Required Qualifications
10+ years of experience in incident response, security operations, SOC leadership, threat detection, digital forensics coordination, or cyber crisis management.
Experience leading incident response readiness programs, tabletop exercises, breach advisory engagements, ransomware response, and post-incident improvement planning.
Strong understanding of SIEM, EDR/XDR, SOC processes, detection engineering, escalation workflows, evidence handling, recovery coordination, and operational cyber metrics.
Experience coordinating with legal, communications, executives, infrastructure teams, cloud teams, IAM teams, and third-party vendors during incidents.
Experience supporting public-sector, healthcare, justice, public safety, elections, or other regulated environments preferred.
Ability to support hybrid delivery and be available for onsite coordination when required and authorized.
Preferred Certifications / Credentials
GCIH, GCFA, GCIA, GREM, CISSP, CISM, Security+, CySA+, Microsoft SC-200, or equivalent incident response/security operations certifications preferred.