> Markdown version of [/jobs/ext/627026-senior-cyber-defense-manager-incident-response](https://www.wearedevelopers.com/jobs/ext/627026-senior-cyber-defense-manager-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Defense Manager - Incident Response - **Company:** Boyd Gaming - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Data Migration, Digital Forensics, Intrusion Detection and Prevention, Security Information and Event Management, Software Vulnerability Management, Mitre Att&ck, Mttr, Cyber Threat Analysis, Information Technology, Cybercrime, Performance Monitor, Splunk, Blue Team (Cyber Security) - **Published:** June 24, 2026 - **Apply:** https://www.dice.com/job-detail/66822a39-eb64-440c-a20a-13118d0d2997 ## About the Role Required: * 10+ years of progressive experience in cybersecurity, with at least 5+ years in incident response, digital forensics, or security operations leadership roles. * Proven experience leading cyber incident response teams and managing complex, high-impact incidents. * Demonstrated success in vendor/MSSP transitions or outsourcing handovers in a cybersecurity context. * Strong understanding of detection technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms) and experience improving detection efficacy. * Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field (Master's preferred). * Relevant certifications such as CISSP, CISM, GIAC GCFAIHTI, or similar. Preferred: * Experience in a regulated industry (e.g., finance, healthcare, critical infrastructure). * Hands-on technical experience with tools such as Splunk, Elastic, CrowdStrike, Microsoft Defender, Sentinel, or similar. * Prior experience building or maturing an internal SOC/IR function while reducing MSSP dependency. Skills & Competencies * Exceptional leadership, communication, and stakeholder management skills - able to translate technical details for non-technical audiences. * Strong project/program management abilities, especially in high-stakes transitions. Analytical mindset with experience in root cause analysis and threat hunting. * Ability to thrive in a fast-paced, high-pressure environment with on-call responsibilities. * Strategic thinker focused on long-term program maturity and risk reduction. ## Description Lead the Cyber Incident Response Program * Oversee the full incident response lifecycle: preparation, identification, containment, eradication, recovery, and post-incident lessons learned (per NIST SP 800-61 or similar frameworks). * Manage day-to-day incident response operations, including triage, investigation coordination, forensic analysis, and executive-level reporting. * Develop, maintain, and regularly test incident response playbooks, runbooks, and escalation procedures. Enhance Detection Capabilities * Drive continuous improvement of threat detection engineering, including tuning of SIEM rules, EDR/XDR configurations, threat intelligence integration, and behavioral analytics. * Collaborate with SOC, threat hunting, and security engineering teams to reduce false positives, accelerate mean time to detect (MTTD) and respond (MTTR), and implement proactive detection use cases. * Lead initiatives to mature internal blue-team capabilities across endpoints, cloud, identity, network, and email environments. Manage MSSP Services Transition * Lead the end-to-end transition of MSSP services from the current provider to the new partner, including planning, knowledge transfer, contract/SLA alignment, and cutover execution. * Conduct due diligence on the new MSSP, define transition success criteria, and mitigate risks during handover (e.g., service continuity, data migration, access controls). * Establish governance for the new MSSP relationship, including performance monitoring, regular service reviews, incident handoff protocols, and continuous improvement feedback loops. * Ensure the transition strengthens rather than disrupts detection and response effectiveness. Team Leadership & Development * Build, mentor, and lead a high-performing incident response team (internal analysts, responders, and cross-functional partners). * Provide performance management, career development, and technical coaching to team members. * Foster a culture of continuous learning, tabletop exercises, red/blue team simulations, and post-incident reviews. * Stakeholder Collaboration & Reporting * Serve as the primary point of contact for major incidents, briefing executive leadership, legal, compliance, and external regulators as needed. * Coordinate with IT, legal, risk, business units, and external partners (e.g., law enforcement, forensics firms) during incidents. * Produce executive-level reports on incident trends, program maturity, detection improvements, and transition status. Program Maturity & Compliance * Align incident response practices with industry standards (NIST, ISO 27001, MITRE ATT&CK, etc.) and regulatory requirements. * Drive metrics-driven improvements and maturity assessments for the IR program. * Contribute to enterprise-wide security initiatives, including vulnerability management, threat intelligence, and security awareness. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)