Jobs · Georgia

Senior Manager, Incident Response

Newell Brands · Atlanta, GA · 4 days ago
HybridFull-time

Alternate Locations: Newell Brands is a leading consumer products company with a portfolio of iconic brands like Graco®, Coleman®, Oster®, Rubbermaid®, Sharpie®, and Yankee Candle® — and 24,000 talented teammates around the world. Our culture is built on values in action: Integrity, Teamwork, Passion for Winning, Ownership, and Leadership.

About the role

The Cyber Security Senior Manager, Incident Response reports to the Senior Manager of Security Operations and serves as the senior-most technical leader within the Newell Brands Security Operations function. This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP) — owning end-to-end response coordination for high-severity and critical security incidents across Newell's global environment. Beyond incident response, the Senior Manager sets the technical direction for Security Operations, leading detection engineering, automation, and control-improvement initiatives while directing the team's day-to-day operational execution. This is a hands-on leadership role: the right candidate pairs deep, current IR and engineering expertise with the operational judgment to run a modern SOC and translate lessons learned into durable, scalable process improvements.

Responsibilities

  • Incident Command & Response
    • Serve as primary Incident Commander in accordance with the Newell Brands CSIRP, leading response activities across all CSIRT functional teams for high-severity and critical incidents.
    • Make and communicate time-sensitive decisions to contain incidents, prevent escalation, and restore normal operations as quickly and efficiently as possible.
    • Coordinate response activities across Security Operations, IT, Legal, HR, Corporate Communications, Privacy, and other cross-functional teams, ensuring alignment with CSIRP priorities.
    • Partner with the CISO to brief executive leadership, the Information Security Governance Committee, and other key stakeholders on incident status, business impact, and response actions.
    • Determine when to activate external IR retainer resources, manage those vendor relationships throughout an engagement, and ensure evidentiary integrity.
    • Lead post-incident reviews and after-action analysis; document findings and drive implementation of corrective actions to reduce recurrence.
    • Maintain and continuously improve CSIRP documentation, incident runbooks, and playbooks; conduct tabletop exercises and simulation drills at least annually.
  • Security Engineering & Control Improvement
    • Develop and recommend security control improvements based on incident findings, threat intelligence, and gap assessments across endpoint, network, identity, and cloud environments.
    • Design, build, and maintain detection engineering content — SIEM correlation rules, behavioral analytics, and custom signatures — to improve fidelity and reduce mean time to detect.
    • Lead automation initiatives across Security Operations workflows including alert triage, enrichment, containment actions, and case management integrations (SOAR/XSOAR or equivalent).
    • Evaluate emerging security technologies and make evidence-based recommendations for tooling investments that improve detection and response capabilities.
    • Collaborate with IT and infrastructure teams to validate that security controls are implemented correctly and test them through adversary simulation and purple team activities.
  • Security Operations
    • Lead day-to-day Security Operations, directing SOC monitoring, alerting, and triage to ensure operational coverage and response readiness across global time zones.
    • Set the technical direction and continuous-improvement roadmap for the SOC, prioritizing the work that most reduces risk and improves detection and response performance.
    • Provide senior technical leadership and mentorship to SOC analysts, elevating investigation quality and accelerating analyst skill development.
    • Own the Security Operations KPI and metrics program, using it to demonstrate measurable improvement in SOC maturity and risk reduction to leadership.
    • Maintain an in-depth understanding of Newell Brands' current and forward-looking threat profile relevant to a global consumer goods company, and ensure operational coverage reflects it.
    • Own Security Operations tooling coverage and effectiveness, identifying and closing gaps across the detection and response stack.
    • Develop and maintain trusted relationships with stakeholders across IT, Legal, HR, Privacy, Ethics, and business unit leadership.
    • Represent Security Operations in the information security community to identify emerging threats, intelligence, and techniques that may impact Newell Brands.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Information Management Systems, or a related field.

Qualifications

  • 10+ years of experience in cyber security, with a minimum of 6 years in a dedicated Incident Response or Security Operations role.
  • Experience leading the technical operations of a SOC or Security Operations team, including setting priorities, mentoring analysts, and driving measurable operational improvement.
  • Demonstrated experience serving as an Incident Commander or leading response efforts for high-severity incidents (ransomware, data breach, nation-state intrusion, or equivalent).
  • Proven experience managing cross-functional response teams under pressure, including coordination with Legal, Communications, and executive stakeholders.
  • Experience managing and directing external IR retainer engagements and third-party forensic vendors.
  • Hands-on expertise with endpoint and network-based forensic investigation, malware analysis, and log-based intrusion analysis.
  • Practical security engineering experience: SIEM detection content development, SOAR playbook authoring, and security automation scripting (Python, PowerShell, or equivalent).
  • Demonstrated ability to provide security control recommendations and architecture guidance across endpoint, network, cloud (Azure, M365), and identity environments.
  • Strong knowledge of network protocols, OS internals, and application-layer vulnerabilities, along with corresponding risk mitigations.
  • Prior experience in a Fortune 500 or complex global enterprise environment preferred.

Preferred Qualifications

  • One or more of the following certifications or similar:
    • GIAC Certified Incident Handler (GCIH)
    • BTL2 (Security Blue Team Level 2)
    • OffSec Defense Analyst (OSDA)
    • Certified Information Systems Security Professional (CISSP)

Similar jobs