> Markdown version of [/jobs/ext/1892173-director-cybersecurity-incident-response](https://www.wearedevelopers.com/jobs/ext/1892173-director-cybersecurity-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director Cybersecurity Incident Response - **Company:** Mountain America Credit Union - **Location:** Sandy, UT, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Digital Forensics, Cyber Threat Analysis, Blue Team (Cyber Security) - **Published:** August 1, 2026 - **Apply:** https://macu.wd5.myworkdayjobs.com/MACU_Careers/job/Sandy-UT/Director-Cybersecurity-Incident-Response_R20373-1 ## About the Role To be effective, an individual must be able to perform each job duty successfully. This is a Director level role that will be tasked to come into the organization and be a hands-on leader to re-establish, build, manage, and guide the team., * 8+ years of experience in cybersecurity operations or incident response with progressive responsibility. * 5+ years in a leadership role responsible for cybersecurity operations or incident response. * Experience leading enterprise-scale incident response programs. * Financial services or regulated industry experience preferred. * Bachelor's degree in a related discipline or equivalent experience required. Licenses, Certifications, Registrations * CISSP strongly preferred. * GCIH, GCFA, CISM, CISA, or GIAC certifications highly desirable. Other Skills and Abilities * Expertise in incident response and digital forensics. * Strong understanding of insider threat risk and investigations. * Executive-level communication and leadership under pressure. * Proven ability to balance security, privacy, and business needs. * Data driven decision making and the ability to drive a program through metrics and tell the story of why things matter * Strategic thinking. * Problem-solving skills. * Verbal/written communication skills. * Leadership and talent management skills. * Public speaking skills., Close vision (clear vision at 20 inches or less) Distance vision (clear vision at 20 feet or more) Color vision (ability to identify and distinguish colors) Weight Lifted or Force Exerted Ability to lift up to 10 pounds frequently and up to 25 pounds occasionally ## Description The Director of Cybersecurity Incident Response & Insider Threat leads MACU's enterprise-wide cyber incident response, digital forensics, threat intelligence, and insider threat program. This role is responsible for preparing the organization to detect, respond to, and recover from cybersecurity incidents while protecting member data, intellectual property, and critical systems. In this highly visible leadership role, you will partner closely with Cybersecurity, IT, Legal, HR, Governance, Risk Management, and Executive Leadership to manage high-impact incidents, insider risk, and crisis situations. You will define response strategy, mature operational capabilities, and ensure the organization is resilient against both external, Incident Response & Crisis Management * Lead the enterprise cybersecurity incident response program, including preparation, detection, containment, eradication, and recovery activities. * Serve as the executive incident commander for high-severity cybersecurity events, coordinating technical teams, business stakeholders, and leadership. * Define and maintain incident response plans, playbooks, escalation models, and crisis communication procedures. * Conduct executive-level briefings during and after incidents, including post-incident reports, root cause analysis, and lessons learned. * Oversee breach investigations, digital forensics, and evidence preservation in coordination with Legal and Compliance. * Lead tabletop exercises, red/blue team simulations, and ransomware readiness scenarios. * Lead the organization's brand protection efforts to safeguard reputation and identity. * Lead proactive threat-hunting initiatives to identify advanced threats, vulnerabilities, and anomalous activities across the enterprise environment. * Define and maintain incident response plans, playbooks, escalation models, and crisis communication procedures. Insider Threat Program Leadership * Own and operate the enterprise Insider Threat Program, addressing malicious, negligent, and compromised insider risks. * Define insider threat detection, triage, investigation, and response processes across people, process, and technology. * Partner with HR, Legal, Privacy, and Risk Management teams to ensure investigations are lawful and appropriate. * Implement behavioral, technical, and contextual monitoring capabilities. * Establish governance, oversight, and separation of duties for insider investigations. Security Operations & Capability Maturity * Collaborate with SOC leadership to enhance monitoring, alerting, and response automation. * Drive continuous improvement using metrics and maturity models. * Translate threat intelligence into actionable detection and response strategies. Governance, Risk, and Compliance * Ensure alignment with regulatory frameworks including NCUA, FFIEC, and NIST. * Support audits, regulatory exams, and breach notification requirements. * Partner with Risk Management and Internal Audit to remediate gaps. Leadership & Influence * Lead and mentor incident response and insider threat professionals. * Partner across IT, Digital Solutions, Legal, HR, Communications, and executives. * Act as a trusted advisor during high-impact and sensitive situations. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [AI Space Factories, Hacking Self-Driving Cars & Detecting Deepfakes](https://www.wearedevelopers.com/videos/1812-ai-space-factories-hacking-self-driving-cars-detecting-deepfakes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Software Developer Salary in Switzerland [2023]](https://www.wearedevelopers.com/magazine/215-software-developer-salary-in-switzerland-2023)