Hubinternational
Manager, Security Incident Response
Chicago, IL
Sponsorship not specified$130k-$150kDetected 11 hours ago
PythonBashPowerShellAWSGCPAzureCloud PlatformsOAuthCybersecuritySIEMSOARDetection EngineeringIncident ResponseAccessibilityM&ATCP/IPDNSFirewallLeadershipCollaborationAdaptability
> stay_score
odds of building a lasting career here
33Unrated
Cap-exempt (no lottery)0
Sponsors this role0
Entry-level history0
PERM / green-card track0
Lottery odds (Level III)83
Fits your clock70
No strong sponsorship signal in the public record yet. In the full product we resolve the exact legal entity and show its filing history with a confidence score — treat as unverified until then.
Lottery odds assume a STEM candidate.
Personalize to your clock →> community_outcomes
No reports yet — be the first to help the next applicant.
About the role
- We believe in protecting and supporting the aspirations of individuals, families, and businesses.
- The Manager ensures investigations are conducted with sound forensic methodology, including log and audit-trail analysis across cloud and on-premises platforms, accurate scoping of impacted systems and accounts.
- Do you thrive in a supportive and client focused work environment?
Requirements
- 5-7 years of relevant experience
- Required Travel: Negligible
Skills
- Bachelor's degree in technology or applicable experience.
- 10+ Years of experience with programming/scripting languages (Powershell, python, shell scripting)
Compensation
- The expected salary range for this position is $ 130,000 to $150,000 and will be impacted by factors such as the successful candidate's skills, experience and working location, as well as the specific position's business line, scope and lev
Company info
- At HUB International, we are a team of entrepreneurs.
- We help our clients evaluate their risks and develop solutions tailored to their needs.
- We believe in empowering our employees to learn, grow, and make a difference.
- Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence.
- HUB is a global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, persnal insurance, retirement, and private wealth management products and services.
- With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions
- Job Description
- In this role, you will manage the Security Incident Response team; for detecting and identifying cyber threats, as well as containment and remediation of these threats.
- This role owns the full incident response lifecycle-detection, triage, containment, eradication, recovery, and post-incident review-and is responsible for building a scalable Incident Response function that pairs reactive response capability with proactive detection engineering and threat hunting.
- Objectives of this Role
- Manages and is responsible for the successful completion of all tasks in assigned projects.
- Lead and manage a Security Incident Response Team focused on responding to security threats and maintaining HUB's critical threat detection and response suite of security applications.
- Available 24/7 for any critical incidents that may arise that require immediate resolution, providing leadership and direction to a multi-disciplinary IT team.
- Work with IT teams to ensure managed environments and procedures comply with defined corporate security policies.
- Mentor and develop team members to help foster individuals' professional growth.
- Engage with teams to practice continuous improvement in processes and tooling.
- Supervises assigned operations team members and performs personnel actions including hiring, individual goal tracking, training, performance evaluation.
- Maintains current knowledge of relevant technology, bringing forth ideas for modernization and improvement.
- Identify potential technical issues and assist in engineering possible solutions
- Engage with management regularly with reports on project status, activities, and achievements
- Lead "Technical Archeology" efforts (Platform and System Decomposition), in respect to gaps identified during incident response activities.
- Lead the creation of security incident response processes and playbooks that are scalable, consistent, repeatable, and supportable.
- Direct forensic investigations of security incidents, including analysis of cloud audit logs (e.g., Microsoft 365 Unified Audit Log), endpoint and network telemetry, and identity activity, to identify indicators of compromise, establish attack timelines, and determine scope of impact.
- Design and maintain a tiered escalation framework and on-call rotation so that incidents are routed to the appropriate analyst and management level based on severity and business impact.
- Drive maturity of the Incident Response and Detection Engineering functions against a KPI-based roadmap, tracking metrics such as mean time to detect (MTTD), mean time to respond (MTTR), alert triage volume, and case closure rates.
- Balance the team's dual-track structure of reactive Incident Response and proactive Detection Engineering/threat hunting, ensuring each track has clear ownership, workflows, and staffing.
- Conduct post-incident reviews and root-cause analysis to capture lessons learned, close process gaps, and feed findings back into playbooks and detection content.
- Daily and Monthly Responsibilities
Apply directly at Hubinternational →Create a free account for alerts like thisView Hubinternational immigration profile
This listing is sourced directly from Hubinternational's careers page and normalized into a canonical job model.