Cyber Security Incident Response Lead

Posted 7 Days Ago
Be an Early Applicant
Framingham, MA, USA
In-Office
Senior level
Retail
The Role
Lead complex enterprise cybersecurity investigations from escalation through recovery, coordinating containment, eradication, and post-incident reviews. Analyze endpoint, identity, cloud, network, email, and log telemetry; conduct threat hunting and insider-risk investigations; and improve incident response plans, playbooks, metrics, detection coverage, and automation. Provide senior technical guidance, communicate business risk, coordinate cross-functional response teams, and participate in an on-call escalation rotation.
Summary Generated by Built In

Staples Digital Solutions is strengthening its cyber defense capabilities, and we’re looking for a senior technical incident response professional to help protect our associates, customers, data, and enterprise technology environment. This role sits within Cyber Security and partners closely with Security Operations, Infrastructure, Cloud, Identity, Legal, Privacy, Risk, Human Resources, and other teams to respond to complex and high-impact cybersecurity events. Based in Framingham, MA, this opportunity reports to the Director of Security Operations and operates as a senior individual contributor with meaningful influence across the enterprise.


As a Cyber Security Incident Response Lead, you’ll serve as a senior technical escalation resource for significant cybersecurity incidents across Staples. You’ll lead hands-on investigation and response activities across endpoint, identity, cloud, network, email, and security telemetry to determine threat scope, business impact, root cause, and recommended response actions. You’ll also help mature the incident response program by improving playbooks, exercises, metrics, processes, threat-hunting practices, detection recommendations, and automation opportunities.


Role requires the incumbent to work at our Framingham, MA facility but we are open to candidates that are willing to relocate to the area.  We will also consider providing relocation assistance. 


What you’ll be doing:

  • Conduct complex cybersecurity investigations from initial escalation through containment, eradication, recovery, and post-incident review.
  • Analyze endpoint, identity, cloud, network, email, and log-based telemetry to identify attacker activity, determine incident scope, and assess potential impact.
  • Provide senior technical guidance during significant incidents in partnership with SOC Leads and Managers.
  • Coordinate response activities across Cyber Security, Infrastructure, Cloud, Identity, Legal, Privacy, GRC, Human Resources, external partners, and other business and technology teams.
  • Develop and continuously improve incident response plans, investigative procedures, escalation processes, playbooks, exercises, metrics, and supporting documentation.
  • Conduct proactive threat hunting based on threat intelligence, vulnerabilities, anomalous activity, and observed adversary techniques.
  • Support insider risk investigations involving suspicious user behavior, misuse of access, data loss, or potentially malicious internal activity.
  • Document investigation findings, lessons learned, recurring risks, and improvement opportunities from post-incident reviews.
  • Partner with Detection Engineering, Threat Intelligence, and security technology teams to improve detection coverage, investigative capabilities, and automation.
  • Participate in an on-call escalation rotation for significant cybersecurity incidents requiring senior technical expertise.

What you bring to the table:

  • Advanced technical investigation, analytical, and problem-solving skills.
  • Sound technical judgment and the ability to make recommendations using incomplete or evolving information.
  • Ability to support complex cybersecurity incidents calmly and effectively under pressure.
  • Strong written and verbal communication skills, including the ability to translate technical findings into clear business risk considerations and recommended actions.
  • Strong collaboration skills across technical and non-technical teams.
  • Curiosity and initiative to identify improvements within the incident response discipline.
  • Strong understanding of evolving attacker behaviors, techniques, and technologies.
  • Discretion and sound judgment when handling sensitive investigations, including potential insider risk matters.
  • Ability to participate in an on-call escalation rotation for significant cybersecurity incidents.

What’s needed- Basic Qualifications:

  • Bachelor’s degree in Computer Science, Information Security, a related field or equivalent work experience.
  • 7+ years of cybersecurity experience, including incident response, digital forensics, threat hunting, detection engineering, or Security Operations.
  • Experience conducting complex cybersecurity investigations in large enterprise environments.
  • Experience developing or maintaining incident response plans, procedures, playbooks, exercises, metrics, or supporting processes.
  • Experience conducting post-incident reviews, root cause analysis, or lessons-learned documentation.
  • Experience coordinating technical response activities across multiple technology and business teams.

What’s needed- Desired Qualifications:

  • Experience within larger distributed enterprise environments, ideally retail and/or e-commerce.
  • Advanced technical training or relevant cybersecurity certifications such as GCIH, GCFA, GCFE, GNFA, CISSP.
  • Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Endpoint, or Microsoft Entra ID.
  • Experience with SOAR platforms and automated incident response workflows.
  • Hands-on experience investigating endpoint, identity, cloud, network, email, or log-based security telemetry.
  • Hands-on experience using SIEM, EDR/XDR, identity security, cloud security monitoring, or security automation technologies.
  • Experience conducting enterprise threat hunting or developing detection content.
  • Experience supporting insider risk, user behavior, data loss, or other user-focused security investigations.
  • Experience investigating identity-based or cloud-based attacks.
  • Experience responding to ransomware, credential compromise, business email compromise, insider threats, data theft, or supply-chain incidents.
  • Knowledge of cybersecurity incident response requirements, including PCI DSS and applicable privacy requirements.

What’s needed- Desired Qualifications:

  • Advanced technical training or relevant cybersecurity certifications such as GCIH, GCFA, GCFE, GNFA, CISSP.
  • Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Endpoint, or Microsoft Entra ID.
  • Experience with SOAR platforms and automated incident response workflows.
  • Experience conducting enterprise threat hunting or developing detection content.
  • Experience supporting insider risk, user behavior, data loss, or other user-focused security investigations.
  • Experience investigating identity-based or cloud-based attacks.
  • Experience responding to ransomware, credential compromise, business email compromise, insider threats, data theft, or supply-chain incidents.
  • Knowledge of cybersecurity incident response requirements, including PCI DSS and applicable privacy requirements.
  • Experience within large retail, e-commerce, or distributed enterprise environments.

We Offer:

  • Inclusive culture with associate-led Business Resource Groups
  • 22 days of PTO and Holiday Schedule (7 observed paid holidays + 1 floating holiday)
  • Online and Retail Discounts, Company Match 401(k), Physical and Mental Health Wellness programs, and more!

The salary range represents the expected compensation for this role at the time of posting. The specific base pay may be influenced by a variety of factors to include the candidate's experience, skill set, education, geography, business considerations, and internal equity. In addition to base pay, this role may be eligible for bonuses, or other forms of variable compensation.

About UsStaples is an Equal Opportunity Employer.  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, age, national origin, protected veteran status, disability, or any other basis protected by federal, state, or local law.

Skills Required

  • Bachelor's degree in Computer Science, Information Security, a related field, or equivalent work experience
  • 7+ years of cybersecurity experience, including incident response, digital forensics, threat hunting, detection engineering, or Security Operations
  • Experience conducting complex cybersecurity investigations in large enterprise environments
  • Experience developing or maintaining incident response plans, procedures, playbooks, exercises, metrics, or supporting processes
  • Experience conducting post-incident reviews, root cause analysis, or lessons-learned documentation
  • Experience coordinating technical response activities across multiple technology and business teams
  • Ability to participate in an on-call escalation rotation for significant cybersecurity incidents
  • Experience in larger distributed enterprise environments, ideally retail or e-commerce
  • Advanced technical training or cybersecurity certifications such as GCIH, GCFA, GCFE, GNFA, or CISSP
  • Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Endpoint, or Microsoft Entra ID
  • Experience with SOAR platforms and automated incident response workflows
  • Hands-on experience investigating endpoint, identity, cloud, network, email, or log-based security telemetry
  • Experience using SIEM, EDR/XDR, identity security, cloud security monitoring, or security automation technologies
  • Experience conducting enterprise threat hunting or developing detection content
  • Experience supporting insider risk, user behavior, data loss, or user-focused security investigations
  • Experience investigating identity-based or cloud-based attacks
  • Experience responding to ransomware, credential compromise, business email compromise, insider threats, data theft, or supply-chain incidents
  • Knowledge of cybersecurity incident response requirements, including PCI DSS and applicable privacy requirements

Staples Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Staples and has not been reviewed or approved by Staples.

  • Wellbeing & Lifestyle Benefits Wellbeing offerings are described as broad, including wellness reimbursements, emotional support and coaching, legal services, identity theft protection, and pet insurance. Employee discounts and select on-site amenities are also positioned as meaningful add-ons beyond basic coverage.
  • Leave & Time Off Breadth Time-off provisions are presented as relatively expansive, including paid time off, company-recognized holidays, and a personal or flexible holiday option. Vacation that grows with tenure and PTO flexibility are highlighted as valued elements.
  • Inclusive Benefits Coverage Healthcare benefits explicitly include gender-affirming care alongside medical, dental, and vision coverage. Family and caregiver programs also include support that references LGBTQ+ considerations and broader life-stage needs.

Staples Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Framingham, MA
Year Founded: 1986

What We Do

For nearly 40 years, Staples has been a trusted leader in delivering end-to-end workplace solutions for consumers and businesses of all sizes across a broad range of industries. The company provides a comprehensive portfolio of products, strategic solutions, and services including print and marketing, shipping, technology, and travel. Its specialized assortment includes high-quality office supplies, janitorial products, technology, furniture, and breakroom essentials, all supported by best-in-class supply chain capabilities and a dedicated team of experts committed to making the workday easier. Headquartered near Boston, Massachusetts, Staples operates throughout North America via direct B2B sales, e-commerce, and more than 900 retail stores. To learn more, visit your local U.S. Staples store, download the Staples app, explore Staples.com or StaplesBusiness.com, or follow @Staples on social media.

Similar Jobs

PNC Bank Logo PNC Bank

Software Engineer

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
86K-158K Annually

MetLife Logo MetLife

Sr. Relationship Manager

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
155K-190K Annually

MetLife Logo MetLife

Customer Care Advocate AMS - Virtual - 9.28.26 - 19200

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
42K-42K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

VP, Sr Director, Finance Technology

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Hybrid
2 Locations
40000 Employees
233K-420K Annually

Similar Companies Hiring

Tastewise Thumbnail
Artificial Intelligence • Big Data • Food • Retail • Software • Generative AI • Big Data Analytics
NYC, NYC
120 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account