Manager, Incident Response
KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise. We foster both personal and professional development, creating new pathways for growth in a collaborative, team-driven culture. Our people are our number one priority, with access to world-class training, leading market tools, and a strong team connection where you can have an impact, advance your skills, and expand your capabilities.
About the role
We are seeking a Manager, Incident Response to join our Advisory practice. In this role, you will lead and manage cyber incident response activities, oversee investigations, and coordinate high-impact engagements for clients facing cyber threats.
Responsibilities
- Lead and manage cyber incident response activities, including triage, containment, eradication, and recovery efforts for client incidents
- Oversee and coordinate incident investigations across cyber threats such as ransomware, data breaches, insider threats, and advanced persistent threats
- Lead and coordinate incident response engagements, including client communications, executive briefings, war-room facilitation, and cross-functional stakeholder management (legal, forensics, privacy, communications, and leadership) during high-impact events
- Oversee incident investigation and remediation, including root cause analysis, development of actionable improvement plans, and integration with broader cyber resilience practices
- Manage incident response delivery and performance, defining and tracking SLAs, metrics, reporting, and contributing to the enhancement of incident response playbooks, methodologies, and service offerings
- Collaborate and lead within the Cyber & Tech Risk practice, partnering across threat management, governance, risk, compliance, privacy, and technology risk teams while mentoring and developing incident response personnel
- Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Requirements
- Five years of experience in cybersecurity incident response or cyber threat management is required
- Bachelor's degree from an accredited college or university (or equivalent work experience); advanced degree a plus
- Proven experience leading cyber incident investigations and managing escalations in high-pressure environments, applying established incident response frameworks (e.g., NIST, SANS) and breach response practices
- Hands-on experience with security monitoring and response technologies, including SIEM, EDR, DLP, network security, and threat intelligence platforms
- Strong engagement and stakeholder management capabilities, with the ability to lead complex workstreams, balance competing priorities, and communicate effectively—including presenting to senior executives
- Demonstrated professionalism and judgment, exhibiting a high degree of integrity and the ability to manage sensitive and confidential matters
- Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future (KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity)
Benefits
KPMG offers a comprehensive compensation and benefits package, including:
- A variety of medical, dental, and vision plans
- Disability and life insurance
- 401(k) plans
- A robust suite of personal well-being benefits to support mental health
- Personal Time Off per fiscal year, based on job classification, standard work hours, and years of service
- Two annual breaks where employees are not required to use Personal Time Off: one at year-end and one around the July 4th holiday
Pay
California Salary Range: $114,095 – $268,180. Salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications, and market considerations.