Incident Coordinator/SOC Liaison/Remote in Sandy Springs
Newnan, Coweta County, Georgia, 30263, USA
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, IT Support, Security Management & Operations, Systems Analyst
Job Description
Our client, a global fintech leader with amazing culture, is hiring for a contract Security Incident Coordinator (internal job title: Information Security Analyst III). This is a fully remote position with EST hours.
This individual will join the Security Operations Center (SOC) within Threat Operations and will serve as a coordination and visibility function for critical incidents across the organization. This acts as the go-to liaison for those high-severity incidents, helping organize activities, track milestones, maintain documentation, and communicate updates to leadership and cross-functional stakeholders.
This is not a highly hands-on technical role and is more closely aligned with a light technical project management and incident coordination. This individual will help drive incident commanders toward resolution without directly owning the technical investigation or challenging the technical decisions of subject-matter experts.
Key Responsibilities:Incident Coordination and Task Management
- Serve as the primary coordinator for major cybersecurity, trust & safety, and fraud incidents.
- Manage approximately 1–3 incidents at a time, with an emphasis on the highest-severity incidents.
- Organize tasks, schedules, approvals, dependencies, and required "go-aheads" using an incident tracker.
- Track incident progress and milestones across the full lifecycle.
- Help incident commanders drive incidents toward resolution.
- Maintain clear communication across involved teams and stakeholders in Service Now Security Incident Response (SIR).
- Act as the primary liaison and external-facing point of contact for high-severity SOC incidents.
- Coordinate with the appropriate subject-matter experts rather than independently owning domains such as banking or routing systems.
- Coordinate the full incident lifecycle, including Containment, Eradication, Recovery, Closure
- Ensure containment is validated against Intuit's control-testing standard before an incident is marked resolved.
- Support leadership commanders by providing visibility into critical incidents and their current status.
- Ensure incident actions, decisions, milestones, and outcomes are documented accurately.
- Prepare regular incident updates, summaries, and milestone communications for leadership channels.
- Provide clear, comprehensive reporting for operational stakeholders, senior leadership, and executives.
- Explain incident details, collective findings, actions, and status updates to executives and other non-technical audiences.
- Translate technical information into clear business-level communications and translate business needs back to technical teams.
- Serve as the "face" of high-severity incidents for stakeholders outside the SOC.
- Communicate confidently when asked to describe incident status, collective ideas, or recommended next steps.
- Provide clear documentation and updates to internal partners, including: IT, Legal, Compliance, Customer Support, plus reinforce adherence to established SOC processes and documentation standards.
Skills and Experience:
- Demonstrated ability to manage multiple concurrent incident tasks and stakeholders in a high-pressure environment while maintaining accuracy and composure.
- Approximately 1–2 years of experience in security operations or a related security environment.
- Solid working knowledge of incident response procedures across cybersecurity, trust & safety, and fraud contexts.
- Experience in incident coordination, security operations, technical project management, or a closely related field.
- Strong organizational, written, and verbal communication skills.
- Ability to communicate confidently with executives and senior leadership.
- Ability to explain technical details to non-technical audiences and communicate business requirements to technical teams.
- Experience with Service Now Security Incident Response (SIR) or a comparable ITSM/SIR platform strongly .
- Comfort working across Insider Risk, Escalations, and DFIR functions without directly owning their technical domains.
- Ability to understand when an issue should be directed to the appropriate subject-matter expert.
- Crowd Strike and Splunk exposure . The ideal candidate should be able to review a Splunk screen and understand the general meaning of the logs and information displayed.
- Ability to work effectively as a coordinator and liaison rather than as the primary hands-on technical…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).