> Markdown version of [/jobs/ext/2945235-security-incident-coordinator-hybrid](https://www.wearedevelopers.com/jobs/ext/2945235-security-incident-coordinator-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Incident Coordinator - hybrid - **Company:** Catapult Solutions Group - **Location:** Charlotte, NC, United States - **Experience:** Experienced - **Salary:** $95,410.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Digital Forensics, Information Technology, Servicenow - **Published:** September 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=520435c879af3569 ## About the Role Our client is seeking a detail-oriented and organized Security Incident Coordinator to join the Security Operations Center (SOC) within Threat Operations., * Minimum 3 years of experience in incident coordination, security operations, or a closely related field. * Demonstrated ability to manage multiple concurrent incidents, tasks, and stakeholders in a high-pressure environment while maintaining accuracy and composure. * Working knowledge of incident response procedures across: * Cybersecurity * Trust & Safety * Fraud * Excellent organizational skills. * Strong written and verbal communication skills. * Ability to translate technical information for non-technical audiences and communicate business requirements to technical teams. * Ability to work effectively across Insider Risk, Escalations, and DFIR functions without directly owning those technical domains. Preferred Qualifications * Experience with ServiceNow Security Incident Response (SIR) or a comparable ITSM/SIR platform. * Relevant professional certifications, including: * PMP * ITIL * CISM * GCIH Education * Bachelor's degree in Information Security, Computer Science, Management Information Systems, or a related field, or equivalent experience. ## Description * Serve as the primary coordinator for major cybersecurity, Trust & Safety, and fraud incidents. * Organize incident-related tasks, track progress, and maintain clear communication across involved teams and stakeholders using ServiceNow Security Incident Response (SIR). * Coordinate the full incident lifecycle, including: * Containment * Eradication * Recovery * Closure * Ensure containment is validated against our clients control-testing standards before an incident is marked resolved. * Develop, maintain, and enforce incident response playbooks and protocols. * Partner with SOC capability champions across: * Insider Risk * Escalations * Digital Forensics & Incident Response (DFIR) * Ensure consistency across incident response processes without duplicating existing technical ownership. * Produce regular incident reporting, ranging from operational status updates to Board and Senior Leadership Team (SLT) summaries. * Clearly document actions taken, incident outcomes, and recommendations for improvement. * Lead the lessons-learned process by facilitating post-incident hot washes. * Convert post-incident findings into documented action items. * Drive updates to reports and playbooks on a regular cadence. * Provide clear and comprehensive documentation and updates to internal partners, including: * IT * Legal * Compliance * Customer Support * Support onboarding and training for team members on incident response protocols and tooling. * Reinforce adherence to established SOC processes. * Stay current on incident response, fraud, and Trust & Safety best practices. * Help adapt SOC processes as threats and business requirements evolve. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [AI Space Factories, Hacking Self-Driving Cars & Detecting Deepfakes](https://www.wearedevelopers.com/videos/1812-ai-space-factories-hacking-self-driving-cars-detecting-deepfakes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023)