• Build, lead, and develop a team of incident responders and security builders, setting clear expectations, creating meaningful ownership, and supporting growth.
• Delegate effectively based on team strengths, development goals, capacity, and operational needs while maintaining accountability for outcomes.
• Define and drive the security incident response roadmap and strategic priorities, including maturing agentic incident response, structured threat hunting, and insider risk investigations as sustained, scaled capabilities rather than one-time builds.
• Balance competing priorities across incident response, strategic initiatives, and team development; make tradeoffs clear and push back when timelines, approaches, or requests create unnecessary risk or unsustainable workload.
• Scale team capacity through AI-assisted tooling and automation, maintaining appropriate controls around human judgment, approval, auditability, and rollback.
• Oversee detection, triage, containment, remediation, and post-incident learning, serving as an escalation point and incident manager for complex or high-severity events.
• Partner with Detection Engineering, Cyber Threat Intelligence, Red Team and other teams to improve cross-functional processes and close detection or response gaps identified through investigations.
• Evolve playbooks, training, tabletop exercises, metrics, and reporting to strengthen operational readiness and program maturity.
• Participate in the on-call rotation, serving as the leadership escalation or incident manager during major or complex incidents.
• Track and report on incident trends, operational metrics, and program maturity, including the impact of automation and AI tooling on response time and coverage.