Jobs and Careers
LU

Manager, Incident Response

Lumin Digital
Remote- United States, United StatesRemotefull_timeVerifiedPosted 29 Aug 2025

About the role

Basic FunctionThe Security Operations Center (SOC) team at Lumin Digital is responsible for all phases of the security incident lifecycle, including preparation, identification, containment, eradication, recovery, and reviewing lessons learned.  This team is responsible for these lifecycle activities, both for internal corporate IT systems as well as the digital banking solutions that Lumin Digital develops and hosts to serve millions of consumers across the globe.  This role serves as the leader of this function: overseeing incident response operations, driving improvements in threat detection and response capabilities, and coordinating across technical and business teams to ensure active monitoring, timely escalation, and measurable outcomes.
Essential Functions and Responsibilities:Identify emerging industry threats, observed trends, and industry best practices guidelines to identify gaps and identify, plan, design, and enhance security controls in collaboration with other risk engineering teamsDevelop comprehensive and insightful fact-based reports on SOC metrics, such as MTTD, MTTR, and coverage, and trends, and present them to internal leadership and client security teams on a regular basisProduce and deliver job-specific education and training to SOC team members on emerging threats and technologies using structured approaches to threat and risk managementReview the technical methods and output of the SOC team to ascertain the quality and fit of solutions, and provide constructive and detailed feedback to improve team members’ ability to perform their dutiesLead formalized security incident response procedures as part of a team, including all phases of the incident handling lifecycle, from preparation through lessons learnedCollect evidence of SOC activities to satisfy client due diligence requests as well as support internal and external audit activitiesPerform other duties as assigned.
Supervisory Responsibility:Set clear expectations, offer direction, and ensure alignment with organizational goals while fostering a supportive environment that encourages collaboration, accountability, and growth.Coach, mentor, and provide training opportunities to build team members’ skills, promote internal growth, and prepare staff for future roles and responsibilities.Manage hiring, onboarding, performance evaluations, promotions, compensation, and terminations, ensuring fair and consistent application of policies and procedures.Assess team performance regularly, address gaps, and ensure duties are completed efficiently and effectively in alignment with department and organizational objectives.
Position Specifications
Education: Bachelor's degree in Information Assurance, Information Security, Cybersecurity, or related field is required; or equivalent combination of education and experience in cybersecurity with demonstrated command of key SOC concepts and technologies and proficiencies in threat modeling, detective and preventative controls, digital forensics, incident response, OSINT, network penetration testing, and other relevant technical security risk management domains.Certifications relevant to security operations or management of SOC teams, such as the GCIH, GCIA, GSOM, or CISM, are preferred.
Experience:5 years of hands-on technical experience directly working with detective security controls, including layer 3, 4, and 7 firewalls, log aggregation, endpoint detection and response, and public cloud security posture management required.3 years of experience leading or driving incident response efforts within a Security Operations Center (SOC) or equivalent function required. Experience may include mentoring teammates, coordinating cross-functional responses, or owning end-to-end incident management processes, preferably in financial institutions or fintech environments.Experience with large-scale AWS operating environments, Linux, Kubernetes, Git, and scripting languages required.Experience analyzing and summarizing security operations information to characterize trends in threats, vulnerabilities, and posture to internal management teams is required.  Applicants are invited to provide an example or excerpt of a report or presentation they solely developed, with any confidential information redacted, in their cover letter that illustrates this experience and skill.
Knowledge, Skills, & Abilities:Excellent teamwork skills, including the ability to lead with command and confidence under pressure and uncertaintyExcellent data analysis skills, including using tools like Excel and OpenSearch, to customize and report on key metrics specifically useful for the company and relevant to the current threat environment and organizational needs of the companyStrong written and verbal communication skills, including the ability to develop clear, data-driven reports and presentations using Google Docs, Slides, or RStrong presenta

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Lumin Digital

View company profile →