Manager, Incident Response
Manager, Incident Response
REMOTE (Eastern and Central Time Zones)
About the Role:
As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver industry-best service to our customers.
This role requires you to be an innovator and driver for customer success in our investigations, digital forensics, and security incident response and support. You will be a thought leader in the company, working closely with other internal and external resources and stakeholders to ensure a timely and effective response to incidents as well as customer success.
Responsibilities:
- Provide thought, technical, and general leadership to the IR Consulting Team and other stakeholders
- Assist with managing the team portfolio to defined metrics (utilization, revenue, margin etc.)
- Deliver services to customers by attending key meetings, performing quality assurance reviews of deliverables, and direct consultation with customers as needed
- Collaborate with the Product Management Team to define and evolve our book of service offerings
- Team with Sales as support on prospective client calls, project scoping and budgets
- Maintain individual and team skills and knowledge base on industry best practices, tools, tabletop exercise techniques, and scenario-based and live testing exercises.
- Manage customer stakeholders and apply security incident investigative protocols from confirmation of the incident to resolution and capturing lessons learned.
- Quickly mitigate damages by coordinating with technical teams and third-party vendors to triage and contain threats.
- Maintain and update incident response playbooks and toolkits based on new procedures, best practices, advanced open-source technologies and various incident response products.
- Design and deploy real time monitoring and triage of incidents and alerts received.
- Identify and document requirements to improve, automate, and work with developers to build tools that drive out inefficiencies, ineffectiveness, and uncompromisingly improve the customer experience.
- Build and foster relationships with local, state, federal and international law enforcement authorities.
Technologies:
- Windows OS and networking protocols
- Windows disk and memory forensics
- Unix OS and networking protocol
- Network traffic analysis
- Scripting and/or programming
- Experience with commercial EDR (SentinelOne, Blackberry PROTECT, CarbonBlack, CrowdStrike) and Forensic tool suites (FTK, AXIOM, EnCase)
- Reverse engineering and malware analysis
Knowledge and Skills:
- Minimum of 5 years experience in cyber security
- 1 or more years of experience leading information security and/or consulting teams
- Bachelor’s Degree with disciplines in the area of Computer Science, Management Information Systems, or Cyber Security or equivalent experience, is preferred
- One or more of the following technical certifications preferred: GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), MCFE, EnCE or equivalent certifications
- Proven track record of complex problem solving and decision-making ability
- Expert level of analytical, planning and organizational ability.
- Strong, proactive communication skills required
If you have other combinations of relevant skills and experience that you expect make you the right candidate for this role, please let us know.
Who we are:
At Pondurance we embrace, educate, and protect people by helping make our world a better and safer place. We believe in inviting good people into our company who are driven to become great!
Every person at Pondurance is encouraged to focus and grow in their individual areas of interest, passion, and career path. We have accessible leaders as Mentors who believe “None of us are as smart as all of us” (R. Pelletier).
We believe everyone has the freedom to be themselves, especially at work and so we embrace, support, and celebrate each other. Each one of us influences our company’s direction through speaking up, you have a voice and we want you to use it.
Do you want to be a part of something different? Do you want to influence real change? Do you want to be part of the solution? Then join us in redefining the security and cyber risk landscape.
What We Offer:
The opportunity to apply your expertise, take on new challenges, and help customers address their biggest security objectives.
An inclusive culture of teamwork that embraces the diversity of our people and communities in which we work.
Some of the corporate benefits (there are more) for full-time employees include:
- Medical, dental, vision, disability, FSA, HSA, life and AD&D insurance, 401(k) Plan.
- Time off: PTO, sick, holiday, & parental leave details are available
- Money: We provide competitive compensation packages based on the market and your overall credentials.
Although this is a remote role, if you live close by, you’ll have access to our office locations: McLean, VA or Indianapolis, IN.
To promote a healthy and safe work community we require background and drug screenings as part of our hiring process. Details of our process will be provided upon request.
We are an equal opportunity employer focused on celebrating diversity and inclusion. We believe that each individual should be treated equally without regard to race, color, identity, national origin, protected veteran status, religion, sex including sexual orientation and gender identity, disability, or any other characteristic protected by law.