Cyber Senior Manager - Incident Response
Deloitte - San Antonio, TX
Apply NowJob Description
Senior Manager - Cyber Incident Response Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Position Summary As a Senior Manager in Deloitte's Cyber Defense & Resilience practice, you will lead complex, multi-workstream incident readiness, response, and recovery programs for enterprise clients. You will shape solution strategy, oversee delivery quality, and advise C-suite and board-level stakeholders through high-impact cyber incidents and broader business disruptions. You will steward Deloitte's Crisis & Incident Response and Technical Resilience offerings, driving innovation, repeatability, and fit-for-purpose architectures aligned to leading standards and technologies. You will also build high-performing teams, develop talent, and contribute to eminence and market growth. Recruiting for this role ends on June 01, 2026 Work you'll do As a Senior Manager on the Cyber Defense & Resilience team, you will be responsible for... + Leading end-to-end incident response programs and large-scale engagements, including readiness assessments, tabletop exercises, investigations, containment, eradication, and recovery, ensuring quality and executive-level communications. + Designing and operationalizing enterprise crisis and incident response capabilities aligned to NIST, ISO/IEC 27001/27035, and CIS controls, integrating technologies such as security information and event management, security orchestration, automation and response, and endpoint detection and response. + Overseeing multi-disciplinary teams across geographies; setting delivery standards, reviewing work products, and instituting continuous improvement and metrics for effectiveness, speed, and resilience outcomes. + Shaping Deloitte Cyber offerings for Crisis & Incident Response and Technical Resilience; creating methods, assets, and accelerators; contributing to thought leadership, training, and community of practice. + Partnering with client executives to define strategy, prioritize investments, and manage risk; supporting account growth through solutioning, estimates, and participation in pursuits. The team Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions. Required Qualifications + 15+ years delivering Cyber Defense and Resilience services, including incident response leadership across readiness, response, and recovery for enterprise clients. + 4+ years overseeing multi-workstream incident response or cyber transformation programs with responsibility for scope, budget, timeline, and quality. + 5+ years implementing or assessing incident response capabilities aligned to National Institute of Standards and Technology (NIST), International Organization for Standardization (ISO/IEC 27001/27035), and Center for Internet Security (CIS) controls. + 5+ years managing distributed teams, including performance management and coaching for practitioners. + Bachelor's degree (BS or BA). + Limited immigration sponsorship may be available. + Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve. Preferred: + 5+ years leading executive communications during cyber incidents, including situation reports, board updates, and post-incident reporting. + Experience integrating or operating security information and event management (e.g., Splunk), security orchestration, automation and response (e.g., Cortex XSOAR), and endpoint detection and response (e.g., CrowdStrike) across incident workflows. + Experience designing and running enterprise crisis simulations and tabletop exercises for executive and technical teams. + One or more certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Global Information Assurance Certification (GIAC) incident response track (e.g., GCFR, GCIH), or Certified Business Continuity Professional (CBCP). + Experience contributing to sales/origination or account growth, including solutioning, estimation, and statement of work development. + Experience with sector-specific regulations impacting incident response and resilience, such as Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI DSS), or North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP). + Previous consulting or
Created: 2026-03-09