Cyber Security Incident Response Lead
Listed on 2026-09-20
-
IT/Tech
Cybersecurity
Staples Digital Solutions is strengthening its cyber defense capabilities, and we’re looking for a senior technical incident response professional to help protect our associates, customers, data, and enterprise technology environment. This role sits within Cyber Security and partners closely with Security Operations, Infrastructure, Cloud, Identity, Legal, Privacy, Risk, Human Resources, and other teams to respond to complex and high-impact cybersecurity events.
Based in Framingham, MA, this opportunity reports to the Director of Security Operations and operates as a senior individual contributor with meaningful influence across the enterprise.
As a Cyber Security Incident Response Lead, you’ll serve as a senior technical escalation resource for significant cybersecurity incidents across Staples. You’ll lead hands‑on investigation and response activities across endpoint, identity, cloud, network, email, and security telemetry to determine threat scope, business impact, root cause, and recommended response actions. You’ll also help mature the incident response program by improving playbooks, exercises, metrics, processes, threat‑hunting practices, detection recommendations, and automation opportunities.
Role requires the incumbent to work at our Framingham, MA facility but we are open to candidates that are willing to relocate to the area. We will also consider providing relocation assistance.
What you’ll be doing :- Conduct complex cybersecurity investigations from initial escalation through containment, eradication, recovery, and post-incident review.
- Analyze endpoint, identity, cloud, network, email, and log‑based telemetry to identify attacker activity, determine incident scope, and assess potential impact.
- Provide senior technical guidance during significant incidents in partnership with SOC Leads and Managers.
- Coordinate response activities across Cyber Security, Infrastructure, Cloud, Identity, Legal, Privacy, GRC, Human Resources, external partners, and other business and technology teams.
- Develop and continuously improve incident response plans, investigative procedures, escalation processes, playbooks, exercises, metrics, and supporting documentation.
- Conduct proactive threat hunting based on threat intelligence, vulnerabilities, anomalous activity, and observed adversary techniques.
- Support insider risk investigations involving suspicious user behavior, misuse of access, data loss, or potentially malicious internal activity.
- Document investigation findings, lessons learned, recurring risks, and improvement opportunities from post‑incident reviews.
- Partner with Detection Engineering, Threat Intelligence, and security technology teams to improve detection coverage, investigative capabilities, and automation.
- Participate in an on‑call escalation rotation for significant cybersecurity incidents requiring senior technical expertise.
- Advanced technical investigation, analytical, and problem‑solving skills.
- Sound technical judgment and the ability to make recommendations using incomplete or evolving information.
- Ability to support complex cybersecurity incidents calmly and effectively under pressure.
- Strong written and verbal communication skills, including the ability to translate technical findings into clear business risk considerations and recommended actions.
- Strong collaboration skills across technical and non‑technical teams.
- Curiosity and initiative to identify improvements within the incident response discipline.
- Strong understanding of evolving attacker behaviors, techniques, and technologies.
- Discretion and sound judgment when handling sensitive investigations, including potential insider risk matters.
- Ability to participate in an on‑call escalation rotation for…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).