It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies. All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Senior Incident Response Coordinator
Location
United States
Posted
80 days ago
Salary
0
Seniority
Senior
No structured requirement data.
Job Description
Senior Incident Response Coordinator
ASM Research
Role Description The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates disciplined war rooms, enforces cadence and runbooks, drives cross-team collaboration, and provides executive-ready communications during and after major events. This role executes the incident response process as defined by enterprise ITSM governance and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness and continual improvement. Key Responsibilities - War‑Room Facilitation: Structure/facilitate major incident bridges; maintain restoration focus; assign actions/owners; track progress to closure; enforce decision/messaging cadence. - Process Execution & Standards: Maintain/enforce incident playbooks, escalation matrices, and communication templates; ensure ITSM record quality, CI linkage, and documentation discipline. - Value‑Stream Awareness: Engage dependencies (infra, app, identity, cloud, network) early based on service mapping; identify/remove bottlenecks delaying restoration (approvals, routing). - Communications: Produce leadership updates/executive briefings translating technical impact/risk/remediation into clear business language; maintain SSOT. - Cross‑Practice Integration: Coordinate with Problem, Change, Release, Service Continuity, and SOC/Cyber IR where service impact/security intersects; support PIRs and trend analysis. - Readiness & Drills: Run tabletop exercises; review playbooks; audit on‑call readiness; ensure consistent execution across shifts/teams. - Mentoring: Coach coordinators/junior IM staff on escalation protocols, communication discipline, and analysis techniques. - Evidence & Audit Trail: Ensure timelines, key decisions, and impact assessments are documented and stored to meet compliance and audit requirements. Qualifications - Bachelor’s degree in Information Technology, Computer Science, Business Administration, or related field, or equivalent relevant work experience. - 8+ years of experience in incident management, incident response, or related IT roles, including leadership of major incidents in large, complex enterprise or federal IT environments. - Deep understanding of ITIL principles and advanced incident management and response best practices, including governance of runbooks, escalation models, and communications. - Demonstrated proficiency with incident management tools, IT service management platforms, and monitoring solutions used to manage major incidents and produce operational and executive reporting. - Excellent problem‑solving, analytical, written, and verbal communication skills, with proven ability to brief senior leadership and translate technical risk into business terms. - Demonstrated ability to lead multiple concurrent complex incidents, make timely decisions with incomplete information, and drive consensus across diverse technical and business stakeholders. - Active SECRET clearance or ability to obtain and maintain required background investigation; U.S. citizenship required. Preferred Qualifications - Leadership experience in enterprise‑scale or defense‑related major incident management, including coordination with external partners or multi‑agency stakeholders. - Advanced incident management or cybersecurity certifications (such as ITIL intermediate/advanced or incident‑response‑oriented credentials). - Experience designing or maturing enterprise incident response frameworks, including integration with cyber defense centers, problem management, and governance processes. Compensation Ranges Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees. EEO Requirements It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies. All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment. Physical Requirements The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions. Disclaimer The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Instructor – CHS & Surveillance Operations
Chenega CorporationFounded in 1974 and headquartered in Anchorage, Alaska, the Chenega Corporation provides clients in the construction, environmental, healthcare, IT, military op
Summary Come join a company that strives for Extraordinary People and Exceptional Performance! Chenega Enterprise Systems & Solutions, LLC, a Chenega Professional Services’ company, is seeking a part-time Instructor – Confidential Human Source (CHS) and Surveillance Operations to support the U.S. Customs and Border Protection (CBP), Office of Intelligence, Law Enforcement Programs & Technology Division (LEPT-D). This role supports CBP operational personnel by delivering advanced instruction in source operations, surveillance, and law enforcement intelligence tradecraft. Our company offers employees the opportunity to join a team where there is a robust employee benefits program, management engagement, quality leadership, an atmosphere of teamwork, recognition for performance, and promotion opportunities. We actively strive to channel our highly engaged employee’s knowledge, critical thinking, innovative solutions for our clients. Responsibilities - Deliver classroom-based CHS and surveillance training - Relate instructional content to CBP law enforcement operations - Facilitate practical exercises and operational scenarios - Mentor and evaluate student performance - Manage classroom environment and learning outcomes - Assist with oversight and development of instructor cadre - Adhere to all security and operational protocols - Support curriculum refinement and training initiatives - Other duties as assigned. Qualifications - Active Secret security clearance - Extensive experience in federal law enforcement intelligence operations - Demonstrated expertise in Confidential Human Source operations and surveillance - Experience analyzing and synthesizing intelligence derived from source operations - Strong written and verbal communication skills - Ability to work flexible schedules - Prior delivery of HUMINT / CHS / Surveillance training as an instructor - Certified training experience from HUMINT or tradecraft schools - 10+ years of federal law enforcement experience - CBP experience (preferred, not required) - Knowledge of instructional design principles (ADDIE or similar) - Knowledge of surveillance and law enforcement intelligence cycles - Strong classroom leadership and mentoring abilities - Ability to motivate students and deliver complex material clearly Teleworking Permitted? Yes Teleworking Details Services will be performed virtually as required Estimated Salary/Wage USD $65.00/Hr. Up to USD $70.00/Hr.
Senior Manager, Adversary Management
CoinbaseA digital currency exchange, Coinbase is used by consumers, merchants, and traders to buy and sell cryptocurrencies, such as Bitcoin, Ethereum, and Litecoin. Founded in 2012 "to cr
Ready to be pushed beyond what you think you’re capable of? At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system. To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems. Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be. While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. Security is a primary competency at Coinbase, and the Security Operations team keeps a watchful eye over every aspect of it. Every day, we go to battle against some of the most sophisticated attackers in the world to protect billions of dollars worth of digital assets and ensure that our customers and employees can enjoy a safe, trusted experience. As Coinbase scales globally, our team is scaling along with it, using a blend of tooling, automation, and strategic team growth to ensure that we’re well-equipped to protect the next billion users of crypto. The Senior Manager, Adversary Management is responsible for strategy, operational oversight, and governance of all aspects of cyber threat intelligence at Coinbase - to include ensuring intelligence support for the Security Operations and other Information Security intelligence requirements. The ideal candidate will possess a deep technical understanding of threat intelligence, cyber-fraud, blockchain (Web 3.0) and traditional (Web 2.0) threat landscapes. Reporting to the Senior Director, Security Operations, this leader will be instrumental in safeguarding the Coinbase environment, its products, and its customers by defining and delivering intelligence services that provide actionable intelligence and disruption of threat-actor activities. To succeed in this role, you must possess a battle-hardened technical background, with a comprehensive understanding of threat landscapes spanning both traditional (Web 2.0) and cutting-edge blockchain technologies (Web 3.0). We want someone who’s hungry and eager to disrupt threat actors and ruin their day. You will be the mastermind behind our long-term and day-to-day strategies, driving the development of our Threat Intelligence and Threat Research teams and services. What you’ll be doing (ie. job duties): - Lead a team of threat intelligence engineers and develop a culture around disruption and deflecting threat actors away from Coinbase and its customers - Lead and set the long-term and day-to-day organizational strategies and operational battle rhythm for Threat Intelligence and Threat Research teams - Engage and partner with leaders internal to Security Operations, Information Security, and across the business to identify intelligence requirements - Define and implement strategies and processes for identification, collection, and processing of prioritized intelligence from external and internal sources and maintain accountability for supplier-provided intelligence providers and tools - Drive stakeholder engagement and enablement through timely threat briefings and reporting on adversary capabilities and intentions - Establish and maintain technical workflows to identify intelligence requirements, to prioritize related work, and to deploy analysis or disruption initiatives - Participate in crypto and community engagements to benchmark teams' capabilities, identify strategic and tactical requirements, and to increase maturity as related to cyber and blockchain intelligence - Have a niche for using AI across intelligence workflows from collection, dissemination and actionable intelligence. We know threat actors are using AI and we would want to stay ahead in the defender’s game - Identify and define services and measurements (Gearing Ratio, KPI, KRI) in conjunction with direct-subordinates responsible for day-to-day operations - Lead engagements with external intelligence sharing communities including FS-ISAC, Crypto ISAC, SEAL ISAC, etc. - Maintain, revise and draft procedures and controls necessary to aid in effective risk and governance for all facets of the Threat Intelligence Operations and Automation function - Prioritize mentoring, leadership, and administrative management of assigned personnel to include goal setting, feedback, and performance evaluation - Perform other duties and/or special projects as assigned What we look for in you (ie. job requirements): - You have experience designing, implementing, and operating highly disruptive Threat Intelligence technologies and services and possess a deep understanding of investigations and the threat intelligence lifecycle - You’re able to mentor a group of highly technical threat intelligence analysts, teaching them a thing or two as you foster their professional growth as their manager. - You’re up-to-date on threat actors, their TTPs, and their motivations in targeting the FinTech or Crypto space - You’ve mastered the art of efficiently leveraging AI agents to be able to perform threat analysis, build adversary trends and proactive define strategies on building identifying and recommending disruptive capabilities across SecOps teams - You are comfortable working cross-functionally with product, IT, and other security stakeholders to design and implement intelligence tech and services - You are actively aware of the threat landscape, and understand the legal, regulatory, and ethical considerations of working with sensitive information and situations - You are discreet, thoughtful, and seek to coordinate systemic, cross functional solutions to mitigate risk - You are adept at translating complex problems into ‘byte-sized’, readily implemented (and preferably automated) solutions - You have excellent verbal and written communication skills. Other team members ask for your input to communicate clearly and concisely and you are comfortable composing briefs and assessments consumed by leadership and training others - You prefer to play as a team and are equally comfortable as the ‘novice’ or the ‘expert’ - Your high degree of empathy means that your coworkers trust you to help tackle their security problems, because you never come across as judgmental or condescending. - Demonstrates the ability to responsibly use generative AI tools and copilots (e.g., LibreChat, Gemini, Glean) in daily workflows, continuously learn as tools evolve, and apply human‑in‑the‑loop practices to deliver business‑ready outputs and drive measurable improvements in efficiency, cost, and quality. Nice to haves: - Bring your vast network of intelligence resources and assets that contribute to the intelligence ecosystem at Coinbase - Have a working or strong understanding blockchain and other crypto technologies - Have experience in one or more of the following areas: incident response, risk management, counterintelligence, fraud detection, intellectual property theft, access and identity management, or IT engineering Job ID: P76252 #LI-Remote Pay Transparency Notice: Depending on your work location, the target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, vision and 401(k)). Annual base salary range (excluding equity and bonus): $243,865—$286,900 USD Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying. Commitment to Equal Opportunity Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Employee Rights and the Know Your Rights notices by clicking on their corresponding links. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law. Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here). Global Data Privacy Notice for Job Candidates and Applicants Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here. AI Disclosure For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description. For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate. The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com
Development Security Operations Engineer, Healthcare Consulting
ICPICP, Inc. is a recognized industry leader in IT product, deployment, integration, and support services.
• Design, build, and maintain automated systems and tools that facilitate software development, testing, deployment, and monitoring • Develop and implement application security vulnerability practices • Deploy CNAPP/CSPM using tools like Microsoft native Defender for Cloud, Prisma Cloud, Wiz • Implement security best practices within the CI/CD pipeline and infrastructure to ensure application security • Responsible for GitHub Enterprise Administration • Ensure proficient in application penetration testing • Assist developers with training and resolving vulnerabilities in a timely manner • Active participation in Change and Architecture Review Meetings • Develop and implement automation scripts to streamline repetitive tasks • Design, build, and maintain continuous integration and continuous delivery pipelines using tools like Sonar, Azure DevOps, GitLab • Manage cloud infrastructure Azure including provisioning, scaling, and configuration management using tools like Terraform or Ansible • Set up monitoring/alert systems to identify potential issues in production environments and create alerts to notify relevant teams • Work closely with our developers, QA engineers, and system administrators to identify and resolve issues throughout the development lifecycle • Debug and troubleshoot technical issues related to deployments, infrastructure, and application performance • Research and analyse the latest security threats, emerging technologies, and DevSecOps trends • Engage in ongoing professional development by attending training sessions, obtaining certifications, and actively participating in industry discussions • Apply new knowledge to improve security strategies, enhance system protections, and drive innovation in DevSecOps practices.
Security Operations Engineer
FICO - Fair Isaac CorporationFICO, also known as Fair Isaac Corporation, is one of the world’s leading credit history and financial analysis organizations. It was founded in 1956 on the i
• Investigate and respond to intrusion events/incidents using SIEM, XSOAR, file analysis, endpoint logs, etc. • Support cybersecurity incident response activities, including but not limited to discover, contain, and mitigate incident response workflows. • Test and evaluate use-cases and work on fine-tuning them. • Identify log sources needed for collection for both cybersecurity and compliance for the SIEM. • Generate appropriate alerting within SIEM to leverage in automation activities. • Write automation in the SOAR to accelerate IR activities (Java, Python, Bash, etc.). • Participate in Monitoring, and Incident Response activities. • Workflow creation and analysis. • Analyze, prioritize and escalate any issues that could potentially put business objectives, results, or processes at risk.



