SOC Incident Commander
Norwalk, CA - USA
Job Summary
Are you looking to Optimize your life Start your exciting path to a rewarding career today!
We are Optimum a leader in the fast-paced world of connectivity and were seeking driven and enthusiastic professionals to join our team empower lives fuel businesses and drive innovation. Connectivity is no longer a luxury but a necessity. A career at Optimum means youll be enabling progress and enhancing lives by providing reliable high-speed connectivity solutions that keep the world connected. Our successes now and in the future are powered by our amazing product a commitment to our people and culture and the connections we make in our communities.
If you are resourceful collaborative and passionate about delivering consistent excellence Optimum is for you!
As a Cyber Security Incident Commander you will be responsible for safeguarding our organizations digital assets by promptly identifying analyzing and responding to cyber security incidents. You will play a critical role in minimizing the impact of security breaches and preventing future incidents through proactive measures and continuous improvement of our incident response processes.
- Incident command & response
- Serve as incident commander for mid-tier and major incidents: own the full lifecycle and direct cross-functional workstreams (IT Legal Communications/PR Engineering executives).
- Monitor alerts and logs; triage and prioritize incidents by severity criticality and business impact.
- Execute incident response playbooks to contain mitigate and remediate breaches then restore affected systems and close off unauthorized access.
- Act as primary point of contact to executive leadership and the CISO translating technical events into business-impact briefings.
- Forensics & analysis
- Conduct host network memory and cloud/hybrid forensics to determine root cause scope and extent of compromise preserving evidence and maintaining chain of custody to legal and regulatory standards.
- Perform malware triage and static/dynamic analysis including sandbox detonation to establish capability and indicators of compromise.
- Integrate threat intelligence and proactively hunt for adversary TTPs mapped to MITRE ATT&CK.
- Leverage AI-enabled tooling to accelerate triage enrichment and investigation (AI First mindset).
- Readiness & continuous improvement
- Own post-incident reviews and root cause analyses; capture lessons learned and drive remediation to closure.
- Develop and mature incident-response playbooks tabletop exercises and readiness drills.
- Organize and execute security exercises including Purple Team Exercises penetration tests and audits.
- Define and report IR metrics (MTTD MTTR) and major-incident tracking to leadership.
- Program & collaboration
- Prepare detailed incident reports covering timeline impact remediation and lessons learned.
- Coordinate with external parties including law enforcement regulators and third-party vendors.
- Develop security policies procedures and best practices; perform risk assessments and audits for compliance with industry standards.
- Evaluate and recommend security technologies partnering with IT to design and implement solutions.
- Lead and mentor junior analysts fostering continuous learning.
- Stay current on emerging threats vulnerabilities and industry trends.
- Bachelors degree in Computer Science or related field.
- Advanced certifications such as CISSP or incident-response/forensics GIAC certifications (GCIH GCFA GCFE GNFA) are preferred
- Minimum five years experience in Information Technology
- Minimum three years of direct IT Security experience in Cyber Security operations and Incident Response
- Experience performing event and log analysis including one or more of the following: Anti-Virus Intrusion Detection Systems Firewalls Active Directory Web Proxies Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security
- Ability to communicate complex information concepts or ideas in a confident and well-organized manner through verbal written and/or visual means
- Solid working knowledge of networking technology and tools firewalls proxies IDS/IPS encryption SIEM and EDR
- Experience writing scripts tools or methodologies to enhance the investigative process
- Working knowledge of the MITRE ATT&CK framework and the NIST incident response lifecycle (NIST SP 800-61).
- Hands-on experience with industry-standard forensic toolsets and with cloud forensics across major cloud and productivity platforms.
- Familiarity with AI tools and an AI First mindset.
At Optimum every action and interaction we take part in is driven by our three Guiding Principles: Do Whats Right Drive One Optimum and Make It Happen. These arent just words they help us build trust create real community and embrace new ways of thinking. Our employees are empowered to do the right thing for our customers and co-workers and to recognize and reward these behaviors when we see them. Its all part of the bigger picture of Be The Difference where each employee knows they have the power to enact real change share new ideas and understand that learning never stop.
If you have the drive to succeed and are ready to embark on a thrilling career seize this opportunity today and join our winning team. Together well shape the future of connectivity.
All job descriptions and required skills qualifications and responsibilities for a particular position are subject to modification by the Company from time to time in the Companys discretion based on business necessity.
We are an Equal Opportunity Employer committed to recruiting hiring and promoting qualified people of all backgrounds regardless of gender race color creed national origin religion age marital status pregnancy physical or mental disability sexual orientation gender identity military or veteran status or any other basis protected by federal state or local law.
The Company collects personal information about its applicants for employment that may include personal identifiers professional or employment related information photos education information and/or protected classifications under federal and state law. This information is collected for employment purposes including identification work authorization FCRA-compliant background screening human resource administration and compliance with federal state and local law.
Applicants for employment with The Company will never be asked to provide money (even if reimbursable) as part of the job application or hiring process. Please review our Fraud FAQ for further details.
We appreciate your interest in this opportunity. Applicants must be authorized to work for ANY employer in the U.S. Please note that at this time we do not provide visa sponsorship for employment.
About Company
Stay connected with Optimum Fiber-powered Internet starting at $25/mo. with a 5-year price lock. Explore internet, TV, mobile & bundle deals today.