Senior Manager, Incident Response
Alternate Locations: Newell Brands is a leading consumer products company with a portfolio of iconic brands like Graco®, Coleman®, Oster®, Rubbermaid®, Sharpie®, and Yankee Candle® — and 24,000 talented teammates around the world. Our culture is built on values in action: Integrity, Teamwork, Passion for Winning, Ownership, and Leadership.
About the role
The Cyber Security Senior Manager, Incident Response reports to the Senior Manager of Security Operations and serves as the senior-most technical leader within the Newell Brands Security Operations function. This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP) — owning end-to-end response coordination for high-severity and critical security incidents across Newell's global environment. Beyond incident response, the Senior Manager sets the technical direction for Security Operations, leading detection engineering, automation, and control-improvement initiatives while directing the team's day-to-day operational execution. This is a hands-on leadership role: the right candidate pairs deep, current IR and engineering expertise with the operational judgment to run a modern SOC and translate lessons learned into durable, scalable process improvements.
Responsibilities
- Incident Command & Response
- Serve as primary Incident Commander in accordance with the Newell Brands CSIRP, leading response activities across all CSIRT functional teams for high-severity and critical incidents.
- Make and communicate time-sensitive decisions to contain incidents, prevent escalation, and restore normal operations as quickly and efficiently as possible.
- Coordinate response activities across Security Operations, IT, Legal, HR, Corporate Communications, Privacy, and other cross-functional teams, ensuring alignment with CSIRP priorities.
- Partner with the CISO to brief executive leadership, the Information Security Governance Committee, and other key stakeholders on incident status, business impact, and response actions.
- Determine when to activate external IR retainer resources, manage those vendor relationships throughout an engagement, and ensure evidentiary integrity.
- Lead post-incident reviews and after-action analysis; document findings and drive implementation of corrective actions to reduce recurrence.
- Maintain and continuously improve CSIRP documentation, incident runbooks, and playbooks; conduct tabletop exercises and simulation drills at least annually.
- Security Engineering & Control Improvement
- Develop and recommend security control improvements based on incident findings, threat intelligence, and gap assessments across endpoint, network, identity, and cloud environments.
- Design, build, and maintain detection engineering content — SIEM correlation rules, behavioral analytics, and custom signatures — to improve fidelity and reduce mean time to detect.
- Lead automation initiatives across Security Operations workflows including alert triage, enrichment, containment actions, and case management integrations (SOAR/XSOAR or equivalent).
- Evaluate emerging security technologies and make evidence-based recommendations for tooling investments that improve detection and response capabilities.
- Collaborate with IT and infrastructure teams to validate that security controls are implemented correctly and test them through adversary simulation and purple team activities.
- Security Operations
- Lead day-to-day Security Operations, directing SOC monitoring, alerting, and triage to ensure operational coverage and response readiness across global time zones.
- Set the technical direction and continuous-improvement roadmap for the SOC, prioritizing the work that most reduces risk and improves detection and response performance.
- Provide senior technical leadership and mentorship to SOC analysts, elevating investigation quality and accelerating analyst skill development.
- Own the Security Operations KPI and metrics program, using it to demonstrate measurable improvement in SOC maturity and risk reduction to leadership.
- Maintain an in-depth understanding of Newell Brands' current and forward-looking threat profile relevant to a global consumer goods company, and ensure operational coverage reflects it.
- Own Security Operations tooling coverage and effectiveness, identifying and closing gaps across the detection and response stack.
- Develop and maintain trusted relationships with stakeholders across IT, Legal, HR, Privacy, Ethics, and business unit leadership.
- Represent Security Operations in the information security community to identify emerging threats, intelligence, and techniques that may impact Newell Brands.
Requirements
- Bachelor’s degree in Information Security, Computer Science, Information Management Systems, or a related field.
Qualifications
- 10+ years of experience in cyber security, with a minimum of 6 years in a dedicated Incident Response or Security Operations role.
- Experience leading the technical operations of a SOC or Security Operations team, including setting priorities, mentoring analysts, and driving measurable operational improvement.
- Demonstrated experience serving as an Incident Commander or leading response efforts for high-severity incidents (ransomware, data breach, nation-state intrusion, or equivalent).
- Proven experience managing cross-functional response teams under pressure, including coordination with Legal, Communications, and executive stakeholders.
- Experience managing and directing external IR retainer engagements and third-party forensic vendors.
- Hands-on expertise with endpoint and network-based forensic investigation, malware analysis, and log-based intrusion analysis.
- Practical security engineering experience: SIEM detection content development, SOAR playbook authoring, and security automation scripting (Python, PowerShell, or equivalent).
- Demonstrated ability to provide security control recommendations and architecture guidance across endpoint, network, cloud (Azure, M365), and identity environments.
- Strong knowledge of network protocols, OS internals, and application-layer vulnerabilities, along with corresponding risk mitigations.
- Prior experience in a Fortune 500 or complex global enterprise environment preferred.
Preferred Qualifications
- One or more of the following certifications or similar:
- GIAC Certified Incident Handler (GCIH)
- BTL2 (Security Blue Team Level 2)
- OffSec Defense Analyst (OSDA)
- Certified Information Systems Security Professional (CISSP)