The Incident Coordinator will exercise agile project management techniques to coordinate Cisco IR Services responses to cyber incidents stemming from external threats. The best candidates for the role have a strong comprehension of incident response, work well with other people and have strong verbal and written communication skills, a sense of diplomacy, ability to anticipate obstacles, and decision-making skills to handle the fast-paced world of incidents. This is not a hands-on technical role.

Essential Responsibilities:

• Coordinate response efforts to cyber incidents caused by external threats that may involve nontraditional working hours
• Serve as a liaison to different businesses and interface with fellow team members and colleagues on other security teams. As-needed, manage relationships with business partners, management, vendors, and external parties
• Lead small to medium sized projects as directed by leadership
• Be a champion for process. Develop and document processes to ensure consistent and scalable response operations
• As requested, develop and deliver metrics to leadership
• Draft communications and report out to customers, immediate leadership and executive management
• Own and manage the teams internal wiki and associated processes and documentation

Basic Qualifications:

• Minimum 3 years of experience in information security
• 4 year degree in Computer Science or a related technical degree, or minimum 6 years of IT experience
• Minimum 1 year of experience in project management

Eligibility Requirements:

• Must be willing to be on-call and work off-shift hours

Desired Characteristics:

• Detailed understanding of Advanced Persistent Threat (APT), Cyber Crime, Hacktivism and associated tactics
• Strong track record of understanding and interest in recognized IT Security-related standards and technologies, demonstrated through training, job experience and/or industry activities
• IT security certifications
• Active US government security clearance
• Industry certifications such as the CISSP, CISM, CISA, PMP, GCIH, and/or GIAC


