NMS
Director of Incident Response
Dallas, TX · Director
No sponsorship$61k-$800kDetected 29 days ago
AWSGCPAzureCloud PlatformsKubernetesPlatform EngineeringSIEMSOC OperationsDetection EngineeringIncident ResponseJiraConfluenceSupply ChainPerformance ManagementResearchLeadershipCommunication
About the role
- You will stand up the IR function from the ground up: playbooks, on-call rotations, tooling integration, forensic capability, and the team itself.
- You will operate as the senior IR authority across Security Engineering, Platform Engineering, Data Center Operations, and customer-facing technical teams.
Responsibilities
- Own major incident command for all Sev-0 and Sev-1 events, security and operational, including customer-facing communications and regulatory notification decisions
- Develop detection-to-containment runbooks mapped to MITRE ATT&CK techniques relevant to HPC and cloud tenancy threats: credential abuse (T1078), lateral movement via Kubernetes and scheduler primitives (T1610, T1613), data exfiltration over research network egress (T1041, T1567), and supply chain compromise in scientific software pipelines (T1195)
- Drive root cause analysis to engineering remediation with measurable closeout SLAs, not written reports that sit on a Confluence page
- Build and maintain the Known Error Database, runbook library, and tabletop exercise program with scheduled red team, customer-triggered, and infrastructure failure scenarios
- Partner with Security Engineering on detection engineering feedback loops: every incident either validates an existing detection, triggers a new one, or exposes a detection gap that becomes a tracked engineering item
- Own executive and board-level incident reporting, including quarterly trend analysis, regulatory and contractual incident disclosures, and customer trust reporting for enterprise accounts
- Co-own business continuity and disaster recovery testing with Platform and DC Operations, ensuring IR plans integrate cleanly with BCP/DR runbooks
- Develop detection-to-containment runbooks mapped to
Requirements
- 10+ years in security operations or incident response, with at least 5 years running major incident response in high-availability, multi-tenant, or mission-critical infrastructure environments
- Hands-on experience with Jira Service Management, PagerDuty or equivalent, and at least one enterprise SIEM or XDR platform in a production IR context
- Comfort operating in a pre-scale organization where tooling, process, and team do not yet exist and must be designed before they can be run
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Nice to have
- GCIH, GCFA, GCFR, or equivalent hands-on IR certification
- ITIL 4 Foundation or Practitioner certification
Skills
- Establish forensic readiness across bare-metal
Compensation
- $61k-$800k
Benefits
- Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.
- Company-Paid Lunch Stipend: Lunch is provided via GrubHub
- Time Off: 25 days of Paid Time Off plus 12 company holidays
- Build the IR function end to end: staffing model, 24/7 coverage plan, severity matrix, escalation tree, retainer relationships, and tooling stack aligned to NIST SP 800-61r2 phase structure
- Instrument the IR function with hard metrics: MTTD, MTTA, MTTC, MTTR by severity and incident class, recurrence rate, playbook coverage percentage, and on-call load distribution
- 5+ years leading IR or SOC teams, including direct accountability for hiring, performance management, and 24/7 operational coverage
Company info
- Lunch is provided via GrubHub
Equal opportunity
- NORTHMARK STRATEGIES LLC IS AN EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER.
- THE COMPANY'S POLICY IS NOT TO DISCRIMINATE AGAINST ANY APPLICANT OR EMPLOYEE BASED ON RACE, COLOR, RELIGION, NATIONAL ORIGIN, GENDER, AGE, SEXUAL ORIENTATION, GENDER IDENTITY OR EXPRESSION, MARITAL STATUS, MENTAL OR PHYSICAL DISABILITY, AND GENETIC INFORMATION, OR ANY OTHER BASIS PROTECTED BY APPLICABLE LAW.
- THE FIRM ALSO PROHIBITS HARASSMENT OF APPLICANTS OR EMPLOYEES BASED ON ANY OF THESE PROTECTED CATEGORIES.
Visa & Work Authorization
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
This listing is sourced directly from NMS's careers page and normalized into a canonical job model.