Incident Response Manager

3 days ago

Vancouver BC, Greater Vancouver Regional District, BC; British Columbia, Canada CyberClan Full-time €140,000 - €170,000

CyberClan provides enterprise security, and human response to small and midsize enterprises and

channel partners through comprehensive risk assessment services, 24/7/365 managed detection and response services, and lightning-fast breach response. Formerly known as Network Test Labs established in Canada and specializing in vulnerability assessments and penetration testing in the gaming industry,

CyberClan has grown from three employees in 2006 in one market to over 75 employees with clients in nine countries and offices in the Australia, Canada, United Kingdom, and United States as a leading Managed Services Provider.

Our mission is to make the online world a safer and more secure place by delivering sophisticated

cybersecurity solutions in a highly personalized — and human — way.

CyberClan is hiring a DFIR Manager who will be leading a high-performing Security Incident Response

function, overseeing cross-functional investigations, incident resolution, and remediation efforts across global operations. This position is responsible for developing and implementing incident response strategies, driving key performance metrics, mentoring team members, and ensuring legal and technical integrity throughout forensic investigations. As a strategic partner to leadership, the role provides detailed reporting, resource management, and operational oversight while also acting as a technical authority during incidents. The ideal candidate foster innovation, ensures constant readiness through training and tooling, and plays a critical role in post-breach remediation, client communication, and maintaining organizational resilience in a 24x7 environment.

The successful candidate will work closely with the Director of Global Incident Response Operations. The ideal candidate will have an energetic, can-do attitude and be comfortable working in a metrics-driven environment, delivering results and supporting team members.

Key Responsibilities

  • Leading security incidents in a cross-functional and collaborative environment, targeting incident resolution & mentoring team members to continue to scale in high-growth
  • Developing IR initiatives that improve our capabilities to respond and swiftly remediate security events.
  • Creating a culture of accountability, quality, agility, and high performance that will foster the attraction, development, and retention of security analysts.
  • Responsible for being a focal incident response point for all within the organization. This includes being able to provide initial analysis and identification of IOC’s, escalation to the appropriate business units and post-incident activities.
  • Oversee Incident Response Plans: Design, implement, and manage the client's incident response policies and procedures to ensure preparedness.
  • Coordinate Incident Response Teams: Lead cross-functional teams during security incidents, ensuring an organized and timely response.
  • Triage and Prioritize Incidents: Assess incidents for severity and potential impact, assigning appropriate resources and setting response priorities.
  • Serve as technical point of contact during an incident, providing updates to internal and external stakeholders.
  • Serve as an incident manager, reporting key findings, barriers, escalations and concerns to the Director of Global Incident Response Operations, while liaising with Legal, Director of Sales, and IRC team.
  • Maintain and prepare departmental reports for Key Performance Indicators (KPIs) to be presented to the Global Head of Incident Response Operations and EVP Sales & Revenue as needed.
  • Responsible for supporting a wide number of technologies and being able to proficiently perform advanced troubleshooting on the fly (packet captures, debugs, traffic analysis).
  • Responsible for developing and documenting Incident Response methods and guidelines for the organizations.
  • Support in the departments DFIR tooling selection process and any proof-of-concept projects.
  • Chain of Custody: Ensure that evidence is collected, handled, and preserved in a legally defensible manner, maintaining the chain of custody for potential litigation
  • Perform live-endpoint investigation.
  • Implements and deploys an Incident Response focused ticketing system to improve incident tracking, remediation and metrics for incidents worked.
  • Post-incident Analysis: Conduct root cause analysis after incidents to identify vulnerabilities and develop strategies to prev