> Markdown version of [/jobs/ext/1862347-manager-incident-response](https://www.wearedevelopers.com/jobs/ext/1862347-manager-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Incident Response - **Company:** PONDURANCE, LLC - **Location:** United States (Remote available) - **Salary:** $150,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Unix, Communications Protocols, Cyber Security, Computer Programming, Digital Forensics, Forensics Tools (Digital Forensics Software), Network Forensics, Network Protocols, Reverse Engineering, Scripting, Malware, Information Technology, Build Tools, Encase, SentinelOne Expertise - **Published:** July 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3c9089e89b75cbd2 ## About the Role * Minimum of 5 years of experience in cybersecurity * 1 or more years of experience leading information security and/or consulting teams * A Bachelor's Degree with disciplines in the area of Computer Science, Management Information Systems, or Cyber Security, or equivalent experience, is preferred * One or more of the following technical certifications preferred: GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), MCFE, EnCE, or equivalent certifications * Proven track record of complex problem-solving and decision-making ability * Expert level of analytical, planning, and organizational ability. * Strong, proactive communication skills are required If you have other combinations of relevant skills and experience that you expect to make you the right candidate for this role, please let us know. ## Description As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver industry-best service to our customers. This role requires you to be an innovator and driver for customer success in our investigations, digital forensics, and security incident response and support. You will be a thought leader within the company, working closely with internal and external resources and stakeholders to ensure timely, effective incident response and customer success. Responsibilities * Provide thought, technical, and general leadership to the IR Consulting Team and other stakeholders * Assist with managing the team portfolio to defined metrics (utilization, revenue, margin, etc.) * Deliver services to customers by attending key meetings, performing quality assurance reviews of deliverables, and providing direct consultation with customers as needed * Collaborate with the Product Management Team to define and evolve our book of service offerings * Team with Sales as support on prospective client calls, project scoping, and budgets * Maintain individual and team skills and knowledge base on industry best practices, tools, tabletop exercise techniques, and scenario-based and live testing exercises. * Manage customer stakeholders and apply security incident investigation protocols from incident confirmation through resolution to lessons-learned. * Quickly mitigate damages by coordinating with technical teams and third-party vendors to triage and contain threats. * Maintain and update incident response playbooks and toolkits based on new procedures, best practices, advanced open-source technologies, and various incident response products. * Design and deploy real-time monitoring and triage of incidents and alerts received. * Identify and document requirements to improve, automate, and work with developers to build tools that drive out inefficiencies, ineffectiveness, and uncompromisingly improve the customer experience. * Build and foster relationships with local, state, federal, and international law enforcement authorities. Technologies * Windows OS and networking protocols * Windows disk and memory forensics * Unix OS and networking protocol * Network traffic analysis * Scripting and/or programming * Experience with commercial EDR (SentinelOne, Blackberry PROTECT, CarbonBlack, CrowdStrike) and Forensic tool suites (FTK, AXIOM, EnCase) * Reverse engineering and malware analysis ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)