Posted on: 10/06/2026
Minimum Job Qualifications :
Essential :
- University degree in Computer Science, Engineering, Cybersecurity, Information Technology, or Business Administration with relevant IT security experience; or equivalent professional experience at a commensurate level.
- A minimum of 10 years of related experience with a Bachelor's degree; or 8 years with a Master's degree; or equivalent work experience.
- A minimum of 5 years of hands-on experience in cybersecurity incident response, crisis communications, security operations, or a directly related field.
- Demonstrated experience managing complex, multi-stakeholder situations under time pressure, with the ability to produce accurate, clear, and concise written communications rapidly in high-stress incident conditions.
- Experience working in crisis communications, and working with communications to executive staff, legal and law enforcement, and external government officials. Experience needs to include work with North America and/or European jurisdictions.
- Excellent written and oral communication skills in English; strong analytical judgment and the ability to work effectively with executive leadership, legal counsel, technical engineers, and external stakeholders.
- Direct familiarity with ISO 27001 and PCI DSS incident response requirements or documented equivalent regulatory communications experience in a comparable regulated environment.
- Highly desired to familiarity with Incident Command System (ICS) Communication Hierarchy principles, NIST SP 800-61 Incident Response Communications, and/or Situational Crisis Communication Theory (SCCT).
- Experience running Disaster Recovery and Incident Response tabletop exercises.
Desirable Qualifications :
- Experience with ITIL-based incident management processes.
- Familiarity with Incident Command System / National Incident Management System (ICS/NIMS) communication principles.
- Crisis communications or public relations experience, particularly in a legal or regulatory environment.
- Experience in a regulated industry such as payment processing, defense contracting, healthcare, or financial services.
- Knowledge of or willingness to develop familiarity with relevant security and operational technologies including Microsoft Azure and AWS cloud environments, ITSM/ServiceNow, SIEM platforms (Splunk), and enterprise GRC tools (OneTrust).
- Wide-ranging experience with in-depth professional knowledge; capable of independently determining methods and procedures on new assignments, exercising judgment in selecting and adapting complex techniques, and producing results that may impact the entire security function. Networks with key contacts outside own area of expertise; uses persuasion in delivering messages that relate to the wider business.
- May be accountable through team for delivery of tactical business targets.
- Demonstrated experience developing or mentoring junior team members and managing a security exercise or communications training program.
Did you find something suspicious?