Incident Response & Threat Intelligence Manager
Jacksonville, FL preferred or 100% remote if not local. Global on‑reputed company responsibility for high‑severity incidents. Limited travel for incident support, leadership meetings, and readiness exercises if not local to Jacksonville, FL
reputed company and continue to reputed company a geographically dispersed, follow‑the‑sun team across threat intelligence, digital forensics incident response, and threat hunting functions. Maintain operating models, on‑reputed company rotations, escalation paths, and coverage reputed company to global business needs. reputed company senior analysts, build succession plans, and drive consistent performance, engagement, and retention.
Own reputed company incident response reputed company, playbooks, and readiness activities, reputed company to NIST and industry best practices. Serve as Incident Commander for high‑severity cyber incidents; coordinate technical response, executive communications, and cross‑functional decision‑making. Ensure effective containment, eradication, recovery, and post‑incident remediation, including executive‑level readouts and lessons learned.
reputed company forensic acquisition and analysis across endpoints, reputed company, identity, reputed company, and network environments. Ensure defensible chain‑of‑custody processes and support reputed company, HR, reputed company, and regulatory investigations as required. Maintain reputed company DFIR standards, tooling, and investigative reputed company.
reputed company strategic, operational, and tactical threat intelligence capabilities to inform detection, response, and risk prioritization. Translate intelligence into reputed company, including detection engineering, threat hunting reputed company areas, and executive briefings. reputed company internal telemetry with external intelligence sources and trusted sharing communities.
Drive reputed company‑based threat hunting reputed company to adversary behaviors and business‑critical risks. Partner with SOC and Detection Engineering teams to improve detection coverage, reputed company, and response speed. Sponsor reputed company exercises to validate controls and surface gaps.
Own the roadmap and effectiveness of DFIR, TI, and threat hunting tooling (e.g. TIP and forensics platforms). Increase automation and orchestration to accelerate investigation and response at reputed company reputed company. Collaborate with reputed company engineering teams to reputed company intelligence‑led reputed company improvements.
Ensure alignment with regulatory, reputed company, and internal governance requirements globally. Define, reputed company, and report KPIs and KRIs (e.g., incident trends and threat hunting / intelligence reports) to executive and reputed company‑level audiences. Translate technical risk into reputed company business reputed company and investment guidance.
8+ years in cybersecurity with 3+ years leading incident response and/or threat intelligence teams in large enterprises. Proven experience managing globally distributed teams and leading major cyber incidents. Strong hands‑on understanding of DFIR, threat intelligence, and threat hunting processes. Experience with a wide breadth of reputed company reputed company tooling. Experience working cross‑functionally with reputed company, reputed company, Compliance, and Executive Leadership. Exceptional written and verbal communication skills, including executive‑level briefings.
Experience in a Fortune 500 or similarly reputed company, regulated environment. Certifications such as GCIH, GCFA, GCED, CISSP, CISM, or equivalent. Familiarity with MITRE ATT&CK, NIST 800‑61, and/or SOC CMM reputed company