Cybersecurity Incident Manager
19 hours ago
phoenix, arizona, United States
USAA
Full-time
Free with email or Google
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Free with email or Google
By continuing, you agree to our Terms & Privacy Policy.
Why USAA? At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
We are proud to support active-duty military spouses. USAA roles may offer remote or hybrid flexibility for active-duty military spouses consistent with applicable policy and business needs.
The Opportunity
As a dedicated Cybersecurity Incident Manager - Lead , the candidate selected for this position serves as a Lead within the Cyber Threat Monitoring and Response (CTMR) team, responsible for leading and coordinating cybersecurity incident response activities throughout the incident lifecycle across security, technology, business, and third-party partner organizations. Acts as an Incident Commander during active cybersecurity incidents by establishing response objectives, maintaining situational awareness, coordinating cross-functional response teams, and communicating incident status, business impact, and response actions to stakeholders and senior leadership.
This role also supports the ongoing development and maturity of the Cyber Threat Operations Center by driving improvements to incident response processes, operating models, playbooks, training, metrics, and after-action review practices. The successful candidate will identify opportunities to enhance response effectiveness, operational readiness, and cyber resilience through continuous improvement, operational excellence, and the application of industry best practices.
Investigates, analyzes, and responds to security anomalies and events (e.g. suspicious behavior, attacks, and security breaches) within USAA's environments using a variety of cyber defense tools to detect and respond to threats. Conducts vulnerability, security configuration, and/or penetration testing assessments of systems and networks. Identifies cyber threats, analyzes operational impacts, and communicates to appropriate stakeholders. Stays current with latest information security threats, exploits, trends, and intelligence
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ or Colorado Springs, CO. Relocation assistance is not available for this position.
What you'll do
Influences and leads efforts across the Information Security department and enterprise as a subject matter expert in their domain.
Leads research efforts and analysis of the latest information security vulnerabilities, threats, exploits, trends and intelligence. Shares intelligence with the enterprise. Collaborates in the Intelligence community with external organizations.
Serves as subject matter expert, leads, and improves the vulnerability management, security configuration assessment, and/or penetration testing programs.
Develops analysts through training and knowledge sharing activities.
Monitors internal and external networks, systems, and applications for advanced security anomalies and events (e.g.suspicious behavior attacks, and security breaches). Trains analysts in incident detection and response.
Leads and improves the incident response program.
Leads and responds to cyber incidents, performing detailed analysis using complex security tools to determine root cause and impact by using a broad range of demonstrated experience (e.g.forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures.
Acts as leader for cyber incidents.
May testify as expert witness in court.
Incorporates discoveries from the incident response process to substantially improve the existing detection capabilities, operational processes, security controls, and overall program.
Prepares and delivers written and verbal briefs with recommendations to senior leadership and external parties on latest threats, alerts, incidents, and improvements.
Drives and directs quality work efforts. Serves as the primary resource for cross-functional team members on escalated issues of a unique nature.
Maintains expert level knowledge of USAA Information Security standards as well as industry information security best practices, frameworks, laws, and regulations.
Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.
What you have:
Bachelor's degree OR 4 years of relevant education and/or experience.
8 years of related experience in Information Security, Cybersecurity and/or Information Technology with a se
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
We are proud to support active-duty military spouses. USAA roles may offer remote or hybrid flexibility for active-duty military spouses consistent with applicable policy and business needs.
The Opportunity
As a dedicated Cybersecurity Incident Manager - Lead , the candidate selected for this position serves as a Lead within the Cyber Threat Monitoring and Response (CTMR) team, responsible for leading and coordinating cybersecurity incident response activities throughout the incident lifecycle across security, technology, business, and third-party partner organizations. Acts as an Incident Commander during active cybersecurity incidents by establishing response objectives, maintaining situational awareness, coordinating cross-functional response teams, and communicating incident status, business impact, and response actions to stakeholders and senior leadership.
This role also supports the ongoing development and maturity of the Cyber Threat Operations Center by driving improvements to incident response processes, operating models, playbooks, training, metrics, and after-action review practices. The successful candidate will identify opportunities to enhance response effectiveness, operational readiness, and cyber resilience through continuous improvement, operational excellence, and the application of industry best practices.
Investigates, analyzes, and responds to security anomalies and events (e.g. suspicious behavior, attacks, and security breaches) within USAA's environments using a variety of cyber defense tools to detect and respond to threats. Conducts vulnerability, security configuration, and/or penetration testing assessments of systems and networks. Identifies cyber threats, analyzes operational impacts, and communicates to appropriate stakeholders. Stays current with latest information security threats, exploits, trends, and intelligence
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ or Colorado Springs, CO. Relocation assistance is not available for this position.
What you'll do
Influences and leads efforts across the Information Security department and enterprise as a subject matter expert in their domain.
Leads research efforts and analysis of the latest information security vulnerabilities, threats, exploits, trends and intelligence. Shares intelligence with the enterprise. Collaborates in the Intelligence community with external organizations.
Serves as subject matter expert, leads, and improves the vulnerability management, security configuration assessment, and/or penetration testing programs.
Develops analysts through training and knowledge sharing activities.
Monitors internal and external networks, systems, and applications for advanced security anomalies and events (e.g.suspicious behavior attacks, and security breaches). Trains analysts in incident detection and response.
Leads and improves the incident response program.
Leads and responds to cyber incidents, performing detailed analysis using complex security tools to determine root cause and impact by using a broad range of demonstrated experience (e.g.forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures.
Acts as leader for cyber incidents.
May testify as expert witness in court.
Incorporates discoveries from the incident response process to substantially improve the existing detection capabilities, operational processes, security controls, and overall program.
Prepares and delivers written and verbal briefs with recommendations to senior leadership and external parties on latest threats, alerts, incidents, and improvements.
Drives and directs quality work efforts. Serves as the primary resource for cross-functional team members on escalated issues of a unique nature.
Maintains expert level knowledge of USAA Information Security standards as well as industry information security best practices, frameworks, laws, and regulations.
Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.
What you have:
Bachelor's degree OR 4 years of relevant education and/or experience.
8 years of related experience in Information Security, Cybersecurity and/or Information Technology with a se