Job Title: IT Security Manager (Incident Management)
Role Summary
The IT Security Manager (Incident Management) is responsible for leading the organization's incident response program, including security event monitoring, incident escalation, digital forensics, OSINT investigations, threat intelligence, and coordination with executive leadership. The role also mentors the Incident Response team and leads post-incident reviews.
Key Responsibilities
- Lead cybersecurity incident response from detection through containment, eradication, and recovery.
- Perform incident triage and determine the severity of security incidents.
- Conduct Open-Source Intelligence (OSINT) investigations.
- Participate in Red Team / Blue Team exercises.
- Perform digital forensic investigations on endpoints, servers, cloud environments, and mobile devices.
- Analyze malware and forensic evidence.
- Develop and improve incident response procedures.
- Coordinate with Security Operations, Legal, HR, and executive leadership.
- Lead incident bridge calls and post-mortem reviews.
- Maintain incident documentation and recommend remediation actions.
- Review threat intelligence and communicate emerging threats.
- Drive cyber defense improvements and security awareness.
Required Qualifications
- Bachelor's degree in Computer Science, MIS, or equivalent experience.
- 7+ years of IT experience.
- 3+ years in Information Security.
- 2+ years of Incident Handling experience.
- Strong understanding of:
- Network protocols
- Firewalls
- IDS/IPS
- Encryption
- Experience with:
- OSINT tools
- Cloud and physical forensic investigations
- Red Team / Blue Team exercises
- Incident Response frameworks
- SIEM & SOAR platforms
- Digital forensic tools (EnCase, AccessData, SIFT, Axiom)
- ITIL (Not mentioned)
- 247 Security Operations environment
Required Technologies
- ThreatConnect
- MISP
- Splunk
- Snowflake
- Swimlane
- Demisto
- EnCase
- AccessData
- SIFT
- Axiom
- Incident Response
- Malware Analysis
- Threat Hunting
- Network Security
- Risk Management
Compliance & Frameworks
- GDPR
- ISO 27001
- NIST 800-53
- NIST CSF
- PCI DSS
Preferred Certifications
- CISSP
- ITIL
- GCIH
- CERT/CC CSIH
- GCTI
- GCFR
- GCFA
- GIME
- GCFE