Incident Response Manager and Security Operations Team Lead
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, Security Management & Operations, IT Project Manager, Information Security & Data Protection
Incident Response Manager and Security Operations Team Lead
JOB SUMMARY
Under the direction of the Chief Information Security Officer, the Incident Response Manager & Security Operations Team Lead is responsible for leading the University's Security Operations and Incident Response functions in support of the University of Connecticut Information Security Office.
The Incident Response Manager works regularly with other senior members of the Information Security Office and is a member of the CISO’s security leadership team.
This position serves in a dual capacity as both a technical subject matter expert and the supervisor of a functional team. The incumbent provides strategic and operational leadership for the University's cybersecurity monitoring, detection, investigation, response, and recovery capabilities while actively participating in complex incident response activities and advanced security operations.
The Incident Response Manager leads a team of cybersecurity professionals responsible for continuous security monitoring, incident response, threat detection, digital forensics, and operational security engineering. The position establishes operational priorities, develops procedures and playbooks, manages security technologies, and coordinates enterprise response activities across the University’s academic, research, and administrative environments.
The manager works collaboratively with University leadership, Information Technology Services, legal counsel, privacy, compliance, research, public safety, and external partners to ensure timely, effective, and coordinated response to cybersecurity incidents.
The Incident Response Manager is responsible for continuously improving the University's incident response maturity and operational security capabilities through process improvement, technology implementation, threat-informed defense, automation, metrics, and staff development.
SALARY
- Incident Response Manager and Security Operations Team Lead (IT Team Lead 2 – M7): $95,066 to $123,585
Note:
All minimum qualifications must be met to be eligible for consideration. Salary will be commensurate with experience within the established range.
BENEFITS INCLUDE
- Defined contribution with employer match or defined benefit program retirement options
- Excellent and affordable healthcare options
- 22 paid vacation days per year, paid sick leave, and 13 paid holidays
- Employee and dependent tuition waivers
- A highly desirable work environment and work-life balance
DUTIES AND RESPONSIBILITIES
- Lead the University's Security Operations and Incident Response programs.
- Direct day-to-day operations of the Security Operations team, including prioritization of work, workload management, coaching, mentoring, and performance management.
- Serve as the incident commander for significant cybersecurity incidents, coordinating technical response activities across multiple University departments. Operates as a primary member of the UConn Incident Response Plan, acting as functional lead for Executive Response Team (ERT) meetings and activities.
- Personally participate in complex incident investigations, threat hunting, malware analysis, digital forensics, containment, eradication, recovery, and post-incident reviews.
- Develop, maintain, and continuously improve incident response plans, operational procedures, playbooks, and technical standards.
- Manage the identification, detection, and response to alerts and events through the University's security monitoring capabilities including SIEM, SOAR, EDR/XDR, threat intelligence, logging, and related security technologies.
- Lead continuous improvement of detection engineering, alert tuning, automation, and operational metrics.
- Coordinate security operations with infrastructure, networking, cloud, identity management, application, and research computing teams.
- Oversee threat detection engineering, use case development, and security content management.
- Manage relationships with incident response vendors, managed security providers, law enforcement, and external cybersecurity organizations.
- Coordinate regulatory reporting and support investigations involving compliance, legal, privacy, and research security requirements.
- Develop operational dashboards, metrics, executive reporting, and key performance indicators for security operations and incident response.
- Lead tabletop exercises, incident simulations, and operational readiness activities.
- Participate in security architecture reviews to improve monitoring and incident response capabilities.
- Develop staffing plans, training plans, career development activities, and succession planning for Security Operations personnel.
- Manage operational projects related to security monitoring, automation, response technologies, and operational maturity.
- Maintain awareness of emerging threats, adversary tactics, vulnerabilities, and industry best practices.
- Participate in after-hours incident response and operational escalations as required.
- Other related duties as assigned.
RELATED SKILLS AND…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).