Jobs and Careers
UN

IT Security Incident Response Leader

University of Miami
Offsite Remote Work - UHealth IT, United States, United StatesRemotefull_timeVerifiedPosted 3 Oct 2025

About the role

Current Employees:

If you are a current Staff, Faculty or Temporary employee at the University of Miami, please click here to log in to Workday to use the internal application process. To learn how to apply for a faculty or staff position using the Career worklet, please review this tip sheet.

The University of Miami Health System, "UHealth", Information Technology Department has an exciting opportunity for a full-time IT Security Incident Response Leader.

The IT Security Incident Response Leader will lead the proactive incident detection, response, and recovery efforts.  This individual will be responsible for developing and implementing incident response strategies, managing a team of cybersecurity professionals, and ensuring compliance with industry standards, regulations, and following industry best practices to optimize incident response processes and enhance the organization’s security posture. The incumbent will also drive continuous improvement through incident analysis, threat hunting, and incident simulation exercises. The ideal candidate possesses strong leadership, communication, and technical skills, with a deep understanding of cybersecurity frameworks and emerging threats.

Core Responsibilities                                                                                                      

  • Supervises the performance management of all assigned staff including making decisions as they pertain to hiring, training, evaluation, promotion, and termination.
  • Manages daily operations and directs staff to achieve departmental goals and objectives.
  • Acts as liaison between industry peers, government agencies (including law enforcement), and other specialists.
  • Utilizes commercial intelligence providers to gain insight into adversary tactics, techniques, and procedures, as well as planned activities and emerging threats.
  • Coordinates with Security Operations to identify and assess security incidents.
  • Advises IT Leadership of significant emerging threats and recommends both strategic and tactical steps to counteract these threats.
  • Establishes departmental goals and objectives, identifies areas of improvement, and implements action plans to meet these.
  • Develops and delivers tabletop preparedness exercises on an annual basis.
  • Leads quarterly reviews of the incident response plan to ensure accuracy in accordance with organizational and infrastructure changes.
  • Attends professional meetings, workshops, conferences, and seminars to keep abreast of technological market advancements.
  • Establishes and continuously assesses the effectiveness of the internal controls within the unit and compliance with University policies and procedures. Ensures employees are trained on controls within the function and on University policy and procedures.

Department Specific Functions

  • Develops and maintains the security incident response process, including all required supporting materials.
  • Develops functional requirements for roles that will be involved in the CSIRT program.
  • Works with business units, IT functions and external providers to ensure that the process is mutually understood and agreed on, and that responsibilities are clear and accepted.
  • Acts as a liaison throughout the entire organization (including, but not limited to, enterprise IT services, lines of business, public relations, legal counsel, and customer call centers).
  • Initiates the security incident response process and executes decision authority to the extent of the role within that process.
  • Ensures execution of the incident response process to the resolution of the incident.
  • Ensures generation, maintenance, and protection of required incident records, such as investigator journals.
  • Organizes, participates in and, if required, chair post-incident reviews for presentation to the senior management.
  • Ensures the delivery of threat intelligence collected from incident engagements to threat intelligence teams and content creators for the purpose of operationalizing.
  • Provides specialized security support for other events that fall outside the security incident realm, such as fraud attempts based on electronic channels or high-impact outages due to reasons other than security.
  • Organizes the day-to-day management of the CSIRT, including staffing, employee development, budgeting and other relevant management functions.

This list of dutie

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

University of Miami

View company profile →