JOB SUMMARY
Under the direction of the Chief Information Security Officer, the Incident Response Manager & Security Operations Team Lead is responsible for leading the University's Security Operations and Incident Response functions in support of the University of Connecticut Information Security Office.
The Incident Response Manager works regularly with other senior members of the Information Security Office and is a member of the CISO’s security leadership team.
This position serves in a dual capacity as both a technical subject matter expert and the supervisor of a functional team. The incumbent provides strategic and operational leadership for the University's cybersecurity monitoring, detection, investigation, response, and recovery capabilities while actively participating in complex incident response activities and advanced security operations.
The Incident Response Manager leads a team of cybersecurity professionals responsible for continuous security monitoring, incident response, threat detection, digital forensics, and operational security engineering. The position establishes operational priorities, develops procedures and playbooks, manages security technologies, and coordinates enterprise response activities across the University’s academic, research, and administrative environments.
The manager works collaboratively with University leadership, Information Technology Services, legal counsel, privacy, compliance, research, public safety, and external partners to ensure timely, effective, and coordinated response to cybersecurity incidents.
The Incident Response Manager is responsible for continuously improving the University's incident response maturity and operational security capabilities through process improvement, technology implementation, threat-informed defense, automation, metrics, and staff development.
SALARY
- Incident Response Manager and Security Operations Team Lead (IT Team Lead 2 – M7): $95,066 to $123,585
Note: All minimum qualifications must be met to be eligible for consideration. Salary will be commensurate with experience within the established range.
BENEFITS INCLUDE
- Defined contribution with employer match or defined benefit program retirement options
- Excellent and affordable healthcare options
- 35 hour work week
- 22 paid vacation days per year, paid sick leave, and 13 paid holidays
- Employee and dependent tuition waivers
- A highly desirable work environment and work-life balance
DUTIES AND RESPONSIBILITIES
- Lead the University's Security Operations and Incident Response programs.
- Direct day-to-day operations of the Security Operations team, including prioritization of work, workload management, coaching, mentoring, and performance management.
- Serve as the incident commander for significant cybersecurity incidents, coordinating technical response activities across multiple University departments. Operates as a primary member of the UConn Incident Response Plan, acting as functional lead for Executive Response Team (ERT) meetings and activities.
- Personally participate in complex incident investigations, threat hunting, malware analysis, digital forensics, containment, eradication, recovery, and post-incident reviews.
- Develop, maintain, and continuously improve incident response plans, operational procedures, playbooks, and technical standards.
- Manage the identification, detection, and response to alerts and events through the University's security monitoring capabilities including SIEM, SOAR, EDR/XDR, threat intelligence, logging, and related security technologies.
- Lead continuous improvement of detection engineering, alert tuning, automation, and operational metrics.
- Coordinate security operations with infrastructure, networking, cloud, identity management, application, and research computing teams.
- Oversee threat detection engineering, use case development, and security content management.
- Manage relationships with incident response vendors, managed security providers, law enforcement, and external cybersecurity organizations.
- Coordinate regulatory reporting and support investigations involving compliance, legal, privacy, and research security requirements.
- Develop operational dashboards, metrics, executive reporting, and key performance indicators for security operations and incident response.
- Lead tabletop exercises, incident simulations, and operational readiness activities.
- Participate in security architecture reviews to improve monitoring and incident response capabilities.
- Develop staffing plans, training plans, career development activities, and succession planning for Security Operations personnel.
- Manage operational projects related to security monitoring, automation, response technologies, and operational maturity.
- Maintain awareness of emerging threats, adversary tactics, vulnerabilities, and industry best practices.
- Participate in after-hours incident response and operational escalations as required.
- Other related duties as assigned.
RELATED SKILLS AND COMPETENCIES
- Leadership - Demonstrates the ability to lead, motivate, coach, and develop highly skilled technical professionals. Creates a collaborative, service-oriented culture focused on operational excellence and continuous improvement.
- Incident Leadership - Provides calm, decisive leadership during complex cybersecurity incidents. Coordinates technical, operational, and executive stakeholders while maintaining effective communication and prioritization.
- Technical Expertise - Demonstrates expert knowledge across security operations, incident response, threat detection, digital forensics, security monitoring, cloud security, endpoint security, identity security, and enterprise security architecture.
- Strategic Thinking - Develops operational roadmaps, establishes priorities, evaluates emerging technologies, and aligns security operations with institutional objectives and risk management strategies.
- Communication - Communicates effectively with technical staff, executive leadership, legal counsel, auditors, and external partners. Produces clear technical documentation and executive-level reporting.
- Project Management - Plans and manages multiple concurrent operational initiatives while balancing daily security operations and incident response responsibilities.
- Physical Demands - This position involves extended periods of sitting and extensive use of computers and office equipment.
MINIMUM QUALIFICATIONS
- Must meet and maintain eligibility requirements to work with CUI/CTI data, as determined by the Facility Security Officer and the Office of Export Control.
- Bachelor's degree and six (6) years of related experience in information security or information technology; OR Associate's degree and eight (8) years of related experience; OR ten (10) years of related experience.
- Three (3) or more years of progressively responsible experience in Security Operations and Incident Response.
- One (1) or more years of experience leading or supervising a technical cybersecurity team or serving as a technical team lead.
- Demonstrated experience leading enterprise cybersecurity incident response activities, including management of executive communication, incident management, remediation, restoration, and drafting of reports.
- Experience identifying, triaging, mitigating and remediating security events and alerts with enterprise SIEM, EDR/XDR, SOAR, threat intelligence, logging, and security monitoring platforms.
- Experience conducting digital forensic investigations, malware analysis, threat hunting, or advanced incident investigations.
- Experience developing incident response plans, playbooks, operational procedures, and security standards.
- Experience managing security technologies to perform security operations and incident response including Microsoft Sentinel, Splunk Enterprise Security, Microsoft Defender, CrowdStrike, Palo Alto Cortex, or comparable enterprise security platforms.
- Experience with cloud security technologies supporting Microsoft Azure, AWS, Microsoft 365, or Google Cloud.
- Experience applying NIST Cybersecurity Framework, NIST SP 800-61, MITRE ATT&CK, CIS Controls, or similar cybersecurity frameworks.
- Demonstrated leadership, analytical, communication, organizational, and project management skills.
PREFERRED QUALIFICATIONS
- Master's degree in Cybersecurity, Computer Science, Information Assurance, or related field.
- Experience managing Security Operations Center (SOC) teams.
- Experience in higher education or research computing environments.
- Experience with Splunk and Microsoft Defender XDR.
- Experience with Splunk SOAR or similar SOAR platforms and security automation.
- Experience with cloud-native security monitoring.
- Experience supporting regulated environments including FERPA, HIPAA, PCI DSS, CJIS, CMMC, NIST 800-171, or similar requirements.
- Experience conducting threat hunting and detection engineering.
- Experience developing executive metrics and operational dashboards.
- Experience managing vendor relationships and cybersecurity procurements.
- Experience coordinating cybersecurity exercises and tabletop events.
- CISSP, GCIH, GCFA, GCIA, GCFE, GNFA, GCED, CASP+, CISM, or comparable advanced cybersecurity certification.
APPOINTMENT TERMS
This is a full-time, permanent position. The University offers a competitive salary, and outstanding benefits, including employee and dependent tuition waivers at UConn, and a highly desirable work environment.
Other rights, terms, and conditions of employment are contained in the collective bargaining agreement between the University of Connecticut and the University of Connecticut Professional Employees Association (UCPEA).
This position is on-site. THIS IS NOT A REMOTE POSITION. The position may be eligible for a hybrid work schedule under applicable bargaining agreements, management approval, and not less than an annual review. This position may require you to travel in-state and you may be required to work irregular hours to support operational or security activities and initiatives.
TERMS AND CONDITIONS OF EMPLOYMENT
Employment of the successful candidate is contingent upon the successful completion of a pre-employment criminal background check. The successful candidate must be determined to be and remain eligible to work with CUI/CTI data as determined by the Facility Security Officer and the Office of Export Control
TO APPLY
Please apply online at Faculty and Staff Positions, Search #499767 to upload a resume, cover letter, and contact information for three (3) professional references. Applicants must clearly demonstrate how they meet the stated minimum qualifications, and any preferred qualifications they may possess, in their application materials.
This job posting is scheduled to be removed at 11:55 p.m. Eastern time on September 11, 2026.
All employees are subject to adherence to the State Code of Ethics.
All members of the University of Connecticut are expected to exhibit appreciation of, and contribute to, an inclusive, respectful, and diverse environment for the University community.
The University of Connecticut aspires to create a community built on collaboration and belonging and has actively sought to create an inclusive culture within the workforce. The success of the University is dependent on the willingness of our diverse employee and student populations to share their rich perspectives and backgrounds in a respectful manner. This makes it essential for each member of our community to feel secure and welcomed and to thoroughly understand and believe that their ideas are respected by all. We strongly respect each individual employee’s unique experiences and perspectives and encourage all members of the community to do the same. All applicants will receive consideration for employment without regard to race, color, ethnicity, religion, age, sex, marital status, national origin, ancestry, sexual orientation, genetic information, physical or mental disabilities, veteran’s status, status as a victim of domestic violence and/or sexual assault and/or trafficking in persons as defined by Connecticut law, prior conviction of a crime, workplace hazards to the reproductive systems, or gender identity or expression.
The University of Connecticut is an AA/EEO employer including for Disability and Veteran status.