Jobs and Careers
DI

Director, Cyber Incident Response

Direct Travel
Remote, United States, United StatesRemotefull_timeVerifiedPosted 5 Aug 2026

About the role

Position Summary

The Director of Incident Response is responsible for leading the organization's cyber incident response program, ensuring the timely detection, containment, eradication, and recovery from cybersecurity incidents. This role develops and executes the enterprise Incident Response strategy, manages a high-performing Security Operations and Incident Response team, and partners closely with IT, Legal, Privacy, Compliance, Communications, Risk, and executive leadership to minimize business impact from cyber threats.

The Director will drive operational excellence across incident response, digital forensics, threat intelligence integration, cyber crisis management, and continuous improvement while ensuring compliance with regulatory and contractual obligations.

 

Key Responsibilities

Incident Response Leadership

  • Lead and manage the enterprise Cyber Incident Response (IR) program.
  • Direct response activities for high-severity security incidents, including ransomware, business email compromise, insider threats, cloud attacks, third-party compromises, and data breaches.
  • Serve as Incident Commander during major cyber incidents.
  • Coordinate cross-functional response efforts across IT Infrastructure, Cloud, Identity, Legal, HR, Privacy, Communications, and executive leadership.
  • Ensure rapid containment, eradication, recovery, and lessons learned activities.

Security Operations

  • Oversee operational effectiveness of:
    • Security Monitoring
    • SIEM
    • EDR/XDR
    • SOAR
    • Threat Detection
    • Threat Hunting
  • Establish incident severity models, response playbooks, escalation procedures, and SLAs.
  • Drive improvements in detection engineering and automation.

Digital Forensics

  • Lead forensic investigations involving endpoints, cloud environments, SaaS platforms, identity systems, and email.
  • Ensure proper evidence preservation and chain of custody.
  • Coordinate with outside forensic firms when necessary.

Cyber Crisis Management

  • Develop and maintain Cyber Crisis Management plans.
  • Conduct tabletop exercises with executive leadership.
  • Coordinate crisis communications during major incidents.
  • Provide executive briefings and Board-level updates during cyber events.

Threat Intelligence & Hunting

  • Integrate threat intelligence into detection and response operations.
  • Oversee proactive threat hunting across enterprise environments.
  • Identify emerging threats targeting the organization and industry.

Program Development

  • Develop and mature the Incident Response program aligned with:
    • NIST CSF
    • NIST SP 800-61
    • MITRE ATT&CK
    • ISO 27035
  • Maintain incident response policies, standards, procedures, and playbooks.
  • Measure program maturity and drive continuous improvement initiatives.

Compliance & Reporting

  • Ensure incident response activities support:
    • PCI DSS
    • HIPAA (where applicable)
    • GDPR
    • CCPA
  • Produce executive dashboards and metrics including:
    • Mean Time to Detect (MTTD)
    • Mean Time to Respond (MTTR)
    • Incident trends
    • Root cause analysis
    • Detection coverage
    • Lessons learned

Leadership

  • Build, mentor, and develop global Incident Response and Security Operations personnel.
  • Foster a culture of continuous learning and operational excellence.
  • Participate in hiring, budgeting, workforce planning, and performance management.

 

Required Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Informat

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Direct Travel

View company profile →