Cybersecurity Incident Manager Lead

USAA

Confirmed live today High trust
Closes in 5 days Hybrid

Quick summary

Work type
Hybrid
Location
San Antonio, TXPlano, TXPhoenix, AZColorado Springs, CO
Salary
$142,320–$273,930 / yr
Employment
Full-time
Posted
2 days ago
Freshness
Confirmed live today
Closes
Oct 7, 2026 (soon)

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $173k
This role $208k
$110k most similar roles pay here $292k

This role pays more than 79% of similar roles. Most pay $151,264–$195,250 — the shaded band above. At the midpoint, this role pays about $208k versus about $173k for comparable roles.

Based on 240 similar postings.

Employer

About USAA

USAA (United Services Automobile Association) is a San Antonio-based Fortune 500 financial services company founded in 1922, dedicated to providing insurance, banking, and investment solutions exclusively to U.S. military members, veterans, and their families.

USAA currently has 30 open roles on FindRole.

Listed pay typically runs $142,320–$265,950 across 21 roles with salary data.

Most-posted roles

View all roles at USAA

At a glance

TL;DR · Cybersecurity Incident Manager Lead

As a Cybersecurity Incident Manager - Lead within the Cyber Threat Monitoring and Response team, you will lead and coordinate cybersecurity incident response activities throughout the entire lifecycle across security, technology, business, and third-party partner organizations. You will act as an Incident Commander during active incidents, establishing objectives, maintaining situational awareness, and communicating status to senior leadership. Your daily responsibilities include investigating security anomalies, performing vulnerability and penetration testing assessments, and driving the maturity of the Cyber Threat Operations Center through improved playbooks and training. You will utilize a variety of cyber defense tools, forensics, networking, servers, and coding skills to identify malicious tactics. This role addresses critical security risks by analyzing threats like ransomware and data exfiltration while ensuring organizational resilience through continuous improvement of detection capabilities and operational processes.

What you'll do

  • Act as an Incident Commander to lead and coordinate cross-functional teams during active cybersecurity incidents.
  • Perform detailed analysis of security anomalies using complex tools to determine root causes and malicious actor tactics.
  • Drive the development and maturity of incident response playbooks, operating models, and after-action review practices.
  • Conduct vulnerability assessments, security configuration audits, and penetration testing across systems and networks.
  • Research and analyze emerging threats, exploits, and trends to share intelligence with the enterprise.
  • Train and mentor analysts in incident detection, response techniques, and knowledge sharing activities.
  • Prepare and deliver technical briefings regarding threat alerts and incident impacts to senior leadership and stakeholders.
  • Ensure all business activities comply with internal security standards and applicable laws or regulations.

What we're looking for

  • Bachelor's degree or 4 years of relevant education and/or experience.
  • 8 years of related experience in Information Security, Cybersecurity, and/or Information Technology with a security focus.
  • 6 years of related experience in one of the specified domains including Security Operations, Risk Management, or Network Security.
  • Expert level of business acumen regarding operations, risk management, and emerging trends.
  • Experience performing security reviews to identify gaps and provide recommendations for risk mitigation strategies.
  • Experience investigating potentially malicious activity to determine weaknesses exploited and their effects on systems.
  • Experience leading technical investigations and response activities during cybersecurity incidents (preferred).
  • Experience across multiple incident response disciplines including forensics, malware analysis, and threat intelligence (preferred).

More like this

Similar roles

Incident Response Analyst, Mid

Booz Allen Hamilton

Bethesda, MD 29 days ago
Splunk SIEM EDR IDS/IPS SOAR Digital Forensics Packet Analysis Malware Triage Threat Hunting Behavioral Analytics Threat Intelligence Identity and Access Management Container Security API Security Vulnerability Management Firewalls Log Analysis
2+ yrs exp

Senior Incident Response Analyst

Booz Allen Hamilton

Bethesda, MD 21 days ago
Splunk SIEM EDR IDS IPS SOAR Microsoft Defender Packet Analysis Malware Triage Digital Forensics Threat Hunting Behavioral Analytics Threat Intelligence Vulnerability Management Firewalls Identity and Access Management Container Security API Security
5+ yrs exp

Vice President Cyber Incident Response

The Federal Reserve

Richmond, VA +12 24 days ago
Incident Response SOC Operations Threat Hunting Malware Analysis Forensics Cyber Threat Intelligence Detection Engineering AI Information Security Change Management
5+ yrs exp

Lead Information Security Systems Engineer

L3Harris

Greenville, TX 7 days ago
AWS SIEM Wazuh Splunk Incident Response Detection Engineering Identity and Access Management Risk Management Framework MITRE ATT&CK Threat Hunting vulnerability-management Linux Windows Networking Cloud Security
9+ yrs exp

Principal Cyber Threat Intelligence Specialist

University of Miami

Remote (Miami, FL) 29 days ago
Cyber Threat Intelligence Artificial Intelligence Security Automation SOC Threat Hunting Incident Response Vulnerability Management Governance, Risk and Compliance Identity and Access Management
10+ yrs exp Remote