×
Register Here to Apply for Jobs or Post Jobs. X

Lead, Cyber Incident Coordination

Job in Eagan, Dakota County, Minnesota, USA
Listing for: Refinitiv
Full Time position
Listed on 2026-09-12
Job specializations:
  • IT/Tech
    Cybersecurity, IT Project Manager
Salary/Wage Range or Industry Benchmark: 118400 - 219800 USD Yearly USD 118400.00 219800.00 YEAR
Job Description & How to Apply Below

Lead, Cyber Incident Coordination Enterprise Security Incident Management (ESIM)

Thomson Reuters' Information Security Risk Management team is seeking a Lead, Cyber Incident Coordination to help mature and improve enterprise incident management capabilities. This is a coordination and process‑focused role rather than a hands‑on technical forensics role. The Lead, Cyber Incident Coordination will help direct and organize the response to major cyber incidents, ensuring teams remain aligned, actions are tracked, communications are clear, and business impact is minimized.

In this role, you will serve as a key point of contact during significant security events. You will support the Director, Cyber Incident Management, in driving timely and effective incident response activities; facilitate coordination among technical and business stakeholders; maintain incident records; manage communications and reporting; and ensure corrective actions are completed following an incident. The role reports directly to the VP of Cyber Defense and works closely with the Director, Cyber Incident Management, who leads the ESIM function.

Key Responsibilities
  • Coordinate cyber incident management activities throughout the full incident lifecycle, from activation of cross‑functional partners through incident closure.
  • Facilitate incident bridges, command calls, and working sessions by maintaining structure, tracking decisions, assigning owners and timelines, and ensuring stakeholders understand their roles and the path to resolution.
  • Support incident management calls chaired by the Chief Information Security Officer by documenting action items, confirming ownership and deadlines, and tracking actions through completion.
  • Coordinate smaller working groups formed during incidents and provide visibility into their tasks, owners, progress, and dependencies.
  • Own and maintain the incident record, including timestamped observations, actions, contacts, decisions, and other relevant documentation.
  • Prepare and manage incident collateral, including executive communications, status reports, fact summaries, and materials required to support notification or disclosure obligations.
  • Deliver clear written and verbal updates to executive and business stakeholders throughout the incident lifecycle.
  • Lead post‑incident reviews by reconstructing timelines, identifying detection gaps, response delays, and communication breakdowns, and translating findings into corrective actions with accountable owners.
  • Track long‑term remediation activities and partner with risk management and technical teams to ensure complex issues are resolved after incident closure.
  • Design and facilitate two executive‑level tabletop exercises annually, including scenario development, timed injects, facilitator and observer materials, after‑action reports, and improvement plans.
  • Support assessment of incident management and response capabilities against recognized frameworks and partner with security teams to drive cross‑functional process improvements.
  • Maintain ESIM documentation, including SharePoint sites, incident records, runbooks, escalation lists, contact lists, and exercise materials.
  • Track and report performance measures that demonstrate improvement in areas such as corrective action closure rates and repeat incident rates.
  • Participate as part of a 24x7 global incident response team on an escalation basis for major incidents, including off‑hours or weekend support as needed.
Required Qualifications
  • Bachelor's degree or equivalent relevant experience.
  • Three or more years of experience supporting or leading processes, programs, or operations within Information Technology, Information Security, risk management, or a related field.
  • Experience participating in or facilitating…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary