Manager, Incident Response/SOAR
Manager, Incident Response/SOARSalary: $160k - $180k + bonusLocation: Chicago, ILHybrid: 3 days onsite, 2 days remoteQualifications8+ years of related experienceTeam Leadership experience, taking initiative; providing and following through on solutions across various skillsets.Experience in SIEM, SOAR, Splunk, Symantec/Netskope DLP, CrowdStrike. Ability to create/tune alerts/rules independently.Advance usage of Splunk SIEM, Splunk SOAR, CrowdStrike, Symantec/Netskope DLP.Incident Response playbook development managing incident analysis and remediation.Security Orchestration and Automated Response tools and concepts.Scripting and development activities to appropriately leverage Application Programing Interfaces (APIs) to optimize integrations between disparate security monitoring and analysis devices.Technical experience and comprehensive knowledge of threat actor capabilities, intentions, methodologies, and motives.Familiarity with computer network exploitation and network attack methodologies while maintaining an understanding of the relationship these activities have with the financial services industry and critical infrastructure.ResponsibilitiesLead cyber security incident responders in response activities including investigation, coordination, review, closure, and reporting.Oversee technical analysis of security events while coordinating incident response activities with internal and external teams.Tier-3 support of alerts and validating tuning requests.Alert tuning and reduction.Lead Automation/AI efforts to optimize security operations effort.Lead 4-6 employees and contingent labor professional for the cyber monitoring and analysis function within Cyber Defense.Manage team effectively in delivery of incident resolution, project tasks, compliance milestones, and systems implementations.Perform talent management functions, including performance reviews, direct feedback, and other administrative functions as required.Confer with and advise subordinates on administrative policies and procedures, technical problems, priorities, and methods.Promote employee development by conducting career-planning sessions with staff and selecting and scheduling employee training classes, conferences, and seminars