CFC Senior Enterprise Security Incident Manager

Experian plc
United States
about 1 month ago
Apply on jobs.smartrecruiters.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$153,075.0 - $275,535.0
Working hours
Regular working hours

Tech stack

Cyber Security Computer Engineering Digital Forensics Information Security Management Mobile Application Software Enterprise Software Applications Cloud Platform System Malware Information Technology Cybercrime Ddos

Job description

As a member of Experian’s Global Security Office (EGSO), the Senior Enterprise Security Incident Manager (ESIM) serves as the Cyber Incident Commander for significant cybersecurity incidents, leading cross-functional response efforts across the enterprise

This hands-on technical role coordinates the full incident response lifecycle, from detection and containment through recovery and post-incident analysis, while providing executive-level communications, driving operational decision-making, and ensuring alignment with Experian’s Global Information Security Incident Response Plan.

You will report to the CFC Senior Director of Incident Response as part of Experian’s Cyber Fusion Center. As an individual contributor, you will partner with technical teams, business leaders, and executives. Your goals will be to minimize business impact, strengthen incident readiness, and improve our cyber resilience.

Must be available to respond to after-hours pages for potentially major security incidents and manage the CFC incident response during assigned nights, weekends, and holidays as part of an on-call rotation.

You’ll have the opportunity to:

  • Lead enterprise-wide response to high-risk cybersecurity incidents as Cyber Incident Commander, validating and escalating incidents, directing cross-functional response efforts, and driving containment, eradication, recovery, and resolution.
  • Provide executive incident leadership by delivering updates to senior leaders and stakeholders, coordinating technical and business teams, supporting decision-making, and maintaining accurate incident documentation.
  • Enhance the incident response program through post-incident reviews, root cause analysis, lessons learned, and continuous improvements to response plans, playbooks, and operational processes.
  • Strengthen cyber readiness by leading tabletop exercises, partnering with business and technology stakeholders to validate response capabilities, identify gaps, and improve preparedness.
  • Support Cyber Fusion Center operations by maintaining awareness of emerging threats, collaborating across security and technology teams, participating in the on-call rotation, and contributing to plans that strengthen Experian’s security posture.

Requirements

  • 8+ years of experience in security operations or information technology, with 5+ years in information security incident handling or response.
  • Bachelor’s degree in Computer Science, Computer Engineering, Information Security, or a related field, or equivalent professional experience.
  • Experience leading/supporting investigations and response to complex cybersecurity incidents, including APTs, ransomware, DDoS, insider threats, web/mobile application attacks, and data exfiltration.
  • Knowledge of cyber incident response, digital investigation methodologies, and adversary tactics, techniques, and procedures (TTPs), including incident triage, impact assessment, containment, remediation, and recovery.
  • Broad technical knowledge of enterprise and cloud environments, including operating systems, networking, security controls, enterprise technologies, and detection and response platforms.
  • Experience investigating complex incidents, performing root cause analysis, making risk-based decisions, and communicating technical findings to all audiences.
  • Leadership experience coordinating cross-functional incident response activities, influencing stakeholders, and managing multiple high-priority cybersecurity incidents.
  • Demonstrated initiative, including the ability to identify improvement opportunities, drive security enhancements, and operate effectively while keeping leadership informed.
  • Plus: Industry certifications in cybersecurity, incident response, digital forensics, or ethical hacking preferred (e.g., GIAC, CISSP, SSCP, CISM, EC-Council, Offensive Security).

Benefits & conditions

  • Great compensation package and bonus plan.
  • Core benefits including medical, dental, vision, and matching 401K.
  • Flexible work environment, ability to work remote, hybrid or in-office.
  • Flexible time off including volunteer time off, vacation, sick and 12-paid holidays.
  • Explore all our exciting benefits here: https://myexperianbenefits.com/.

About the company

Experian is a global data and technology company, powering opportunities for people and businesses around the world. We operate across a range of markets, from financial services to healthcare, automotive, agribusiness, insurance, and many more. Experian invests in people and new advanced technologies to unlock the power of data. We have an amazing team of 25,200 people in 32 countries., Our uniqueness is that we celebrate yours. Experian’s people first, inclusive and purpose driven culture is multi award-winning; World’s Best Workplaces 2025 (Fortune Global Top 25), Great Place To Work in 26 countries to name a few. Check out Experian Life on social or explore our Careers Site to understand why.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.smartrecruiters.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

57 sec

Responding effectively to exploits after security patch releases

Vandana Verma · LIVE

3:11 min

Surviving sudden scale events and malicious traffic

Justin Kitagawa · Coffee With Developers

Videos

See all

Related articles

See all