Cybersecurity Incident Manager - Lead
Job Description
The Cybersecurity Incident Manager - Lead role within USAA’s Cyber Threat Monitoring and Response (CTMR) team coordinates cybersecurity incident response across the full incident lifecycle. This position serves as Incident Commander during active incidents, leads investigations into security anomalies, threats, and breaches, and strengthens detection and response operations over time.
Key Responsibilities
- Provide domain expertise as a subject matter expert, influencing and leading security efforts across the Information Security department and the enterprise.
- Lead research and analysis of emerging information security vulnerabilities, threats, exploits, trends, and intelligence; share intelligence with the enterprise and collaborate with external organizations in the intelligence community.
- Serve as subject matter expert to lead and improve vulnerability management, security configuration assessment, and/or penetration testing programs.
- Develop analysts through training and structured knowledge sharing activities.
- Monitor internal and external networks, systems, and applications for advanced security anomalies and events, including suspicious behavior and security breaches; train analysts in incident detection and response.
- Lead and improve the incident response program.
- Lead and respond to cyber incidents by performing detailed analysis with complex security tools to identify root cause and impact, including use of experience across forensics, networking, servers, and coding, to determine malicious actor tactics, techniques, and procedures.
- Act as leader for cyber incidents.
- Incorporate findings from incident response activities to improve detection capabilities, operational processes, security controls, and the overall program.
- Prepare and deliver written and verbal briefs with recommendations to senior leadership and external parties regarding latest threats, alerts, incidents, and improvements.
- Drive quality work across escalated, unique issues as the primary resource for cross-functional team members.
- Maintain expert-level knowledge of USAA Information Security standards and industry best practices, frameworks, and relevant laws and regulations.
- Ensure risks tied to business activities are identified, measured, monitored, and controlled in line with risk and compliance policies and procedures.
Additional responsibility: May testify as an expert witness in court.
Requirements
- Bachelor's degree OR 4 years of relevant education and/or experience.
- 8 years of related experience in Information Security, Cybersecurity and/or Information Technology with a security focus, including accountability for complex tasks and/or projects.
- 6 years of related experience in one or more of the following domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security.
- Expert level business acumen across business operations, risk management, industry practices, and emerging trends.
- Experience performing security reviews to identify gaps and generate recommendations for risk mitigation strategies.
- Experience investigating potentially malicious activity to determine exploited weaknesses, exploitation methods, and effects on systems and information.
Benefits
- Comprehensive medical, dental and vision plans
- 401(k)
- Pension
- Life insurance
- Parental benefits
- Adoption assistance
- Paid time off program with paid holidays plus 16 paid volunteer hours
- Various wellness programs
- Career path planning and continuing education
Location, Schedule, and Compensation
- Work location: San Antonio, TX (hybrid)
- Schedule: In the office 4 days per week
- Based in: San Antonio, TX, Plano, TX, Phoenix, AZ, or Colorado Springs, CO
- Compensation range: $142,320 - $273,930 per year
Relocation and Sponsorship
- Relocation assistance: Not available for this position
- USAA visa sponsorship: Not provided for this role
Application Information
- Applications are accepted on an ongoing basis.
- The posting remains open until the position is filled.
- Candidates are encouraged to apply the same day they view this posting.