Cybersecurity Incident Commander

SoFi SoFi · Fintech · San Francisco, CA · Information Security

SoFi is seeking a Cybersecurity Incident Commander to lead incident command efforts and manage security incident response across the organization. This role involves coordinating cross-functional response, maintaining incident command structure, and ensuring communication and documentation during security events. The ideal candidate has experience in cybersecurity operations, incident response, and handling high-severity incidents, with strong communication and organizational skills.

What you'd actually do

  1. Serve as the primary Security Incident Commander for security incidents identified by the SOC.
  2. Lead and manage the end-to-end lifecycle of security incidents, including triage validation, containment, eradication, recovery, and closure.
  3. Establish and maintain incident command during high-severity or large-scale incidents.
  4. Drive cross-functional collaboration and decision making across technical and business teams to ensure timely and effective response.
  5. Facilitate incident communication, coordinate response resources, and maintain clear situational awareness for all engaged.

Skills

Required

  • 3–7+ years of experience in cybersecurity operations, incident response, or SOC environments.
  • Strong understanding of the incident response lifecycle and frameworks (e.g., NIST 800-61).
  • Ability to interpret technical findings and translate them into clear, actionable updates for both technical and non-technical stakeholders.
  • Strong organizational skills with the ability to manage multiple concurrent incidents.
  • Experience facilitating cross-functional communication across various media channels and driving accountability during live incidents.
  • Ability to operate independently while collaborating effectively across distributed teams.

Nice to have

  • Experience in a formal CSIRT or Incident Commander role.
  • Working knowledge of security technologies such as SIEM, EDR, email security, IAM, cloud security controls, and network monitoring tools.
  • Knowledge of regulatory and compliance considerations (e.g., financial services, PCI, SOX, GLBA).
  • Experience directing or conducting digital forensics or deep technical investigations.
  • Familiarity with cloud-native security incident response (AWS, GCP, or Azure).
  • Exposure to MITRE ATT&CK framework and threat intelligence integration.
  • Relevant certifications such as GCIA, GCIH, GCED, CISSP, CISM, or similar.
  • Experience developing or maintaining incident response playbooks and runbooks.

What the JD emphasized

  • Direct experience coordinating or leading security incident response efforts in enterprise environments.
  • Experience handling high-severity incidents such as ransomware, business email compromise, insider threats, cloud compromise, or data exfiltration events.
  • Excellent written and verbal communication skills, especially in high-pressure situations.