> Markdown version of [/jobs/ext/1894196-incident-response-manager](https://www.wearedevelopers.com/jobs/ext/1894196-incident-response-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Manager - **Company:** TTEC - **Location:** Atlanta, GA, United States (Remote available) - **Experience:** Experienced - **Salary:** $120,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, Cyber Security, Data Security, Open Source Technology, PCI Data Security Standards, Windows PowerShell, Penetration Tools, Phishing, Security Information and Event Management, Privacy Controls, Scripting, Malware, Information Technology, Api Design - **Published:** August 1, 2026 - **Apply:** https://www.careerjet.com/job/us5c47bc1c544c40a7d470090657bbfeb9/eaa ## About the Role * 5+ years in CyberSecurity including experience with security tools including EDR, SIEM, etc. * 3+ years of leadership experience * Strong understanding of advanced threat analysis methodologies like MITRE ATT&CK® * Review runbooks to assist SOC Analysts and other team members with appropriate reactions and activities based on finding types * Capable of self-direction in situations involving complex attack methods that require in-depth analysis and response * Ensure solid communication with key stakeholders, including progress on issues or findings and setting relevant expectations * Familiarity with security assessments and audits covering Protected Health Information (PHI), Personally Identifiable Information (PII), and Payment Card Industry Data Security Standard (PCI DSS) * Experience in preparing security documentation, evaluating and documenting security and privacy controls, and completing non-technical analysis activities Nice To Have * Some experience with common penetration tools/frameworks (Open Source or Commercial) * Powershell and/or Python scripting experience and building API-based integrations ## Description Your potential has a place here with TTEC's award-winning employment experience. As an Incident Response Manager working remote in the United States, you'll be a part of bringing humanity to business. #experienceTTEC Our employees have spoken. Our purpose, team, and company culture are amazing and our Great Place to Work® certification in the United States says it all! What You'll be Doing: As part of our Information Security team, you will manage the team that is responsible detecting, containing, and remediating cybersecurity threats. This role balances the technical understanding of attack methods and response with the leadership skills to manage the experienced security analysts. During a Typical Day You'll: ·Lead Incident Lifecycle efforts, serving as the responder for security incidents escalated by the 24x7 SOC, including coordination of containment, eradication, and recovery activities across technical teams. ·Manage and mentor a high-performing Incident Response and Security Analyst team, providing hands-on technical guidance, coaching, and professional development to strengthen detection and response capabilities. ·Develop, maintain, and continuously improve the Incident Response Plan (IRP) and detailed playbooks for a range of threat scenarios, including ransomware, phishing, insider threat, and third-party incidents, ensuring alignment with evolving attack methods and regulatory requirements. ·Design and facilitate tabletop and simulation exercises to test incident readiness, validate executive and technical response procedures, and identify gaps prior to real-world events. ·Translate complex technical findings into clear, actionable communications for Legal, HR, executive leadership, and business stakeholders during and after security incidents. ·Conduct Post-Incident Reviews (Post-Mortems) to assess root cause, response effectiveness, and control gaps, driving continuous improvement of security posture, policies, and processes. ·Prepare, validate, and maintain security and compliance documentation ·Advise internal and client teams on remediation of security and privacy weaknesses, balancing risk, compliance, and operational impact. ·Prepare and deliver security and privacy awareness training tailored to technical teams, business users, and leadership audiences., Overview: Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully comm… + 1 day ago + ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)