> Markdown version of [/jobs/ext/2847896-cybersecurity-incident-response-manager](https://www.wearedevelopers.com/jobs/ext/2847896-cybersecurity-incident-response-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Incident Response Manager - **Company:** Fortuna Cysec Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Audit Trail, Microsoft Azure, Software as a Service, Digital Forensics, Identity and Access Management, Python (Programming Language), Log Analysis, Microsoft Office, Windows Servers, Network Segmentation, OAuth, PCI Data Security Standards, Windows PowerShell, Reverse Engineering, Security Information and Event Management, Forensic Toolkit, Scripting, Okta, Mitre Att&ck, Malware, Cyber Threat Analysis, Microsoft InTune, Cybercrime, Microsoft Sentinel, CIS Benchmarks, Encase, Splunk, SentinelOne Expertise - **Published:** September 11, 2026 - **Apply:** https://www.thejobnetwork.com/job/59222d09-4605-4174-b77c-760b50775563/incident-response-manager ## About the Role * 5-10+ years of hands-on experience in incident response, threat hunting, SOC operations, or digital forensics. * Deep technical expertise with EDR platforms (Microsoft Defender, SentinelOne, CrowdStrike, Carbon Black). * Strong SIEM experience with log parsing, correlation, and custom detection creation (Wazuh, Microsoft Sentinel, Elastic, Splunk). * Strong Windows Servers, Office 365 & Azure EntraID / Intune Experience * Hands-on experience with cloud IR in Azure, AWS, and hybrid environments. * Proficiency with forensic tools (Velociraptor, KAPE, FTK, EnCase) and memory analysis frameworks (Volatility). * Strong understanding of identity security (Entra ID, Okta), email security (M365, Proofpoint), and SaaS compromise patterns. * Familiarity with MITRE ATT&CK, NIST 800-61, CIS Controls, ISO 27035. * Ability to communicate complex technical findings to both technical and executive audiences. * Relevant certifications: GCIA, GCFA, GCIH, GNFA, CISSP, or equivalent experience., * Experience in an MDR, MSSP, or IR consulting environment. * Scripting/automation skills in Python or PowerShell. * Experience with malware analysis, cloud forensics, or identity compromise investigations. * Experience supporting regulated industries (HIPAA, FERPA, PCI-DSS, SOX, CJIS) and mission-driven organizations. ## Description The Cybersecurity Incident Response Manager leads and directly participates in high-severity investigations across Fortuna Cysec's customer base. This role blends technical depth, operational leadership, and customer-facing communication. You will serve as the senior escalation point for complex incidents, drive containment and remediation, and strengthen TheFense platform's detection and response capabilities. Requirements: Lead and Execute Incident Response · Command all phases of incident response-triage, investigation, containment, eradication, and recovery-while performing hands-on technical analysis. · Analyze EDR telemetry, SIEM alerts, network logs, cloud audit logs, and identity events across Microsoft, AWS, and hybrid environments. · Execute containment actions including endpoint isolation, identity disablement, MFA resets, OAuth token revocation, and firewall/network segmentation changes. · Conduct forensic acquisition and analysis using Velociraptor, KAPE, FTK, EnCase, and Volatility. · Reverse-engineer or sandbox suspicious binaries/scripts to determine behavior and impact. · Lead hypothesis-driven threat hunts mapped to MITRE ATT&CK using TheFense's unified telemetry. Strengthen IR Operations · Oversee daily IR operations across global SOC/NOC teams, ensuring SLA adherence and seamless follow-the-sun handoffs. · Review and enhance IR playbooks, runbooks, and automated response actions within TheFense. · Ensure high-quality incident documentation, evidence handling, and customer-ready reporting. · Conduct root-cause analysis and deliver technically detailed post-incident reviews. · Partner with engineering to refine detection logic, reduce false positives, and improve automation. Engage Directly with Customers · Serve as the technical authority during active breaches, guiding CISOs, IT directors, and executive stakeholders. · Deliver clear, concise briefings that include attack path analysis, forensic findings, and prioritized remediation steps. · Support customer teams with hands-on remediation across identity, cloud, endpoint, and email ecosystems. · Provide strategic recommendations aligned with NIST, CIS Controls, and Fortuna Cysec best practices. Advance Threat Intelligence and Detection · Translate emerging threat intelligence into new detection rules, response playbooks, and threat-hunting queries. · Validate detection logic through lab testing, simulated attacks, and historical telemetry review. · Identify detection gaps and collaborate with TI teams to enrich investigations with IOCs and adversary behavior patterns. Build Team and Platform Maturity · Mentor analysts across global SOC/NOC teams in IR, forensics, cloud investigations, and threat hunting. · Develop internal tooling and automation using Python or PowerShell. · Participate in tabletop exercises, purple-team engagements, and breach simulations. · Contribute to the evolution of TheFense platform by evaluating new telemetry sources and response capabilities. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)