К содержимому

Manager, Incident Response

Arctic Wolf · United Kingdom

Зарплата
76 000 – 114 000
Грейд
Middle
Формат
Удалённо
Категория
Безопасность
Откликнуться

Прямого контакта в посте нет

Откройте вакансию в Telegram-боте: там весь исходный пост и способ отклика.

Открыть в Telegram

Описание

Manager, Incident Response
At Arctic Wolf, we're not just navigating the cybersecurity landscape - we're redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: we've earned recognition on the Forbes Cloud 100, CNBC Disruptor 50, Fortune Future 50, and Fortune Cyber 60 lists, and we recently took home the 2024 CRN Products of the Year award. We’re proud to be named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services and earning a Customers' Choice distinction from Gartner Peer Insights. Our Aurora Platform also received CRN’s Products of the Year award in the inaugural Security Operations Platform category. Join a company that’s not only leading, but also shaping, the future of security operations.
Our mission is simple: End Cyber Risk. We’re looking for a Manager, Incident Reponse to be part of making this happen, based in the UK.
About the Role
The Manager, Incident Response is responsible for leading and maturing Arctic Wolf's Incident Response practice by combining strategic leadership, operational management, and advanced technical incident response expertise. This role leads and develops a team of Incident Response professionals while maintaining the technical depth required to support and lead complex investigations, cyber extortion events, ransomware engagements, business email compromise matters, and large-scale recovery efforts.
The Manager is accountable for delivering world-class incident response services, ensuring operational excellence, maintaining technical quality standards, driving process improvements, developing team capabilities, and supporting organizational growth. This individual serves as both a management leader and a senior technical escalation resource capable of leading the most complex investigations and customer engagements
Team Leadership & People Management
- Lead, mentor, develop, and manage a hybrid/remote team of Incident Response professionals.
- Ensure operational standardization across delivery regions
- Recruit, hire, onboard, train, and retain top DFIR talent.
- Conduct performance reviews, career development planning, coaching sessions, and succession planning.
- Foster a culture of collaboration, accountability, technical excellence, and continuous improvement.
- Ensure team members receive exposure to a variety of investigative and recovery activities to support career growth.
- Lead team development initiatives through formal mentoring, peer coaching, technical reviews, and knowledge-sharing programs.
- Serve as an escalation point for personnel, client, and delivery-related issues.
Incident Response Operations
- Oversee the delivery of Incident Response services to ensure consistent, scalable, and high-quality outcomes.
- Scope incoming matters, monitor, and manage incident response engagements across the team.
- Assign personnel to engagements based on skillsets, availability, customer needs, and goals.
- Maintain awareness of all active investigations and recovery efforts, stepping in when escalation or leadership intervention is required.
- Ensure proper case management practices, utilization targets, resource planning, scheduling, and workload balancing.
- Develop and implement operational processes, standards, and quality assurance mechanisms.
- Review incident reports, executive summaries, investigative findings, and customer deliverables prior to delivery.
- Establish and maintain key performance indicators (KPIs), service metrics, and operational reporting capabilities.
- Drive continuous improvement initiatives that enhance efficiency, consistency, customer satisfaction, and service quality.
- Provide technical leadership and mentorship to team members throughout engagements and forensic activities
Technical Incident Response & Forensics
- Lead and support advanced digital forensic and incident response investigations.
- Conduct and oversee host, network, cloud, and log-based forensic analysis.
- Perform investigative activities involving Windows, Linux, macOS, Azure, AWS, and Google Cloud environments.
- Guide containment, eradication, recovery, and remediation activities during active security incidents.
- Validate investigative findings and technical conclusions developed by team members.
- Develop complex investigation strategies and incident response plans for customer environments.
- Conduct forensic analysis through collected evidence to determine threat actor activity and timeline, identify persistent mechanisms, data impact and indicators of compromise.
- Maintain expert-level knowledge of emerging threats, attack methodologies, ransomware trends, and DFIR best practices.
- Participate directly in the most complex, high-risk, or high-visibility engagements, when required.
Customer & Stakeholder Engagement
- Serve as a senior trusted advisor during active cybersecurity incidents.
- Communicate technical findings to executive leadership, legal counsel, insurance carriers, and technical stakeholders.
- Lead scoping discussions and engagement planning for new incident response matters.
- Support cyber extortion and ransomware negotiation strategy development and approval.
- Present recovery plans, investigative findings, and strategic recommendations to customer stakeholders.
- Build and maintain relationships with legal counsel, cyber insurance carriers, strategic partners, and customers.
- Support business development activities, attend industry events, and thought leadership initiatives as needed.
- Recommend Arctic Wolf solutions and services where appropriate based on customer needs.
Strategic Leadership & Program Development
- Partner with Directors and Executive Leadership to execute the vision, strategy, and growth plans for the Incident Response organization.
- Identify opportunities for automation, innovation, tooling improvements, and operational efficiencies.
- Define and standardize processes, methodologies, documentation, and service delivery frameworks.
- Drive reporting and analytics initiatives that demonstrate business impact, customer outcomes, operational efficiency, and risk reduction.
- Collaborate across Product, Engineering, Security Operations, Concierge, MDR, Sales, Marketing, and Customer Success teams.
- Support strategic planning, budgeting, forecasting, workforce planning, and organizational scaling initiatives.
- Champion quality assurance programs, service delivery excellence, and customer experience improvements
General Responsibilities
- Create and participate in escalation, evening, weekend, and holiday on-call rotations.
- Conduct peer reviews, quality reviews, and case audits.
- Promote information sharing, documentation, and organizational learning.
- Maintain required technical certifications and professional development goals.
- Perform other duties as assigned in support of Arctic Wolf's Incident Response mission and organizational objectives.
Key Skills
- Digital Forensics & Incident Response (DFIR)
- Leadership and Team Development
- Incident Command and Crisis Management
- Cyber Extortion and Ransomware Response
- Executive Communication
- Customer Relationship Management
- Strategic Planning
- Operational Excellence
- Process Development and Standardization
- Performance Metrics and Reporting
- Cloud and Enterprise Incident Response
- Investigation Quality Assurance
- Resource Planning and Utilization Management
- Stakeholder Management
- Cross-Functional Collaboration
- Project and Program Management
Minimum Qualifications
- 3+ years of experience leading technical teams, people management, or service delivery organizations.
- Demonstrated experience leading complex cyber incident investigations and recovery efforts.
- Strong knowledge of host, network, cloud, and enterprise forensic analysis.
- Experience managing customer-facing engagements involving legal counsel, cyber insurance carriers, and executive stakeho
  • aws
  • azure
  • gcp
  • linux
  • macos
  • windows
  • dfir
  • incident_response
  • digital_forensics
  • ransomware
  • crisis_management
  • cloud_security

Оценка вакансии

84/100 · хорошо

  • Описание полное
  • Зарплатная вилка указана
  • Компания и проект описаны
  • Контакта нет
  • Стек описан подробно
  • Формат работы понятен
Как считается

Похожие вакансии