> Markdown version of [/jobs/ext/3394589-cyber-security-incident-response-lead](https://www.wearedevelopers.com/jobs/ext/3394589-cyber-security-incident-response-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Incident Response Lead - **Company:** Staples, Inc. - **Location:** Framingham, MA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Data Loss, Digital Forensics, Identity and Access Management, Intrusion Detection and Prevention, PCI Data Security Standards, Azure Active Directory, Security Information and Event Management, Cyber Threat Analysis, Azure Security Center, Information Technology, Cybercrime, Microsoft Sentinel, Cyber Warfare, Security Orchestration, Automation & Response - **Published:** September 13, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3388775434&tx=VT6964THV&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Advanced technical investigation, analytical, and problem-solving skills. * Sound technical judgment and the ability to make recommendations using incomplete or evolving information. * Ability to support complex cybersecurity incidents calmly and effectively under pressure. * Strong written and verbal communication skills, including the ability to translate technical findings into clear business risk considerations and recommended actions. * Strong collaboration skills across technical and non-technical teams. * Curiosity and initiative to identify improvements within the incident response discipline. * Strong understanding of evolving attacker behaviors, techniques, and technologies. * Discretion and sound judgment when handling sensitive investigations, including potential insider risk matters. * Ability to participate in an on-call escalation rotation for significant cybersecurity incidents. What's needed- Basic Qualifications: * Bachelor's degree in Computer Science, Information Security, a related field or equivalent work experience. * 7+ years of cybersecurity experience, including incident response, digital forensics, threat hunting, detection engineering, or Security Operations. * Experience conducting complex cybersecurity investigations in large enterprise environments. * Experience developing or maintaining incident response plans, procedures, playbooks, exercises, metrics, or supporting processes. * Experience conducting post-incident reviews, root cause analysis, or lessons-learned documentation. * Experience coordinating technical response activities across multiple technology and business teams., * Experience within larger distributed enterprise environments, ideally retail and/or e-commerce. * Advanced technical training or relevant cybersecurity certifications such as GCIH, GCFA, GCFE, GNFA, CISSP. * Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Endpoint, or Microsoft Entra ID. * Experience with SOAR platforms and automated incident response workflows. * Hands-on experience investigating endpoint, identity, cloud, network, email, or log-based security telemetry. * Hands-on experience using SIEM, EDR/XDR, identity security, cloud security monitoring, or security automation technologies. * Experience conducting enterprise threat hunting or developing detection content. * Experience supporting insider risk, user behavior, data loss, or other user-focused security investigations. * Experience investigating identity-based or cloud-based attacks. * Experience responding to ransomware, credential compromise, business email compromise, insider threats, data theft, or supply-chain incidents. * Knowledge of cybersecurity incident response requirements, including PCI DSS and applicable privacy requirements., * Advanced technical training or relevant cybersecurity certifications such as GCIH, GCFA, GCFE, GNFA, CISSP. * Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Endpoint, or Microsoft Entra ID. * Experience with SOAR platforms and automated incident response workflows. * Experience conducting enterprise threat hunting or developing detection content. * Experience supporting insider risk, user behavior, data loss, or other user-focused security investigations. * Experience investigating identity-based or cloud-based attacks. * Experience responding to ransomware, credential compromise, business email compromise, insider threats, data theft, or supply-chain incidents. * Knowledge of cybersecurity incident response requirements, including PCI DSS and applicable privacy requirements. * Experience within large retail, e-commerce, or distributed enterprise environments. ## Description As a Cyber Security Incident Response Lead, you'll serve as a senior technical escalation resource for significant cybersecurity incidents across Staples. You'll lead hands-on investigation and response activities across endpoint, identity, cloud, network, email, and security telemetry to determine threat scope, business impact, root cause, and recommended response actions. You'll also help mature the incident response program by improving playbooks, exercises, metrics, processes, threat-hunting practices, detection recommendations, and automation opportunities. Role requires the incumbent to work at our Framingham, MA facility but we are open to candidates that are willing to relocate to the area. We will also consider providing relocation assistance. What you'll be doing: * Conduct complex cybersecurity investigations from initial escalation through containment, eradication, recovery, and post-incident review. * Analyze endpoint, identity, cloud, network, email, and log-based telemetry to identify attacker activity, determine incident scope, and assess potential impact. * Provide senior technical guidance during significant incidents in partnership with SOC Leads and Managers. * Coordinate response activities across Cyber Security, Infrastructure, Cloud, Identity, Legal, Privacy, GRC, Human Resources, external partners, and other business and technology teams. * Develop and continuously improve incident response plans, investigative procedures, escalation processes, playbooks, exercises, metrics, and supporting documentation. * Conduct proactive threat hunting based on threat intelligence, vulnerabilities, anomalous activity, and observed adversary techniques. * Support insider risk investigations involving suspicious user behavior, misuse of access, data loss, or potentially malicious internal activity. * Document investigation findings, lessons learned, recurring risks, and improvement opportunities from post-incident reviews. * Partner with Detection Engineering, Threat Intelligence, and security technology teams to improve detection coverage, investigative capabilities, and automation. * Participate in an on-call escalation rotation for significant cybersecurity incidents requiring senior technical expertise. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [How to Avoid LLM Pitfalls - Mete Atamel and Guillaume Laforge](https://www.wearedevelopers.com/videos/1328-how-to-avoid-llm-pitfalls-mete-atamel-and-guillaume-laforge) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [From Shadow AI to Secure Intelligence: Safe AI Usage in the Enterprise](https://www.wearedevelopers.com/videos/2093-from-shadow-ai-to-secure-intelligence-safe-ai-usage-in-the-enterprise) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)