Cybersecurity Incident Commander
SoFiWA - Seattle4w ago
Job description
About the role
As a , you will play a critical role in safeguarding our digital assets and ensuring the integrity of our systems. This position is designed for individuals who thrive in high-pressure environments and possess a strong background in cybersecurity incident management. You will lead the response to security incidents, coordinating efforts across various teams to mitigate risks and protect sensitive information. Your expertise will be essential in developing and refining our incident response strategies, ensuring that SoFi remains a leader in cybersecurity resilience.
Key facts
What you'll do
- Lead the incident response team in identifying, managing, and mitigating cybersecurity incidents, ensuring a swift and effective response to threats.
- Develop and implement incident response plans, playbooks, and procedures to enhance the organization's preparedness for potential security breaches.
- Collaborate with cross-functional teams, including IT, legal, and compliance, to coordinate incident response efforts and ensure alignment with organizational policies.
- Conduct post-incident reviews to analyze the effectiveness of the response and identify areas for improvement in processes and protocols.
- Monitor security alerts and threat intelligence to proactively identify potential vulnerabilities and risks to SoFi's systems.
- Serve as the primary point of contact for all security incidents, communicating with stakeholders and providing regular updates on incident status and resolution efforts.
- Provide training and guidance to team members and other employees on incident response best practices and security awareness.
- Maintain documentation related to incidents, including timelines, actions taken, and lessons learned, to support compliance and reporting requirements.
- Engage with external partners, such as law enforcement and cybersecurity firms, to enhance incident response capabilities and share intelligence.
- Stay current with industry trends, emerging threats, and regulatory requirements to ensure SoFi's incident response strategies remain effective and compliant.
- Participate in tabletop exercises and simulations to test and refine incident response plans and team readiness.
- Contribute to the development of a culture of security awareness within the organization, promoting proactive risk management among all employees.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A minimum of 5 years of experience in cybersecurity, with a focus on incident response and management.
- Proven track record of leading incident response efforts in a fast-paced environment, preferably within the financial services sector.
- Strong understanding of cybersecurity frameworks, standards, and best practices (e.g., NIST, ISO 27001).
- Excellent analytical and problem-solving skills, with the ability to think critically under pressure.
- Strong communication skills, both verbal and written, with the ability to convey complex technical information to non-technical stakeholders.
- Experience with security tools and technologies, such as SIEM, intrusion detection systems, and endpoint protection solutions.
- Familiarity with regulatory requirements and compliance standards relevant to the financial industry.
- Relevant certifications, such as CISSP, CISM, or CEH, are highly desirable.
Nice to have
- Experience with cloud security and managing incidents in cloud environments.
- Knowledge of threat hunting and vulnerability management practices.
- Familiarity with programming or scripting languages (e.g., Python, PowerShell) for automation of incident response tasks.
- Previous experience in a financial technology or fintech organization.
- Understanding of data privacy regulations, such as GDPR or CCPA.
Skills & tools
- Proficient in using security information and event management (SIEM) tools for monitoring and analysis.
- Familiarity with incident response platforms and ticketing systems.
- Strong knowledge of network security protocols and technologies.
- Experience with forensic analysis tools and methodologies.
- Ability to work collaboratively in a team-oriented environment.
Practical notes
- This position may require occasional travel to other SoFi locations or industry events.
- Candidates must be willing to participate in on-call rotations for incident response outside of regular business hours.
- The role may involve exposure to sensitive information, requiring a high level of discretion and confidentiality.
META
Company: SoFi
Title: Cybersecurity Incident Commander
Listed
location: WA
Seattle; CA
San Francisco