> Markdown version of [/jobs/ext/2448193-cyber-incident-management-lead](https://www.wearedevelopers.com/jobs/ext/2448193-cyber-incident-management-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Incident Management Lead - **Company:** Gunnison Consulting Group Inc - **Location:** Gunnison, CO, United States - **Experience:** Expert - **Salary:** $160,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Cyber Security, Intrusion Detection and Prevention, Red Team (Cyber Security), Software Vulnerability Management, Malware, Information Technology, Purple Team (Cyber Security), Cyber Warfare - **Published:** August 28, 2026 - **Apply:** https://www.dice.com/job-detail/d582f5f0-90f8-4151-b68b-116281cf3f01 ## About the Role * ship required * Master of Science in Information Technology, Cybersecurity, or a related field OR equivalent experience * 10+ years of experience in security operations and incident response, including leading enterprise-level or cloud-based cyber incidents. * At least 5 years of experience managing incident response teams and overseeing threat detection, forensic analysis, malware analysis, and coordination of major incident activities. Clearance Requirement: Ability to obtain and maintain a Public Trust. Desired Qualifications: * GIAC (such as GCIH, GCFA, IA) certification(s) * CISSP or CISM certification * Cloud security certifications such as Microsoft SC-200 or AZ-500 * EC-Council certifications The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements. ## Description * Lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident Response Team (CSIRT). * Manage incident response operations for cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments. * Review, maintain, and update the Enterprise Incident Response Plan and supporting Standard Operating Procedures (SOPs) to ensure alignment with federal and organizational requirements. * Direct incident response efforts including triage, containment, eradication, recovery, and post-incident remediation activities. * Coordinate with internal stakeholders, third-party vendors, security teams, and leadership during cybersecurity incidents to ensure effective communication and response execution. * Conduct annual incident response exercises, tabletop events, and testing activities to validate operational readiness and improve response capabilities. * Perform incident information gathering, analysis, distribution, and stakeholder notification activities in accordance with established response procedures and reporting timelines. * Develop and publish incident reports, executive summaries, after-action reports, lessons learned, and remediation recommendations following cybersecurity events. * Lead penetration testing, red team, purple team, adversary emulation, and breach-and-attack simulation activities to assess and improve the organization's security posture. * Develop and maintain penetration testing concepts of operations, rules of engagement, test plans, and standard operating procedures. * Coordinate penetration testing activities including onboarding, active assessments, vulnerability validation, findings analysis, remediation tracking, and patch verification. * Integrate incident response and penetration testing activities with vulnerability management, threat modeling, continuous monitoring, event detection, and compliance reporting processes. * Track and report incident response and penetration testing metrics, trends, findings, and remediation activities to cybersecurity leadership and stakeholders. * Support continuous improvement of incident management, threat detection, and cyber defense capabilities through collaboration with security operations, engineering, and compliance teams. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)