> Markdown version of [/jobs/ext/731683-incident-response-manager](https://www.wearedevelopers.com/jobs/ext/731683-incident-response-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Manager - **Company:** Crowe LLP - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $110,800.0 - $226,400.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing, Linux, Digital Forensics, Python (Programming Language), Windows PowerShell, Azure Active Directory, Security Information and Event Management, Google Cloud, Mitre Att&ck, Azure Security Center, Falcon Platform, Cybercrime, Microsoft Sentinel, Cyber Warfare, Splunk, SentinelOne Expertise - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=01bbbe692eb8bd01 ## About the Role Do you have experience in Technical report writing?, * 7+ years of cybersecurity experience with at least 3 years focused on incident response, digital forensics, threat hunting, or cyber defense operations. * Demonstrated experience leading complex incident response engagements from initial detection through recovery. * Experience managing project teams, mentoring technical staff, and coordinating cross-functional stakeholders. * Strong leadership, decision-making, and risk management capabilities. * Excellent communication skills with the ability to present technical findings to executive and non-technical audiences. * Ability to manage competing priorities and multiple concurrent engagements. * Strong understanding of networking, operating systems, identity systems, cloud technologies, and cybersecurity principles. * Experience utilizing SIEM platforms such as Splunk, Elastic, Microsoft Sentinel, or FortiSIEM. * Experience utilizing EDR platforms such as CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, or Carbon Black. * Proficiency with scripting and automation using PowerShell, Python, Bash, or similar technologies. * Strong documentation and report-writing capabilities. * Willingness to travel approximately 15% or more as required., * Expert knowledge of Windows, Linux, Active Directory, Microsoft Entra ID, Microsoft 365, AWS, Azure, and Google Cloud environments. * Advanced understanding of attacker tactics, techniques, and procedures (MITRE ATT&CK). * Experience leading enterprise-scale ransomware investigations and recovery efforts. * Experience coordinating legal counsel, cyber insurance carriers, law enforcement, and third-party stakeholders during incidents. * Experience developing incident response programs, tabletop exercises, and cyber resilience strategies. * Experience managing consulting engagements and project financials. * Experience building and managing cybersecurity teams. * Relevant certifications such as GCFA, GCIH, GCED, GREM, GCTD, CISSP, CCSP, CISM, AWS Security Specialty, or Azure Security Engineer Associate. We expect the candidate to uphold Crowe's values of Care, Trust, Courage, and Stewardship. These values define who we are. We expect all of our people to act ethically and with integrity at all times., We are committed to a merit-based hiring process, evaluating all candidates consistently using objective, job-related criteria such as relevant experience, demonstrated skills, measurable impact, and alignment with the role's responsibilities, and making employment decisions in a fair and inclusive manner free from discrimination. ## Description The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders, overseeing engagement delivery, and acting as a trusted advisor to clients during cybersecurity crises. This role combines deep technical expertise with leadership, business development, client relationship management, and operational oversight responsibilities., * Serve as the primary client-facing leader during major cybersecurity incidents. * Lead multiple concurrent incident response engagements involving ransomware, data breaches, insider threats, cloud compromises, and advanced threat actor activity. * Provide executive-level briefings to CISOs, CIOs, legal counsel, executive leadership, boards of directors, and other stakeholders. * Direct forensic investigations, threat hunting activities, containment efforts, eradication plans, and recovery operations. * Review and approve technical findings, investigation reports, executive summaries, and client deliverables. * Coordinate internal and external resources to ensure successful engagement execution and client outcomes. * Ensure investigations meet legal, regulatory, and evidentiary requirements. * Develop and maintain incident response methodologies, playbooks, procedures, and service offerings. * Lead and mentor Incident Response consultants and senior staff through coaching, technical guidance, and performance feedback. * Assist with recruiting, onboarding, and professional development of team members. * Support business development efforts through proposal development, scoping, client presentations, and strategic discussions. * Identify opportunities to expand client relationships and deliver additional cybersecurity services. * Contribute to thought leadership through whitepapers, webinars, conference presentations, and market-facing content., Crowe LLP does not accept unsolicited candidates, referrals or resumes from any staffing agency, recruiting service, sourcing entity or any other third-party paid service at any time. Any referrals, resumes or candidates submitted to Crowe, or any employee or owner of Crowe without a pre-existing agreement signed by both parties covering the submission will be considered the property of Crowe, and free of charge. Crowe will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws. Please visit our webpage to see notices of the various state and local Ban-the-Box laws and Fair Chance Ordinances, where applicable. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)