Incident Response Engagement-Lead
Applying for this one?
We write the CV against this exact posting — its wording, its requirements — not a template with your name in it.
$25, one-time. No subscription.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Incident Response Engagement-Lead based in the United States.
This role leads complex cyber incident engagements from initial scoping through containment, eradication, and recovery. You will act as a central liaison between claims teams, legal counsel, incident response providers, and affected policyholders. The position combines hands-on digital forensics expertise with project leadership, consulting, and stakeholder management. You will oversee external forensic investigations, manage timelines and scope, and ensure findings are translated into actionable insights. The role requires confidence working in legally sensitive environments where accuracy, discretion, and clear communication are essential. You will collaborate across technical, legal, claims, underwriting, and external partner teams during high-pressure situations. You will also contribute to improving incident response methodologies, playbooks, and tools within a growing cyber resilience environment.
Accountabilities:
- Lead and coordinate the full incident response lifecycle, including scoping, containment, eradication, and recovery, across moderately complex, multi-system environments.
- Serve as the primary point of contact for claims teams, breach counsel, incident response providers, and policyholders throughout active cyber incident engagements.
- Manage and oversee digital forensics and incident response providers, ensuring investigations are appropriately scoped, timely, accurate, and aligned with engagement objectives.
- Identify, track, and actively manage scope changes and potential scope creep across multiple concurrent engagements while maintaining timelines and stakeholder alignment.
- Schedule, coordinate, and facilitate briefings on complex forensic findings, translating technical investigation results into clear and actionable reporting for technical, legal, and executive audiences.
- Work effectively within legally sensitive investigations, applying an understanding of Attorney-Client Privilege and Work Product Doctrine in coordination with legal counsel.
- Collaborate with claims adjusters, underwriters, external partners, and other stakeholders to support accurate incident documentation and informed coverage determinations.
- Contribute to the ongoing development and improvement of incident response methodologies, playbooks, processes, and tooling.
- 4–6 years of hands-on experience in digital forensics and incident response (DFIR), with meaningful exposure to the cyber insurance ecosystem, including experience working with or on behalf of insurance carriers, breach counsel, and/or policyholders.
- Demonstrated experience managing cyber incidents through scoping, containment, eradication, and recovery.
- Proven ability to lead moderately complex, multi-system investigations while applying strong project management skills and proactively controlling scope.
- Experience working in legally sensitive environments, with an understanding of Attorney-Client Privilege and the Work Product Doctrine.
- Strong consulting, communication, and stakeholder management skills, including the ability to present forensic findings to technical, legal, and executive audiences.
- Ability to remain organized, decisive, and detail-oriented while managing multiple concurrent engagements in high-pressure incident response situations.
- A bachelor’s degree in Cybersecurity, Information Security Management, Digital Forensics, Computer Science, or a related discipline is preferred.
- Equivalent professional experience may be considered in lieu of a degree, particularly when combined with relevant industry certifications such as GCIH, GNFA, CompTIA CySA+, CISM, or CISSP.
- Strong analytical, problem-solving, written communication, and presentation skills, with the ability to translate complex technical information into practical recommendations.
- Remote work opportunity within the United States.
- Competitive compensation aligned with experience and responsibilities.
- Comprehensive employee benefits, including healthcare coverage.
- A collaborative and dynamic environment with opportunities to work across technical, legal, claims, underwriting, and external partner teams.
- Opportunities for continuous professional development and career growth.
- The opportunity to work on complex, high-impact cyber incidents and contribute to the evolution of incident response practices.
- An inclusive workplace committed to equal employment opportunity and a diverse range of perspectives.
- Exposure to an innovative, technology-driven environment focused on cyber risk, resilience, and incident response.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Seen 5 hours ago · within 114 minutes of the employer posting it.
Original posting on Jobgether's site ↗
Posting text belongs to the employer. Removal requests: contact us.
Nearby
Live postings like this one
Same employer first, then the same role elsewhere.
- Remote5h ago
- Remote5h ago
- Remote5h ago
- Remote5h ago
- Remote5h ago
- Remote5h ago
- Remote5h ago
- Remote5h ago
One job at a time
One posting. One CV. $25.
Pick the job you actually want and we write for it.