Security Incident Coordinator

Wilson•Charlotte, NC
•Hybrid

About The Position

Our technology client is seeking a detail-oriented and organized Security Incident Coordinator to join the Security Operations Center (SOC) within Threat Operations. The Security Incident Coordinator will own task management, coordination, and reporting for cybersecurity, trust & safety, and fraud incidents across the organization, ensuring timely and effective resolution and clear communication at every stage.

Requirements

  • Bachelor's degree in Information Security, Computer Science, Management Information Systems, or a related field, or equivalent experience.
  • Minimum 3 years of experience in incident coordination, security operations, or a closely related field.
  • Demonstrated ability to manage multiple concurrent incidents, tasks, and stakeholders in a high-pressure environment while maintaining accuracy and composure.
  • Solid working knowledge of incident response procedures across cybersecurity, trust & safety, and fraud contexts.
  • Excellent organizational, written, and verbal communication skills; able to translate technical detail for non-technical audiences and vice versa.
  • Comfort working across Insider Risk, Escalations, and DFIR functions without owning their technical domains directly.

Nice To Haves

  • Relevant certifications a plus: PMP, ITIL, CISM, or GCIH.
  • Experience with ServiceNow Security Incident Response (SIR) or a comparable ITSM/SIR platform strongly preferred.

Responsibilities

  • Serve as the primary coordinator for major cybersecurity, trust & safety, and fraud incidents: organizing tasks, tracking progress, and maintaining clear communication across all involved teams and stakeholders in ServiceNow Security Incident Response (SIR).
  • Coordinate the full incident lifecycle: containment, eradication, recovery, and closure, ensuring containment is validated against Intuit's control-testing standard before an incident is marked resolved.
  • Develop, maintain, and enforce incident response playbooks and protocols in partnership with SOC capability champs across Insider Risk, Escalations, and DFIR, ensuring consistency without duplicating existing ownership.
  • Produce regular incident reporting, from operational status updates to board/SLT-level summaries, with clear actions taken, outcomes, and recommendations for improvement.
  • Run the lessons-learned loop: facilitate post-incident hot washes, convert findings into documented action items, and drive report/playbook updates on a regular cadence rather than ad hoc.
  • Provide clear, comprehensive documentation and updates to relevant internal partners, including IT, Legal, Compliance, and Customer Support.
  • Support onboarding and training for team members on incident response protocols and tooling, reinforcing adherence to established SOC processes.
  • Stay current on incident response and fraud/trust & safety best practices, adapting SOC processes as threats and requirements evolve.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service