
Cyber Incident Manager
Solis · United States
- Hybrid
- Full-time
- $120,000 / year
- United States
Tailored resume — keyword-matched to this role.
Hiring manager — we find who's hiring.
Intro email — drafted to reach them directly.
Job highlights
- Lead cyber incident response engagements end-to-end.
- Coordinate cross-functional teams during critical events.
- Serve as the primary client contact during incidents.
- Drive rapid and effective incident response outcomes.
- Document all incident timelines and actions accurately.
About the role
Cyber Incident Manager
As a Cyber Incident Manager, you’ll be at the forefront of high-stakes cyber events, leading critical incident response efforts that protect organisations when it matters most. Acting as a trusted advisor to clients during their most challenging moments, you’ll bring clarity, structure, and decisive leadership to fast-moving situations - minimising impact, restoring operations, and driving successful outcomes.
At Solis, you’ll do this with the backing of a global cybersecurity business powered by real-world intelligence - drawing on millions of data points and thousands of incidents to deliver enterprise-grade, human-led protection, supported by deep visibility across the global threat landscape.
Key Responsibilities
- Lead end-to-end cyber incident response engagements from initial notification through to resolution and client offboarding
- Coordinate cross-functional response efforts across forensics, legal, PR, business resumption, and executive stakeholders to ensure a unified approach
- Act as the primary client contact during incidents, providing clear, timely updates and managing expectations in high-pressure situations
- Drive organisation and prioritisation of incident response activities to ensure rapid and effective outcomes
- Maintain accurate, detailed, and defensible documentation of incident timelines, actions taken, and outcomes
Skills, Knowledge & Expertise
- Strong decision-making and problem-solving skills, with the ability to remain calm and structured under pressure
- Excellent communication skills, with the ability to translate complex technical concepts into clear, actionable updates for non-technical stakeholders
- Ability to manage and de-escalate high-stress situations while working with diverse stakeholders
- Strong organisational skills and attention to detail across multiple concurrent incidents
- Solid technical understanding of cyber threats, attack vectors, and incident response methodologies
- Minimum 2 years’ experience in cybersecurity, ideally within incident response or a related field
- Hands-on experience with incident response tools such as EDR, SIEM platforms, and forensic collection/analysis tools
- Experience working in fast-paced or high-pressure environments requiring rapid decision-making
Key skills/competency
- Cyber Incident Response
- Incident Management
- Cybersecurity
- Risk Management
- Communication
- Problem-Solving
- Decision-Making
- Team Leadership
- Technical Acumen
- Client Management
Skills & topics
- Cyber Incident Manager
- Incident Response
- Cybersecurity
- SIEM
- EDR
- Forensics
- Threat Intelligence
- Risk Management
- Security Operations
- IT Security
How to get hired
- Tailor your resume: Highlight your cybersecurity, incident response, and leadership experience. Use keywords from the job description.
- Craft a compelling cover letter: Emphasize your ability to handle high-pressure situations and communicate complex information clearly.
- Prepare for behavioural questions: Be ready to discuss past incident responses, decision-making under pressure, and stakeholder management.
- Showcase technical skills: Be prepared to discuss your experience with EDR, SIEM, and forensic tools.
- Understand Solis: Research Solis's global cybersecurity services and their approach to threat intelligence.
Technical preparation
Master SIEM and EDR tool functionalities.,Practice forensic data collection techniques.,Study common attack vectors and exploits.,Review incident response frameworks and playbooks.
Behavioral questions
Describe a high-pressure incident you managed.,How do you de-escalate tense stakeholder situations?,Explain a complex technical issue simply.,How do you prioritize tasks during chaos?
Frequently asked questions
- What is the primary role of a Cyber Incident Manager at Solis?
- The Cyber Incident Manager at Solis leads critical incident response efforts, acting as a trusted advisor to clients during high-stakes cyber events. They bring structure and leadership to fast-moving situations to minimize impact and restore operations.
- What technical skills are essential for the Cyber Incident Manager role at Solis?
- Essential technical skills include a solid understanding of cyber threats, attack vectors, and incident response methodologies. Hands-on experience with incident response tools like EDR and SIEM platforms, as well as forensic collection/analysis tools, is also crucial.
- How does Solis support its Cyber Incident Managers during client engagements?
- Solis supports its Cyber Incident Managers with the backing of a global cybersecurity business powered by real-world intelligence. This includes drawing on millions of data points and thousands of incidents to deliver enterprise-grade, human-led protection with deep visibility across the global threat landscape.
- What kind of experience is required for the Cyber Incident Manager position at Solis?
- A minimum of 2 years’ experience in cybersecurity, ideally within incident response or a related field, is required. Experience working in fast-paced or high-pressure environments demanding rapid decision-making is also a key requirement.
- How important are communication skills for this Cyber Incident Manager role at Solis?
- Communication skills are paramount. The role requires translating complex technical concepts into clear, actionable updates for non-technical stakeholders and managing client expectations effectively during high-pressure situations.
- What does Solis mean by 'end-to-end cyber incident response'?
- End-to-end incident response at Solis covers the entire lifecycle of a cyber event, from the initial notification through to the successful resolution of the incident and client offboarding, ensuring a comprehensive and thorough approach.