Lead Cyber Incident Management
- Salary
- $118.4K–$219.8K
- Hiring from
- United States
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
Job Description: Lead Cyber Incident Management
- Enterprise Security Incident Management (ESIM)
Thomson Reuters' Information Security Risk Management team is looking for a Lead Cyber Incident Management to help mature and strengthen our enterprise incident management capabilities.
This role focuses on incident management and process. It is not a hands-on technical forensics role. As Lead Cyber Incident Management you will help lead and manage the response to major cyber incidents. That means keeping teams aligned, tracking actions, keeping communications clear and limiting business impact.
You will be a key point of contact during significant security events. You'll work with the Director, Cyber Incident Management, to drive timely and effective incident response. You'll also manage coordination between technical and business stakeholders, own incident records, lead communications and reporting, and make sure corrective actions are completed after an incident.
The role reports directly to the VP of Cyber Defense and works closely with the Director, Cyber Incident Management, who leads the ESIM function.
Key Responsibilities
- Manage cyber incidents through the full lifecycle, from activating cross-functional partners through to incident closure.
- Lead incident bridges, command calls and working sessions. Keep them structured, track decisions, assign owners and timelines, and make sure stakeholders understand their roles and the path to resolution.
- Support incident management calls chaired by the Chief Information Security Officer by documenting action items, confirming owners and deadlines, and tracking actions to completion.
- Oversee smaller working groups formed during incidents, and give visibility into their tasks, owners, progress and dependencies.
- Own and maintain the incident record, including timestamped observations, actions, contacts, decisions and other relevant documentation.
- Prepare and manage incident materials, including executive communications, status reports, fact summaries and materials needed for notification or disclosure obligations.
- Give clear written and verbal updates to executive and business stakeholders throughout the incident lifecycle.
- Lead post-incident reviews. Reconstruct timelines, identify detection gaps, response delays and communication breakdowns, and turn the findings into corrective actions with accountable owners.
- Track long-term remediation and work with risk management and technical teams to make sure complex issues are resolved after incident closure.
- Design and lead two executive-level tabletop exercises each year, including scenario development, timed injects, facilitator and observer materials, after-action reports and improvement plans.
- Assess incident management and response capabilities against recognized frameworks, and work with security teams to drive cross-functional process improvements.
- Maintain ESIM documentation, including SharePoint sites, incident records, runbooks, escalation lists, contact lists and exercise materials.
- Track and report performance measures that show improvement in areas such as corrective action closure rates and repeat incident rates.
- Serve on a 24x7 global incident response team on an escalation basis for major incidents, including off-hours or weekend support as needed.
Required Qualifications
- Bachelor's degree or equivalent relevant experience.
- Three or more years of experience supporting or leading processes, programs or operations in Information Technology, Information Security, risk management or a related field.
- Experience participating in or leading a major incident bridge, command call, war room or similar high-pressure environment.
- Proven ability to manage and align stakeholders, including senior leaders, without direct authority.
- Working knowledge of an incident management framework such as NIST SP 800-61 or ITIL Major Incident Management, including severity classification and escalation criteria.
- Enough technical knowledge to understand and accurately document active cyber incident response discussions, risks, actions and decisions.
- Ability to write concise, accurate executive communications and status updates under time pressure.
- Strong ability to turn complex technical issues into clear, actionable information for business and executive audiences.
- Excellent written and verbal communication skills, including the ability to build reports and presentations for executives.
- Strong organizational, critical-thinking and attention-to-detail skills, especially when maintaining records that may be used for evidentiary or regulatory purposes.
- Proficiency with Microsoft 365 tools, including SharePoint, Teams and Microsoft Office.
- Ability to work well in a dynamic environment with ambiguity, competing priorities and fast turnaround times.
- Strong interpersonal and stakeholder-management skills, with the ability to influence and deliver across multiple teams.
- Flexibility to support off-hours and weekend incident response when needed.
Preferred Qualifications
- Bachelor's degree in Information Technology, Information Systems, Cybersecurity or a related field.
- Experience leading or supporting cybersecurity incident response programs or enterprise major incident management processes.
- Experience designing or leading tabletop exercises, simulations, crisis-management exercises or structured training programs.
- Experience building post-incident review processes, corrective action plans and long-term remediation tracking.
- Familiarity with executive crisis communications, regulatory notification processes or enterprise risk management practices.
- Experience supporting incident response maturity assessments and process improvement initiatives.
- Familiarity with security operations, threat detection, digital forensics, vulnerability management or other cybersecurity functions.
- Experience leading or mentoring others, or a clear interest in moving into people and function leadership.
What’s in it For You?
- Hybrid Work Model: We’ve adopted a flexible hybrid working environment for our office-based roles while delivering a seamless experience that is digitally and physically connected.
- Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance.
- Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow’s challenges and deliver real-world solutions. Our Grow My Way programming and skills-first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI-enabled future.
- Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.
- Culture: Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more. We live by our values: Obsess over our Customers, Compete to Win, Challenge (Y)our Thinking, Act Fast / Learn Fast, and Stronger Together.
- Social Impact: Make an impact in your community with our Social Impact Institute. We offer employees two paid volunteer days off annually and opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.
- Making a Real-World Impact: We are one of the few companies globally that helps its customers pursue justice, truth, and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.
Our use of AI within the recruitment process Thomson Reuters utilizes Artificial Intelligence (AI) to support parts of our global recruitment process. Unless you opt-out, our AI system will assess the information provided by you and compare it to the requirements listed for the role, and present the result to our recruitment personnel for further review. The AI system acts as a supporting tool, but there is always a human making the decision if you will be considered for the role.In the United States, Thomson Reuters offers a comprehensive benefits package to our employees. Our benefit package includes market competitive health, dental, vision, disability, and life insurance programs, as well as a competitive 401k plan with company match. In addition, Thomson Reuters offers market leading work life benefits with competitive vacation, sick and safe paid time off, paid holidays (including two company mental health days off), parental leave, sabbatical leave. These benefits meet or exceeds the requirements of paid time off in accordance with any applicable state or municipal laws. Finally, Thomson Reuters offers the following additional benefits: optional hospital, accident and sickness insurance paid 100% by the employee; optional life and AD&D insurance paid 100% by the employee; Flexible Spending and Health Savings Accounts; fitness reimbursement; access to Employee Assistance Program; Group Legal Identity Theft Protection benefit paid 100% by employee; access to 529 Plan; commuter benefits; Adoption & Surrogacy Assistance; Tuition Reimbursement; and access to Employee Stock Purchase Plan.Thomson Reuters complies with local laws that require upfront disclosure of the expected pay range for a position. The base compensation range varies across locations.
For any eligible US locations, unless otherwise noted, the base compensation range for this role is $118,400 USD - $219,800 USD.
For Ontario, Canada, the base compensation range for this role is $140,000 CAD - $175,000 CAD.
Base pay is positioned within the range based on several factors including an individual’s knowledge, skills and experience with consideration given to internal equity. Base pay is one part of a comprehensive Total Reward program which also includes flexible and supportive benefits and other wellbeing programs.
This role may also be eligible for an Annual Bonus based on a combination of enterprise and individual performance.
About Us
Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. We serve professionals across legal, tax, accounting, compliance, government, and media. Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.
We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments. At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.
As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug-free workplace.
Thomson Reuters makes reasonable accommodations for applicants with disabilities, including veterans with disabilities, and for sincerely held religious beliefs in accordance with applicable law. If you reside in the United States and require an accommodation in the recruiting process, you may contact our Human Resources Department at HR.Leave-Expert@thomsonreuters.com. Disability accommodations in the recruiting process may include things like a sign language interpreter, making interview rooms accessible, providing assistive technology, or other relevant accommodations. Please note this email is not intended for general recruitment questions and we will promptly respond to inquiries regarding accommodations. More information on requesting an accommodation here.
Learn more on how to protect yourself from fraudulent job postings here.
More information about Thomson Reuters can be found on thomsonreuters.com
At Thomson Reuters, we’re not riding the AI wave — we’re reshaping the future of professional work across law, tax, compliance, and journalism.
Here, you will collaborate with smart, ambitious people who thrive on solving complex problems, delivering market-leading solutions, and innovating with curiosity and care.
Learn more about a career with us
Future-ready careers
Our focus on a skills-first approach ensures you’ll have the tools and knowledge to grow, lead, and thrive in an AI-enabled future.