Incident Response Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+12 more
Job description
Under the direction of the Chief Information Security Officer, the Incident Response Manager & Security Operations Team Lead is responsible for leading the University’s Security Operations and Incident Response functions in support of the University of Connecticut Information Security Office.
The Incident Response Manager works regularly with other senior members of the Information Security Office and is a member of the CISO’s security leadership team.
This position serves in a dual capacity as both a technical subject matter expert and the supervisor of a functional team. The incumbent provides strategic and operational leadership for the University’s cybersecurity monitoring, detection, investigation, response, and recovery capabilities while actively participating in complex incident response activities and advanced security operations.
The Incident Response Manager leads a team of cybersecurity professionals responsible for continuous security monitoring, incident response, threat detection, digital forensics, and operational security engineering. The position establishes operational priorities, develops procedures and playbooks, manages security technologies, and coordinates enterprise response activities across the University’s academic, research, and administrative environments.
The manager works collaboratively with University leadership, Information Technology Services, legal counsel, privacy, compliance, research, public safety, and external partners to ensure timely, effective, and coordinated response to cybersecurity incidents.
The Incident Response Manager is responsible for continuously improving the University’s incident response maturity and operational security capabilities through process improvement, technology implementation, threat-informed defense, automation, metrics, and staff development.
SALARYIncident Response Manager and Security Operations Team Lead (IT Team Lead 2 \u2013 M7): $95,066 to $123,585Note: All minimum qualifications must be met to be eligible for consideration. Salary will be commensurate with experience within the established range.
BENEFITS INCLUDEDefined contribution with employer match or defined benefit program retirement optionsExcellent and affordable healthcare options35 hour work week22 paid vacation days per year, paid sick leave, and 13 paid holidaysEmployee and dependent tuition waiversA highly desirable work environment and work-life balanceDUTIES AND RESPONSIBILITIESLead the University’s Security Operations and Incident Response programs.Direct day-to-day operations of the Security Operations team, including prioritization of work, workload management, coaching, mentoring, and performance management.Serve as the incident commander for significant cybersecurity incidents, coordinating technical response activities across multiple University departments. Operates as a primary member of the UConn Incident Response Plan, acting as functional lead for Executive Response Team (ERT) meetings and activities.Personally participate in complex incident investigations, threat hunting, malware analysis, digital forensics, containment, eradication, recovery, and post-incident reviews.Develop, maintain, and continuously improve incident response plans, operational procedures, playbooks, and technical standards.Manage the identification, detection, and response to alerts and events through the University’s security monitoring capabilities including SIEM, SOAR, EDR/XDR, threat intelligence, logging, and related security technologies.Lead continuous improvement of detection engineering, alert tuning, automation, and operational metrics.Coordinate security operations with infrastructure, networking, cloud, identity management, application, and research computing teams.Oversee threat detection engineering, use case development, and security content management.Manage relationships with incident response vendors, managed security providers, law enforcement, and external cybersecurity organizations.Coordinate regulatory reporting and support investigations involving compliance, legal, privacy, and research security requirements.Develop operational dashboards, metrics, executive reporting, and key performance indicators for security operations and incident response.Lead tabletop exercises, incident simulations, and operational readiness activities.Participate in security architecture reviews to improve monitoring and incident response capabilities.Develop staffing plans, training plans, career development activities, and succession planning for Security Operations personnel.Manage operational projects related to security monitoring, automation, response technologies, and operational maturity.Maintain awareness of emerging threats, adversary tactics, vulnerabilities, and industry best practices.Participate in after-hours incident response and operational escalations as required.Other related duties as assigned.RELATED SKILLS AND COMPETENCIESLeadership - Demonstrates the ability to lead, motivate, coach, and develop highly skilled technical professionals. Creates a collaborative, service-oriented culture focused on operational excellence and continuous improvement.Incident Leadership - Provides calm, decisive leadership during complex cybersecurity incidents. Coordinates technical, operational, and executive stakeholders while maintaining effective communication and prioritization.Technical Expertise - Demonstrates expert knowledge across security operations, incident response, threat detection, digital forensics, security monitoring, cloud security, endpoint security, identity security, and enterprise security architecture.Strategic Thinking - Develops operational roadmaps, establishes priorities, evaluates emerging technologies, and aligns security operations with institutional objectives and risk management strategies.Communication - Communicates effectively with technical staff, executive leadership, legal counsel, auditors, and external partners. Produces clear technical documentation and executive-level reporting.Project Management - Plans and manages multiple concurrent operational initiatives while balancing daily security operations and incident response responsibilities.Physical Demands - This position involves extended periods of sitting and extensive use of computers and office equipment.MINIMUM QUALIFICATIONS
Requirements
Must meet and maintain eligibility requirements to work with CUI/CTI data, as determined by the Facility Security Officer and the Office of Export Control.Bachelor’s degree and six (6) years of related experience in information security or information technology; OR Associate’s degree and eight (8) years of related experience; OR ten (10) years of related experience.Three (3) or more years of progressively responsible experience in Security Operations and Incident Response.One (1) or more years of experience leading or supervising a technical cybersecurity team or serving as a technical team lead.Demonstrated experience leading enterprise cybersecurity incident response activities, including management of executive communication, incident management, remediation, restoration, and drafting of reports.Experience identifying, triaging, mitigating and remediating security events and alerts with enterprise SIEM, EDR/XDR, SOAR, threat intelligence, logging, and security monitoring platforms.Experience conducting digital forensic investigations, malware analysis, threat hunting, or advanced incident investigations.Experience developing incident response plans, playbooks, operational procedures, and security standards.Experience managing security technologies to perform security operations and incident response including Microsoft Sentinel, Splunk Enterprise Security, Microsoft Defender, CrowdStrike, Palo Alto Cortex, or comparable enterprise security platforms.Experience with cloud security technologies supporting Microsoft Azure, AWS, Microsoft 365, or Google Cloud.Experience applying NIST Cybersecurity Framework, NIST SP 800-61, MITRE ATT&CK, CIS Controls, or similar cybersecurity frameworks.Demonstrated leadership, analytical, communication, organizational, and project management skills.PREFERRED QUALIFICATIONS
Master’s degree in Cybersecurity, Computer Science, Information Assurance, or related field.Experience managing Security Operations Center (SOC) teams.Experience in higher education or research computing environments.Experience with Splunk and Microsoft Defender XDR.Experience with Splunk SOAR or similar SOAR platforms and security automation.Experience with cloud-native security monitoring.Experience supporting regulated environments including FERPA, HIPAA, PCI DSS, CJIS, CMMC, NIST 800-171, or similar requirements.Experience conducting threat hunting and detection engineering.Experience developing executive metrics and operational dashboards.Experience managing vendor relationships and cybersecurity procurements.Experience coordinating cybersecurity exercises and tabletop events.CISSP, GCIH, GCFA, GCIA, GCFE, GNFA, GCED, CASP+, CISM, or comparable advanced cybersecurity certification.APPOINTMENT TERMS, Employment of the successful candidate is contingent upon the successful completion of a pre-employment criminal background check. The successful candidate must be determined to be and remain eligible to work with CUI/CTI data as determined by the Facility Security Officer and the Office of Export Control
Benefits & conditions
This is a full-time, permanent position. The University offers a competitive salary, and outstanding benefits, including employee and dependent tuition waivers at UConn, and a highly desirable work environment.
Other rights, terms, and conditions of employment are contained in the collective bargaining agreement between the University of Connecticut and the University of Connecticut Professional Employees Association (UCPEA).
This position is on-site. THIS IS NOT A REMOTE POSITION. The position may be eligible for a hybrid work schedule under applicable bargaining agreements, management approval, and not less than an annual review. This position may require you to travel in-state and you may be required to work irregular hours to support operational or security activities and initiatives.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Best Paying Jobs in Technology