Help us elevate and internalize a world-class incident response program. As Senior Manager, Incident Response, you'll design, implement, and continuously improve our IR capabilities--owning use case creation and deployment in Microsoft Sentinel, advising senior leaders during investigations, and leading our shift from third-party services to a resilient follow-the-sun model powered by internal talent. If you thrive at the intersection of hands-on engineering, program leadership, and mentorship, we'd love to hear from you.Please note: CFA Institute does not provide work authorization or visa sponsorship for this position (including student or temporary worker visas).
What You'll DoLead the enterprise Incident Response (IR) program--set strategy, roadmap, and standards aligned to business goals and industry best practices.
Drive the transition from a third-party SIEM/incident service to an internal, follow-the-sun IR operating model.
Own IR process excellence--mature workflows, playbooks, runbooks, and documentation; run regular QA reviews and exercises to identify and close gaps.
Create actionable, threat-informed use cases and detections; collaborate across teams to translate risk and regulatory needs into robust engineering solutions.
Implement, validate, and optimize use cases in our SIEM (Microsoft Sentinel) to ensure accurate real-time detection, triage, analysis, and reporting.
Serve as senior incident advisor and escalation point ("senior 3") for containment, eradication, and recovery; mentor and coach responders at all levels.
Plan and run tabletop exercises, purple-team style drills, and ongoing responder training in partnership with IT, architecture, and business stakeholders.
Define and report KPIs/KRIs for IR readiness and performance; deliver clear, executive-level insights and recommendations.
Integrate threat intelligence to proactively detect, mitigate, and learn from emerging risks.
What You'll Bring
Minimum QualificationsBachelor's degree in Computer Science, Information Security, or related field (or equivalent practical experience).
7+ years in incident response, security operations, or closely related domain, including 2+ years in a senior/lead or advisory capacity.
Deep expertise in SIEM engineering: configuration, tuning, and detection/use-case development (Microsoft Sentinel, Splunk, QRadar, ArcSight, or similar).
Strong knowledge of network protocols; Windows, Linux, and macOS; cloud environments; and endpoint security technologies.
Demonstrated success leading complex technical investigations and coordinating multidisciplinary teams under pressure.
Exceptional written and verbal communication skills; ability to translate complex technical issues for executive and non-technical audiences.
Track record of mentorship, training, and measurable process improvement.
Highly organized with an analytical, risk-based approach to problem solving.
Preferred QualificationsAdvanced degree and/or relevant certifications such as CISSP, GCIH, GCFA, or comparable SANS/GIAC credentials.
Hands-on experience operating a global or follow-the-sun IR model and conducting purple-team exercises.
Familiarity with threat intelligence platforms and automations, SOAR tooling, and metrics frameworks for cyber risk.
Why Join Us?Shape a modern, globally responsive IR capability at mission-driven scale.
Collaborate across security architecture, IT, and the business to drive meaningful risk reduction.
Enjoy flexible work arrangements within the US and the support of a leadership team that values authenticity, courage, accountability, agility, and a growth mindset.
Grow as a talent magnet--mentor others, build high-functioning teams, and leave a lasting impact on our security culture.
At CFA Institute, we are committed to transparency and equity in our hiring process. In compliance with wage transparency laws in many of the jurisdictions in which we recruit, we provide the following information regarding compensation for this position:
MNCJobz.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.