Director, Cyber Incident Response

The Direct
United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cyber Security Digital Forensics Executive Information Systems Forensics Tools (Digital Forensics Software) Identity and Access Management Intrusion Detection and Prevention PCI Data Security Standards
+8 more
Azure Active Directory Security Information and Event Management Cloud Platform System Mitre Att&ck Mttr Cyber Threat Analysis Information Technology Cybercrime

Job description

The Director of Incident Response is responsible for leading the organization’s cyber incident response program, ensuring the timely detection, containment, eradication, and recovery from cybersecurity incidents. This role develops and executes the enterprise Incident Response strategy, manages a high-performing Security Operations and Incident Response team, and partners closely with IT, Legal, Privacy, Compliance, Communications, Risk, and executive leadership to minimize business impact from cyber threats.

The Director will drive operational excellence across incident response, digital forensics, threat intelligence integration, cyber crisis management, and continuous improvement while ensuring compliance with regulatory and contractual obligations., Incident Response Leadership

  • Lead and manage the enterprise Cyber Incident Response (IR) program.
  • Direct response activities for high-severity security incidents, including ransomware, business email compromise, insider threats, cloud attacks, third-party compromises, and data breaches.
  • Serve as Incident Commander during major cyber incidents.
  • Coordinate cross-functional response efforts across IT Infrastructure, Cloud, Identity, Legal, HR, Privacy, Communications, and executive leadership.
  • Ensure rapid containment, eradication, recovery, and lessons learned activities.

Security Operations

  • Oversee operational effectiveness of: *

  • Security Monitoring
  • SIEM
  • EDR/XDR
  • SOAR
  • Threat Detection
  • Threat Hunting
  • Establish incident severity models, response playbooks, escalation procedures, and SLAs.
  • Drive improvements in detection engineering and automation.

Digital Forensics

  • Lead forensic investigations involving endpoints, cloud environments, SaaS platforms, identity systems, and email.
  • Ensure proper evidence preservation and chain of custody.
  • Coordinate with outside forensic firms when necessary.

Cyber Crisis Management

  • Develop and maintain Cyber Crisis Management plans.
  • Conduct tabletop exercises with executive leadership.
  • Coordinate crisis communications during major incidents.
  • Provide executive briefings and Board-level updates during cyber events.

Threat Intelligence & Hunting

  • Integrate threat intelligence into detection and response operations.
  • Oversee proactive threat hunting across enterprise environments.
  • Identify emerging threats targeting the organization and industry.

Program Development

  • Develop and mature the Incident Response program aligned with: *

  • NIST CSF
  • NIST SP 800-61
  • MITRE ATT&CK
  • ISO 27035
  • Maintain incident response policies, standards, procedures, and playbooks.
  • Measure program maturity and drive continuous improvement initiatives.

Compliance & Reporting

  • Ensure incident response activities support: *

  • PCI DSS
  • HIPAA (where applicable)
  • GDPR
  • CCPA
  • Produce executive dashboards and metrics including: *

  • Mean Time to Detect (MTTD)
  • Mean Time to Respond (MTTR)
  • Incident trends
  • Root cause analysis
  • Detection coverage
  • Lessons learned

Leadership

  • Build, mentor, and develop global Incident Response and Security Operations personnel.
  • Foster a culture of continuous learning and operational excellence.
  • Participate in hiring, budgeting, workforce planning, and performance management., * Reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
  • Mature the Incident Response program to align with NIST and industry best practices.
  • Develop comprehensive incident response playbooks for critical attack scenarios.
  • Conduct regular executive and technical tabletop exercises.
  • Improve security monitoring coverage across cloud, identity, endpoints, and SaaS applications.
  • Enhance automation and orchestration to reduce manual response efforts.
  • Build executive reporting with meaningful security metrics and risk insights.
  • Strengthen partnerships with IT, Infrastructure, Legal, HR, Privacy, and business stakeholders.
  • Lead continuous improvement initiatives based on lessons learned from incidents.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related discipline.
  • 15+ years of cybersecurity experience.
  • 5+ years leading Security Operations or Incident Response teams.
  • Experience leading enterprise-scale cyber incident response.
  • Experience working with executive leadership during cyber crises.
  • Deep knowledge of cloud security (Microsoft 365, Azure).
  • Experience managing enterprise SIEM and EDR platforms.
  • Strong understanding of Identity and Access Management.
  • Experience with threat intelligence and threat hunting.

Preferred Certifications

  • CISSP
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Certified Enterprise Defender (GCED)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Manager (CISM)

Technical Skills

Experience with one or more of the following technologies:

  • CrowdStrike Falcon
  • Microsoft Entra ID
  • SOAR platforms
  • Threat Intelligence Platforms (TIP)
  • Digital Forensics tools
  • Network Detection & Response (NDR)
  • Email security platforms
  • Cloud-native security tools

Leadership Competencies

  • Executive presence
  • Strategic thinking
  • Decision-making under pressure
  • Crisis leadership
  • Strong communication and presentation skills
  • Cross-functional collaboration
  • Coaching and mentoring
  • Budget and vendor management
  • Continuous improvement mindset, The ideal Director of Incident Response combines deep technical expertise with proven leadership in cyber crisis management. They are comfortable leading high-pressure incident response efforts, communicating effectively with executives, and building scalable, mature security operations. They possess a strong understanding of modern attack techniques, cloud environments, identity security, digital forensics, and threat intelligence, while fostering a culture of collaboration, resilience, and continuous improvement across the security organization.

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • Retirement plan
  • Vision insurance
  • Dental insurance

About the company

Direct Travel is one of the fastest growing Travel Management Companies (TMC) in the world. Leveraging the expertise of its people and innovative technology solutions, Direct Travel enables clients to derive the greatest value from their travel program through superior service, progressive technologies, and significant cost savings. Direct Travel has offices globally and is currently ranked among the top providers on Travel Weekly’s Power List. For more information, visit www.dt.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · World Congress 2021

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

Videos

See all

Related articles

See all