Jobs and Careers
MA

Senior Manager, Incident Response

Madrigal Pharmaceuticals
PA - Pennsylvania – Remote, United States, United StatesRemotefull_timeVerifiedPosted 6 Apr 2026
💰 $194,000/yr($159,000/yr – $194,000/yr)

About the role

Madrigal is a biopharmaceutical company focused on delivering novel therapeutics for metabolic dysfunction-associated steatohepatitis (MASH), a serious liver disease that can progress to cirrhosis, liver failure, need for liver transplantation and premature mortality. Every member of our Madrigal team is connected by our shared purpose: leading the fight against MASH.

 

Madrigal’s medication, Rezdiffra (resmetirom), is a once-daily, oral, liver-directed THR-β agonist designed to target key underlying causes of MASH. Rezdiffra is the first and only medication approved by both the FDA and European Commission for the treatment of MASH with moderate to advanced fibrosis (F2 to F3). An ongoing Phase 3 outcomes trial is evaluating Rezdiffra for the treatment of compensated MASH cirrhosis (F4c).

 

Our success is driven by our people. We are building a dynamic, inclusive, and high-performing culture that values scientific excellence, operational rigor, and collaboration. To support our continued growth, we are strengthening our workforce strategy to ensure we have the right talent, at the right time, in the right way.

The Senior Manager, Incident Response leads the organization’s enterprise-wide cyber incident response capability, ensuring rapid detection, containment, and recovery across cloud, identity, endpoint, and SaaS environments. This role combines hands-on technical leadership with program development, driving continuous improvement in response readiness, forensic rigor, and cross-functional coordination to reduce business risk and strengthen organizational resilience.

The ideal candidate brings deep expertise in cloud and identity-driven threats, strong investigative discipline, and the ability to translate complex incidents into clear business impact, regulatory implications, and executive-level decisions.

Key Responsibilities

  • Lead the organization’s enterprise cyber incident response capability across cloud, identity, endpoint, SaaS, and email environments, ensuring effective detection, containment, eradication, and recovery.
  • Direct technical investigations and forensic activities to determine root cause, scope, and business impact, including risks to sensitive data, intellectual property, and regulated systems, maintaining defensible evidence handling aligned with legal and regulatory requirements.
  • Own the continuous improvement of the incident response program, including readiness, tooling, and alignment to evolving threat and regulatory landscapes.
  • Develop, maintain, and operationalize incident response playbooks, workflows, and tabletop exercises aligned with NIST and MITRE ATT&CK frameworks, including clearly defined escalation paths and decision-making frameworks.
  • Oversee detection and response to phishing, credential compromise, token abuse, and business email compromise, coordinating identity, endpoint, and cloud response actions.
  • Correlate signals across security platforms (EDR, SIEM, identity and cloud telemetry) to identify coordinated or persistent threats and reduce attacker dwell time.
  • Serve as a senior escalation point during high-severity incidents, translating technical findings into business impact, executive-ready communications, and risk-based recommendations.
  • Define and track incident response metrics (e.g., MTTD, MTTR, dwell time, containment effectiveness), lead post-incident reviews, and drive continuous improvement in response effectiveness, resilience, and program maturity.
  • Partner with Security Operations, Engineering, IT, Compliance, Legal, HR, and Communications to align response strategies, remediation efforts, and enterprise risk reduction.

Required & Desired Qualifications

Required Qualifications

  • 8+ years of experience in cybersecurity, with significant hands-on focus in incident response, threat detection, or security operations.
  • Proven experience leading security incident response in cloud-first environments, including Azure, AWS, and Microsoft 365.
  • Strong working knowledge of endpoint detection and response (EDR), SIEM platforms, identity and cloud-native logging, and security tooling.
  • Demonstrated expertise in investigating phishing, credential compromise, business email compromise (BEC), and identity-driven attacks.
  • Solid understanding of attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK.
  • Experience directing or performing digital forensics, incident documentation, and evidence handling in support of legal, regulatory, and compliance requirements.
  • Ability to lead cross-functional response efforts and make sound decisions under pressure during high-severity incidents.
  • Strong written and verbal

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Madrigal Pharmaceuticals

View company profile →