Cybersecurity Incident Manager - Lead

Posted Yesterday
Be an Early Applicant
4 Locations
In-Office
142K-274K Annually
Senior level
Insurance
The Role
Leads cybersecurity incident response as an Incident Commander, coordinating cross-functional teams, investigating threats, analyzing root cause and impact, and communicating with senior leadership. Drives incident response program maturity through improved playbooks, processes, training, metrics, detection capabilities, and after-action reviews. Also leads vulnerability management, security assessments, threat intelligence, analyst development, and response to complex threats including ransomware, insider attacks, data exfiltration, and cloud compromise.
Summary Generated by Built In

Why USAA?

At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.

Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.

We are proud to support active-duty military spouses. USAA roles may offer remote or hybrid flexibility for active-duty military spouses consistent with applicable policy and business needs.

The Opportunity

As a dedicated Cybersecurity Incident Manager - Lead, the candidate selected for this position serves as a Lead within the Cyber Threat Monitoring and Response (CTMR) team, responsible for leading and coordinating cybersecurity incident response activities throughout the incident lifecycle across security, technology, business, and third-party partner organizations. Acts as an Incident Commander during active cybersecurity incidents by establishing response objectives, maintaining situational awareness, coordinating cross-functional response teams, and communicating incident status, business impact, and response actions to stakeholders and senior leadership.


This role also supports the ongoing development and maturity of the Cyber Threat Operations Center by driving improvements to incident response processes, operating models, playbooks, training, metrics, and after-action review practices. The successful candidate will identify opportunities to enhance response effectiveness, operational readiness, and cyber resilience through continuous improvement, operational excellence, and the application of industry best practices.


Investigates, analyzes, and responds to security anomalies and events (e.g. suspicious behavior, attacks, and security breaches) within USAA's environments using a variety of cyber defense tools to detect and respond to threats. Conducts vulnerability, security configuration, and/or penetration testing assessments of systems and networks. Identifies cyber threats, analyzes operational impacts, and communicates to appropriate stakeholders. Stays current with latest information security threats, exploits, trends, and intelligence


We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ or Colorado Springs, CO. Relocation assistance is not available for this position.

 

What you'll do

  • Influences and leads efforts across the Information Security department and enterprise as a subject matter expert in their domain.
  • Leads research efforts and analysis of the latest information security vulnerabilities, threats, exploits, trends and intelligence. Shares intelligence with the enterprise. Collaborates in the Intelligence community with external organizations.
  • Serves as subject matter expert, leads, and improves the vulnerability management, security configuration assessment, and/or penetration testing programs.
  • Develops analysts through training and knowledge sharing activities.
  • Monitors internal and external networks, systems, and applications for advanced security anomalies and events (e.g.suspicious behavior attacks, and security breaches). Trains analysts in incident detection and response.
  • Leads and improves the incident response program.
  • Leads and responds to cyber incidents, performing detailed analysis using complex security tools to determine root cause and impact by using a broad range of demonstrated experience (e.g.forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures.
  • Acts as leader for cyber incidents.
  • May testify as expert witness in court.
  • Incorporates discoveries from the incident response process to substantially improve the existing detection capabilities, operational processes, security controls, and overall program.
  • Prepares and delivers written and verbal briefs with recommendations to senior leadership and external parties on latest threats, alerts, incidents, and improvements.
  • Drives and directs quality work efforts. Serves as the primary resource for cross-functional team members on escalated issues of a unique nature.
  • Maintains expert level knowledge of USAA Information Security standards as well as industry information security best practices, frameworks, laws, and regulations.
  • Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.

What you have:

  • Bachelor's degree OR 4 years of relevant education and/or experience.
  • 8 years of related experience in Information Security, Cybersecurity and/or Information Technology with a security focus to include accountability for complex tasks and/or projects.
  • 6 years of related experience in one of the following domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security.
  • Expert level of business acumen in the areas of business operations, risk management, industry practices and emerging trends.
  • Experience performing security reviews to identify gaps, resulting in recommendations for inclusion in risk mitigation strategies.
  • Experience investigating potentially malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information.

 

What sets you apart:

  • Experience leading technical investigations and response activities during cybersecurity incidents, including coordinating responders, prioritizing actions, and validating containment efforts.
  • Experience across multiple incident response disciplines, including security monitoring, alert triage, incident investigation, case disposition, malware analysis, digital forensics, threat intelligence, endpoint security, network security, identity security, and incident containment.
  • Demonstrated ability to coordinate cross-functional teams and maintain situational awareness during complex or high-severity cybersecurity incidents.
  • Experience responding to ransomware, credential compromise, insider threats, data exfiltration, cloud compromise, advanced malware, or other large-scale cyber threats.
  • Familiarity with proactive cybersecurity activities such as threat hunting, detection engineering, cyber threat intelligence, purple teaming, red teaming, or adversary emulation.
  • Experience developing and maturing incident response programs, processes, playbooks, operating models, and after-action review programs to improve response capabilities and operational effectiveness.
  • Experience communicating technical findings, business impact, and response recommendations to senior leadership and stakeholders during active cybersecurity incidents.
  • Experience coordinating cybersecurity response activities across security, technology, business, and third-party partner organizations.

 

Compensation range: The salary range for this position is: $142,320 - $273,930.

 

USAA does not provide visa sponsorship for this role. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).


Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location.

 

Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.

The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.

 

Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.

 

For more details on our outstanding benefits, visit our benefits page on USAAjobs.com.

Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.

 

USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Skills Required

  • Bachelor's degree or four years of relevant education and/or experience
  • Eight years of related experience in information security, cybersecurity, or information technology with a security focus
  • Six years of related experience in a security domain, such as security operations, security assessment and testing, security architecture, network security, or identity and access management
  • Expert-level business acumen in business operations, risk management, industry practices, and emerging trends
  • Experience performing security reviews, identifying gaps, and recommending risk mitigation strategies
  • Experience investigating potentially malicious activity, including determining exploited weaknesses, exploitation methods, and system or information effects
  • Experience leading technical investigations and response activities during cybersecurity incidents
  • Experience across incident response disciplines including monitoring, alert triage, malware analysis, digital forensics, threat intelligence, endpoint security, network security, identity security, and containment
  • Ability to coordinate cross-functional teams and maintain situational awareness during complex or high-severity incidents
  • Experience responding to ransomware, credential compromise, insider threats, data exfiltration, cloud compromise, or advanced malware
  • Familiarity with threat hunting, detection engineering, cyber threat intelligence, purple teaming, red teaming, or adversary emulation
  • Experience developing and maturing incident response programs, processes, playbooks, operating models, and after-action reviews
  • Experience communicating technical findings, business impact, and response recommendations to senior leadership
  • Experience coordinating cybersecurity response activities across security, technology, business, and third-party organizations

USAA Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about USAA and has not been reviewed or approved by USAA.

  • Retirement Support — Robust retirement programs include a rich 401(k) employer match alongside a company-funded pension, reinforcing long-term financial security. These elements are often singled out as standout features of the total rewards package.
  • Healthcare Strength — Comprehensive medical, dental, vision, behavioral health, and telehealth coverage is paired with wellness incentives and onsite or reimbursed fitness resources. These offerings are perceived as meaningfully enhancing overall compensation value.
  • Parental & Family Support — Fully paid parental leave, adoption assistance, and childcare reimbursement reflect substantial support for families. These benefits are widely regarded as valuable contributors to the employment proposition.

USAA Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Antonio, TX
35,000 Employees

What We Do

At USAA, our mission is more than just words – it’s the reason we do what we do. Our goal is to be the military community’s provider of choice for insurance, banking, financial products and advice. Take a look back at our history and you’ll see a strong track record of providing members with the highest level of care and support. And we’re proud to continue helping them achieve better financial futures. It’s that kind of dedication that’s helped us grow to more than 35,000 employees. Share our passion for serving those who serve? Whether you’re connected to the military or not, we’re always looking for talented individuals to join our team.

Similar Jobs

Hybrid
8 Locations
289097 Employees
Hybrid
2 Locations
289097 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Finance Transformation Business Change Analyst

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office
Spring, TX, USA
85422 Employees
93K-214K Annually

PwC Logo PwC

AWS Cloud Infrastructure and Operations Delivery Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
67 Locations
370000 Employees
99K-232K Annually

Similar Companies Hiring

MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account