis, containment, eradication, recovery, and post-incident activities.
  • Hands-on digital forensics expertise across Windows, Linux, macOS, network, and cloud environments.
  • Experience delivering security services within MSSP, SOC, or MDR environments supporting multiple clients concurrently.
  • Strong background producing client-facing incident reports, post-incident reviews, and investigative documentation.
  • Proficiency with SIEM platforms (Devo, Splunk, Sentinel), EDR tools (CrowdStrike, SentinelOne, Defender for Endpoint), and case management systems.
  • Deep knowledge of cyber attack lifecycles, threat actor TTPs, ransomware, BEC, APT, insider threats, and identity-based attack techniques.
  • Expertise in forensic artifact analysis, memory forensics, live-response triage, network forensics, and cloud investigations across Microsoft 365, Azure AD/Entra ID, AWS, and Google Workspace.
  • Scripting and automation skills using Python, PowerShell, or Bash, with familiarity in SIEM/SOAR platforms, automated response playbooks, malware analysis, and chain-of-custody practices.
  • Holds or is actively pursuing industry certifications such as GIAC Certified Incident Handler (GCIH) or GIAC Certified Forensic Analyst (GCFA), with strong communication, leadership, collaboration, and documentation skills.

Responsibilities

  • Lead Incident Response (IR) retainer engagements, directing containment, eradication, recovery, and incident triage activities across client environments.
  • Investigate security incidents including ransomware, BEC, data exfiltration, insider threats, and APTs through remote and on-site response engagements.
  • Coordinate incident response efforts with client IT teams, legal counsel, insurers, regulators, and stakeholders in accordance with MSOD requirements.
  • Deliver professional incident reports, root cause analyses, and post-incident review (PIR) documentation.
  • Maintain chain-of-custody procedures for digital evidence and support forensic investigations with legal or regulatory implications.
  • Perform digital forensic investigations across Windows, Linux, macOS, Microsoft 365, Azure AD/Entra ID, AWS, and Google Workspace environments.
  • Analyze memory, disk, log, network, and cloud audit data to determine incident scope, impact, root cause, and develop IOCs.
  • Utilize EDR tools and threat-hunting techniques to identify adversary activity, trace lateral movement, and support containment decisions.
  • Serve as an escalation point for SOC analysts, providing mentorship, investigation guidance, and contributing to IR playbooks, runbooks, TTX, and purple team exercises.
  • Communicate incident status, impacts, PIR findings, and strategic recommendations effectively to both technical and executive stakeholders.

Benefits

  • Compensation programs, including variable and commission compensation opportunities for eligible roles
  • Vacation entitlement
  • Paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service