FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in incident management, including the development and execution of Incident Action Plans (IAPs) and compliance with SOC 2 and ISO/IEC 27001 standards. Proven ability to lead cross-functional teams during security incidents while maintaining regulatory compliance and effective communication with stakeholders.
Highest-signal resume keywords
Incident ManagementSOC 2 ComplianceISO/IEC 27001 KnowledgeKPI DevelopmentIncident Commander Experience
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Incident ResponseRisk ManagementGRC DocumentationPost-Incident ReviewsControl MappingRisk AssessmentsAudit-Ready DocumentationIncident Response PlansIAP TemplatesMetrics Tracking
Soft Skills
Strong Written CommunicationDecision-Making Under PressureTeam LeadershipCollaboration with StakeholdersProblem-Solving
Certifications & Qualifications
ICS-100 CertificationICS-200 Certification
Industry Keywords
FintechFinancial ServicesGLBA Safeguards RuleCompliance ProgramsEmergency Services CoordinationPhysical Security ManagementSecurity OperationsRegulatory ExposureBusiness ContinuityTabletop Exercises
Tech Stack
Tools & technologiesCyber Security
About the role
Key responsibilities & impact- Serve as Incident Manager for security and operational incidents, holding full command and control over response activities
- Build, execute, and maintain Incident Action Plans (IAPs) with clear structure, ownership, and timelines
- Make time-sensitive decisions under pressure while weighing safety, regulatory exposure, and business continuity
- Lead post-incident reviews and drive corrective actions through closure
- Run tabletop exercises and simulations to test playbooks and team readiness
- Manage physical security incidents, including unauthorized access, safety threats, and facility disruptions
- Coordinate with Facilities, HR, Legal, and local authorities during physical security events
- Align physical security controls with cybersecurity, business continuity, and compliance programs
- Coordinate technical responders and non-technical stakeholders throughout incidents
- Direct Security Operations, Engineering, IT, Legal, Compliance, Communications, and Executive Leadership during the incident lifecycle
- Engage law enforcement, emergency services, regulators, and vendors when required
- Maintain response playbooks and escalation paths
- Support SOC 2 Type I and Type II compliance, including control ownership, evidence collection, auditor coordination, and remediation tracking
- Support ISO/IEC 27001 alignment, including risk assessments, Statement of Applicability support, and control mapping
- Support GLBA Safeguards Rule obligations, vendor oversight, and risk documentation
- Conduct risk assessments and control-effectiveness reviews
- Support regulator, auditor, and customer due-diligence requests
- Define and track incident response and compliance KPIs
- Report metrics and program status to Executive Leadership
- Maintain incident response plans, IAP templates, after-action reports, GRC documentation, policies, standards, procedures, risk register, control evidence, audit responses, remediation records, escalation matrices, and contact trees
Requirements
What you’ll need- 3–5 years of experience in incident response, GRC, or risk management, preferably in a regulated environment such as fintech or financial services
- Direct experience serving as Incident Commander or in a comparable incident leadership role, including running IAPs and post-incident reviews
- Familiarity with SOC 2 and GLBA Safeguards Rule compliance programs
- Working knowledge of ISO/IEC 27001
- Experience building and tracking KPIs/metrics for incident response and compliance programs
- Strong written documentation skills; comfortable producing audit-ready records under time pressure
- Professional certifications such as ICS-100/200 preferred
- Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent experience/certifications
- Ability to work in-office as part of the role’s regular schedule
- Ability to perform the essential physical functions of the position, including frequent sitting, repetitive wrist motions, grasping, speaking, listening, close vision, and focus adjustment; occasional lifting/carrying of 20 lbs or less and other movement as required
Benefits
Comp & perks- Comprehensive Medical, Dental, and Vision Insurance
- Generous Paid Time Off
- Birthday Day Off
- 12 Paid Company Holidays
- 401(k) Match
- FSA and HSA
- Paid Life Insurance
- Paid Disability Insurance
- Pet Insurance
- Employee Assistance Program (EAP)
- Professional Development Courses
- In Office Provided Snacks and Drinks
- Gym Facilities (LA & Tustin/CEC Offices)
- In Office Engagement Activities
