Senior Cyber Incident Responder

CanopiusChicago, IL
$95,000 - $115,000Hybrid

About The Position

Canopius is a market-leading cyber insurer with an in-house Cyber Incident Management Team supporting policyholders through stressful and time-critical cyber events. The Senior Cyber Incident Manager will act as a senior escalation point for complex or high-severity incidents, leading the coordination of response activity from notification through to resolution. The role sits between frontline incident response and global leadership, providing experienced operational oversight, guidance to junior responders and consistent service delivery across the global follow-the-sun model. Working closely with Claims, Underwriting, Insights & Analytics and external response vendors, the role will help ensure incidents are managed with clarity, empathy and discipline, while translating live incident experience into practical insights that improve service, underwriting understanding and client preparedness.

Requirements

  • Strong experience in cyber incident management, cyber claims, breach response coordination, crisis response, professional services or a similar client-facing environment.
  • Proven ability to coordinate complex incidents involving multiple stakeholders, vendors and competing priorities.
  • Good understanding of common cyber incidents, including ransomware, business email compromise, data breach, social engineering and operational disruption.
  • Strong client service mindset, with excellent judgement, empathy and composure under pressure.
  • Clear written and verbal communication skills, including the ability to explain technical issues in accessible business language.
  • Strong organisational discipline, including case management, documentation, handovers and action tracking.
  • Experience working with external response vendors, including forensic, legal, communications or advisory partners.
  • Ability to support and guide junior colleagues without requiring full people-management accountability.
  • Comfortable working across regions, time zones and functions in a global operating model.
  • Sufficient cyber understanding (hands-on forensic or deep technical investigation expertise is not required).

Responsibilities

  • Lead and coordinate complex cyber incidents, including ransomware, business email compromise, data incidents, social engineering and operational disruption events.
  • Triage incidents, assess severity, establish response plans and coordinate appropriate vendor support.
  • Act as a senior escalation point for challenging or sensitive matters, escalating strategic or exceptional issues to the Global Head of Cyber Incident Management.
  • Maintain clear incident timelines, actions, decisions, communications and next steps throughout the incident lifecycle.
  • Provide calm, clear and empathetic guidance to policyholders, brokers and internal stakeholders during high-pressure situations.
  • Support consistent service delivery across the global follow-the-sun model, including handovers, SLAs, case documentation and communication standards.
  • Participate in rota and on-call arrangements as required to support global incident response coverage.
  • Ensure incident files, metadata, outcomes and post-incident summaries are accurate, timely and complete.
  • Identify process gaps, service issues and opportunities to improve incident workflows, templates and operating procedures.
  • Provide practical guidance and mentoring to junior Cyber Incident Responders during live incidents and day-to-day case management.
  • Work closely with Claims to support coverage confirmation, claims progression and policyholder communication.
  • Collaborate with Underwriting and Insights & Analytics to share incident trends, loss drivers, control observations and emerging threat themes.
  • Support the development of client preparedness content, tabletop exercises, playbooks and lessons-learned outputs.
  • Coordinate external vendors during live incidents, including forensic firms, legal counsel, communications advisors and specialist response partners.
  • Provide structured feedback on vendor responsiveness, quality, communication, cost management and policyholder experience.
  • Help track vendor outcomes and identify recurring issues or opportunities for service improvement.
  • Contribute to continuous improvement initiatives that enhance policyholder experience, operational consistency and the broader cyber proposition.

Benefits

  • hybrid working
  • competitive base salary
  • non-contributory 401k
  • discretionary bonus
  • insurances including medical, dental and vision cover
  • many other benefits to enhance financial, physical, social and psychological health
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service