Incident Commander
About the Role
The Incident Commander (IC) is responsible for the management, supervision, and coordination of cyber security incidents as part of a 24x7, 365 Security Operations environment, including nights, weekends, and holiday coverage through an on-call rotation or designated duty schedule. Serving as the critical bridge between executive leadership and technical response teams, the IC provides authoritative command and control during incidents, ensures rapid and informed decision-making, and drives continuous improvement of the City's cyber incident response capabilities.
Responsibilities
- Lead significant, high-impact, or high-visibility cyber security incidents, including validation, prioritization, escalation, and coordination of response activities across multiple City agencies in a 24x7 operational tempo, including nights and weekends as required
- Serve in an on-call Incident Commander capacity, providing off-hours leadership, decision-making, and executive communication during active incidents
- Exercise rapid, independent decision-making in high-stress, fluid environments, including incidents affecting critical infrastructure, life-safety systems, and essential City services
- Provide strategic guidance on, and tracking of, tools, visibility, staffing, and capability gaps impacting the City's overall cyber security posture and response readiness
- Act as the primary liaison between the SOC and impacted agency business, technical, legal, and executive teams throughout the incident lifecycle
- Coordinate and direct efforts among SOC analysts, incident responders, threat intelligence, forensics, legal, communications, and external partners using clearly defined command-and-control structures
- Deliver timely, accurate, and actionable briefings to executive leadership, Agency heads, and other stakeholders during and following incidents
- Lead and oversee After-Action Reports (AARs) and lessons-learned activities, translating findings into concrete improvements to people, process, and technology
- Test, maintain, and continuously improve incident response plans, playbooks, and escalation procedures to address emerging threats and evolving attack techniques
- Build and maintain strong working relationships across City technology, security, legal, privacy, communications, and operational teams
- Participate in and lead special initiatives, exercises, and strategic projects related to cyber resilience, operational readiness, and incident response maturity
- Handle special projects and initiatives as assigned
Minimum Qualifications
- A baccalaureate degree from an accredited college including or supplemented by 24 credits in the field of voice and/or data telecommunications or in a pertinent scientific, technical, electronic or related area, and four years of satisfactory full-time experience in the performance of analytical, planning, operational, technical, or administrative duties in a voice and/or data telecommunications or closely related electronics planning, management, and/or service organization, one year of which must have been in a highly specialized capacity and 18 months must have been in an executive, managerial, or administrative capacity or in the supervision of staff performing work in the voice and/or data telecommunications field; or
- An associate degree from an accredited college including or supplemented by 12 credits in the field of voice and/or data telecommunications or in a pertinent, scientific, technical, electronic or related area and five years of experience as described in "1" above; or
- Education and/or experience equivalent to "1" above. However, all candidates must have at least a four-year high school diploma or its educational equivalent and one year of the specialized experience as described in "1" above and must possess the 18 months of executive, managerial, administrative or supervisory experience as described in "1" above
Preferred Skills
- 7+ years of experience in information security incident handling and/or security operations
- 6+ years of supervisory or managerial experience, leading technical teams during high-pressure operational events
- Demonstrated experience managing large-scale and complex incidents, including but not limited to APT activity, DDoS, ransomware, malicious insiders, web and mobile application attacks, and data exfiltration events
- Proven ability to independently analyze complex problems, determine root causes, and drive remediation in ambiguous or incomplete information environments
- Strong knowledge of enterprise technologies, systems, and networks, including common detection and response gaps affecting SOC effectiveness
- Deep understanding of adversary tactics, techniques, and procedures (TTPs) and how they manifest in real-world incidents
- Familiarity with industry frameworks and best practices, including NIST CSF, NIST SP 800-61, and incident command methodologies
- Bachelor's degree in Information Technology, Cybersecurity, or a related discipline, or equivalent professional experience
- Exceptional written and verbal communication skills, with the ability to translate complex technical issues into clear, authoritative guidance for executive and non-technical audiences
- Demonstrated ability to influence decision-making and drive consensus across diverse stakeholders during high-stakes situations
- Strong organizational skills with the ability to manage multiple high-visibility incidents or initiatives simultaneously
- Relevant professional certifications such as CISSP, GCIA, GCIH, GCFA, GHFI, GNFA, GREM (highly desirable)
- Willingness and availability to support after-hours, weekend, and emergency incident response as part of a 24x7 leadership model
Schedule
Day shift. Due to the necessary management duties of this position in a 24/7 operation, the candidate may be required to be on call and work various shifts such as weekends and/or nights/evenings.
Work Location
Brooklyn, NY