Senior Manager, Cyber Incident Response Team (CIRT)
India
Bengaluru
,
Karnataka
Information Technology
312

Similar Roles
The Team
We are seeking a Senior Manager, Cyber Incident Response Team (CIRT) to lead the organization's cyber incident response capability, responsible for preparing for, detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across enterprise environments.
This role serves as the operational leader for the Cyber Incident Response Team, managing all aspects of cyber incident handling, digital forensics, threat containment, crisis coordination, and post-incident remediation. The Senior Manager will partner closely with Security Operations, Threat Intelligence, Legal, Privacy, Infrastructure, Engineering, and Business stakeholders to minimize the impact of security incidents and continuously improve organizational cyber resilience.
The ideal candidate combines deep technical expertise in incident response, digital forensics, malware analysis, and cyber crisis management with strong leadership skills and the ability to effectively coordinate high-pressure response efforts across global teams.
Responsibilities
Cyber Incident Response Leadership
Incident Management & Cyber Crisis Response
Digital Forensics & Investigations
Incident Readiness & Response Planning
Threat Intelligence & Threat Hunting Collaboration
Stakeholder & Executive Engagement
What We are looking For
Required Skills
Preferred Skills
Key Competencies
Expected Hours of Work
This is a full-time position. Work is generally performed Monday through Friday; however, participation in on-call rotations, after-hours investigations, weekends, holidays, and emergency response activities will be required to support cyber incident management and crisis response operations.
Travel Requirements
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
It is the policy of Mobility to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Mobility will provide reasonable accommodations for qualified individuals with disabilities.
We are seeking a Senior Manager, Cyber Incident Response Team (CIRT) to lead the organization's cyber incident response capability, responsible for preparing for, detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across enterprise environments.
This role serves as the operational leader for the Cyber Incident Response Team, managing all aspects of cyber incident handling, digital forensics, threat containment, crisis coordination, and post-incident remediation. The Senior Manager will partner closely with Security Operations, Threat Intelligence, Legal, Privacy, Infrastructure, Engineering, and Business stakeholders to minimize the impact of security incidents and continuously improve organizational cyber resilience.
The ideal candidate combines deep technical expertise in incident response, digital forensics, malware analysis, and cyber crisis management with strong leadership skills and the ability to effectively coordinate high-pressure response efforts across global teams.
Responsibilities
Cyber Incident Response Leadership
- Lead the Cyber Incident Response Team (CIRT) responsible for managing enterprise cybersecurity incidents across cloud, endpoint, network, identity, application, and SaaS environments.
- Develop and execute the strategic roadmap for incident response readiness, operational maturity, and continuous improvement.
- Build, mentor, and lead a high-performing team of incident responders, cyber investigators, and forensic analysts.
- Establish operational metrics, service level objectives, and response effectiveness measures.
- Ensure incident response capabilities remain aligned with evolving threat landscapes and business requirements.
Incident Management & Cyber Crisis Response
- Serve as the primary operational leader during cybersecurity incidents and security events.
- Coordinate containment, eradication, and recovery activities across technical and business stakeholders.
- Lead response efforts for ransomware, business email compromise, account compromise, insider threats, malware outbreaks, data loss incidents, cloud security incidents, and advanced persistent threats.
- Manage executive communications, stakeholder engagement, and escalation processes during critical incidents.
- Facilitate cyber crisis management activities and support organizational business continuity efforts.
Digital Forensics & Investigations
- Oversee digital forensic investigations involving endpoints, cloud platforms, identity systems, applications, email systems, and network infrastructure.
- Ensure proper evidence collection, chain-of-custody procedures, and forensic analysis methodologies.
- Lead root cause investigations and determine attacker timelines, scope, impact, and indicators of compromise.
- Coordinate with Legal, Privacy, Compliance, Human Resources, and external partners as required.
- Maintain readiness of forensic tools, investigative procedures, and response resources.
Incident Readiness & Response Planning
- Develop, maintain, and regularly test incident response plans, playbooks, runbooks, and operational procedures.
- Conduct tabletop exercises, simulations, and response drills to validate preparedness.
- Continuously improve incident workflows based on lessons learned, threat intelligence, and industry best practices.
- Ensure response procedures align with applicable regulatory, contractual, and compliance requirements.
- Drive organizational awareness and readiness programs related to cyber incident management.
Threat Intelligence & Threat Hunting Collaboration
- Partner with Threat Intelligence and Security Operations teams to improve detection and response capabilities.
- Leverage threat intelligence to identify emerging risks, adversary tactics, and attack trends.
- Support proactive threat hunting activities related to active incidents and emerging threats.
- Utilize frameworks such as MITRE ATT&CK to improve investigative methodologies and response effectiveness.
- Ensure indicators of compromise and lessons learned are incorporated into detection and monitoring capabilities.
Stakeholder & Executive Engagement
- Provide incident updates, risk assessments, and response recommendations to senior leadership.
- Coordinate communications with executive leadership, legal counsel, privacy teams, and external stakeholders when required.
- Develop executive-level reporting on incident trends, response metrics, and organizational readiness.
- Build strong partnerships across cybersecurity, infrastructure, engineering, and business organizations.
- Support regulatory inquiries, audit activities, and incident reporting obligations when necessary.
What We are looking For
Required Skills
- 8+ years of cybersecurity experience with significant focus on incident response, cyber investigations, digital forensics, or threat detection.
- 3+ years of leadership experience managing cybersecurity response teams.
- Deep expertise in cyber incident response lifecycle management, including detection, containment, eradication, and recovery.
- Strong knowledge of digital forensics, malware analysis, intrusion analysis, and attack investigations.
- Experience responding to enterprise-scale cybersecurity incidents, including ransomware and advanced threat activity.
- Hands-on experience with EDR/XDR, SIEM, cloud security platforms, forensic tools, and threat intelligence solutions.
- Strong understanding of operating systems, networks, cloud platforms, identity systems, and cybersecurity controls.
- Familiarity with NIST Incident Response Framework, MITRE ATT&CK, Cyber Kill Chain, and industry best practices.
Preferred Skills
- Experience operating within a global enterprise cybersecurity environment.
- Experience conducting cloud forensics across AWS, Azure, and Google Cloud Platform.
- Familiarity with litigation support, incident reporting requirements, privacy regulations, and breach notification processes.
- Relevant certifications such as CISSP, GCIH, GCFA, GCFE, GCIA, GNFA, CISM, or equivalent.
- Bachelor's or Master's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.
Key Competencies
- Incident command and crisis leadership
- Cybersecurity investigations and forensics
- Strategic decision-making under pressure
- Executive communication and stakeholder management
- Analytical and problem-solving skills
- Team leadership and talent development
- Risk assessment and prioritization
- Cross-functional collaboration
- Attention to detail and operational discipline
- Continuous improvement mindset
Expected Hours of Work
This is a full-time position. Work is generally performed Monday through Friday; however, participation in on-call rotations, after-hours investigations, weekends, holidays, and emergency response activities will be required to support cyber incident management and crisis response operations.
Travel Requirements
- Up to 10% domestic and international travel may be required.
- Travel may include incident response planning sessions, cybersecurity exercises, leadership meetings, training events, and industry conferences.
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
It is the policy of Mobility to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Mobility will provide reasonable accommodations for qualified individuals with disabilities.
