Skip to content

Open nowPosted 29 days ago

Cyber Security Incident Response Lead

Staples Inc.19 open roles

Where
Framingham, MA, United States
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCyber Security Incident Response LeadStaples Inc. · Framingham, MA, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Staples Inc.'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Staples Inc. postings stay open a median of 6 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 29 days ago

Staples Inc. median: 6 days open

The posting

Job Description

Staples Digital Solutions is strengthening its cyber defense capabilities, and we’re looking for a senior technical incident response professional to help protect our associates, customers, data, and enterprise technology environment. This role sits within Cyber Security and partners closely with Security Operations, Infrastructure, Cloud, Identity, Legal, Privacy, Risk, Human Resources, and other teams to respond to complex and high-impact cybersecurity events. Based in Framingham, MA, this opportunity reports to the Director of Security Operations and operates as a senior individual contributor with meaningful influence across the enterprise.

As a Cyber Security Incident Response Lead, you’ll serve as a senior technical escalation resource for significant cybersecurity incidents across Staples. You’ll lead hands-on investigation and response activities across endpoint, identity, cloud, network, email, and security telemetry to determine threat scope, business impact, root cause, and recommended response actions. You’ll also help mature the incident response program by improving playbooks, exercises, metrics, processes, threat-hunting practices, detection recommendations, and automation opportunities.

Role requires the incumbent to work at our Framingham, MA facility but we are open to candidates that are willing to relocate to the area. We will also consider providing relocation assistance.

What you’ll be doing:

  • Conduct complex cybersecurity investigations from initial escalation through containment, eradication, recovery, and post-incident review.
  • Analyze endpoint, identity, cloud, network, email, and log-based telemetry to identify attacker activity, determine incident scope, and assess potential impact.
  • Provide senior technical guidance during significant incidents in partnership with SOC Leads and Managers.
  • Coordinate response activities across Cyber Security, Infrastructure, Cloud, Identity, Legal, Privacy, GRC, Human Resources, external partners, and other business and technology teams.
  • Develop and continuously improve incident response plans, investigative procedures, escalation processes, playbooks, exercises, metrics, and supporting documentation.
  • Conduct proactive threat hunting based on threat intelligence, vulnerabilities, anomalous activity, and observed adversary techniques.
  • Support insider risk investigations involving suspicious user behavior, misuse of access, data loss, or potentially malicious internal activity.
  • Document investigation findings, lessons learned, recurring risks, and improvement opportunities from post-incident reviews.
  • Partner with Detection Engineering, Threat Intelligence, and security technology teams to improve detection coverage, investigative capabilities, and automation.
  • Participate in an on-call escalation rotation for significant cybersecurity incidents requiring senior technical expertise.

What you bring to the table:

  • Advanced technical investigation, analytical, and problem-solving skills.
  • Sound technical judgment and the ability to make recommendations using incomplete or evolving information.
  • Ability to support complex cybersecurity incidents calmly and effectively under pressure.
  • Strong written and verbal communication skills, including the ability to translate technical findings into clear business risk considerations and recommended actions.
  • Strong collaboration skills across technical and non-technical teams.
  • Curiosity and initiative to identify improvements within the incident response discipline.
  • Strong understanding of evolving attacker behaviors, techniques, and technologies.
  • Discretion and sound judgment when handling sensitive investigations, including potential insider risk matters.
  • Ability to participate in an on-call escalation rotation for significant cybersecurity incidents.

What’s needed- Basic Qualifications:

  • Bachelor’s degree in Computer Science, Information Security, a related field or equivalent work experience.
  • 7+ years of cybersecurity experience, including incident response, digital forensics, threat hunting, detection engineering, or Security Operations.
  • Experience conducting complex cybersecurity investigations in large enterprise environments.
  • Experience developing or maintaining incident response plans, procedures, playbooks, exercises, metrics, or supporting processes.
  • Experience conducting post-incident reviews, root cause analysis, or lessons-learned documentation.
  • Experience coordinating technical response activities across multiple technology and business teams.

What’s needed- Desired Qualifications:

  • Experience within larger distributed enterprise environments, ideally retail and/or e-commerce.
  • Advanced technical training or relevant cybersecurity certifications such as GCIH, GCFA, GCFE, GNFA, CISSP.
  • Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Endpoint, or Microsoft Entra ID.
  • Experience with SOAR platforms and automated incident response workflows.
  • Hands-on experience investigating endpoint, identity, cloud, network, email, or log-based security telemetry.
  • Hands-on experience using SIEM, EDR/XDR, identity security, cloud security monitoring, or security automation technologies.
  • Experience conducting enterprise threat hunting or developing detection content.
  • Experience supporting insider risk, user behavior, data loss, or other user-focused security investigations.
  • Experience investigating identity-based or cloud-based attacks.
  • Experience responding to ransomware, credential compromise, business email compromise, insider threats, data theft, or supply-chain incidents.
  • Knowledge of cybersecurity incident response requirements, including PCI DSS and applicable privacy requirements.

What’s needed- Desired Qualifications:

  • Advanced technical training or relevant cybersecurity certifications such as GCIH, GCFA, GCFE, GNFA, CISSP.
  • Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Endpoint, or Microsoft Entra ID.
  • Experience with SOAR platforms and automated incident response workflows.
  • Experience conducting enterprise threat hunting or developing detection content.
  • Experience supporting insider risk, user behavior, data loss, or other user-focused security investigations.
  • Experience investigating identity-based or cloud-based attacks.
  • Experience responding to ransomware, credential compromise, business email compromise, insider threats, data theft, or supply-chain incidents.
  • Knowledge of cybersecurity incident response requirements, including PCI DSS and applicable privacy requirements.
  • Experience within large retail, e-commerce, or distributed enterprise environments.

We Offer:

  • Inclusive culture with associate-led Business Resource Groups
  • 22 days of PTO and Holiday Schedule (7 observed paid holidays + 1 floating holiday)
  • Online and Retail Discounts, Company Match 401(k), Physical and Mental Health Wellness programs, and more!

The salary range represents the expected compensation for this role at the time of posting. The specific base pay may be influenced by a variety of factors to include the candidate's experience, skill set, education, geography, business considerations, and internal equity. In addition to base pay, this role may be eligible for bonuses, or other forms of variable compensation.

About Us

Staples is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, age, national origin, protected veteran status, disability, or any other basis protected by federal, state, or local law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Staples Inc.'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Staples Inc.'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Staples Inc.'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.