Hiring.Camp

Cyber Security Incident Response & Threat Intelligence Manager

Ncr

·

Jun 16, 2026

Location
Chennai Embassy Tower Office, India
Type
Full-time
Department
Human Resources
Seniority
Manager
Experience
12+ years
Source
Workday

Description

About NCR VOYIX

NCR Voyix Corporation (NYSE: VYX) is a global platform-powered leader in unified commerce for shopping and dining. Combining a flexible, intelligent platform with end-to-end payments capabilities and services developed through its deep industry experience, NCR Voyix empowers retailers and restaurants to accelerate new possibilities for their operations, experiences and business outcomes. NCR Voyix is headquartered in Atlanta, Georgia, and serves customers in more than 35 countries worldwide.

Cyber Security Incident Response & Threat Intelligence Manager

We are seeking a highly skilled and strategic Cyber Security Incident Response & Threat Intelligence Manager to lead our security operations function. This role combines proactive threat intelligence with advanced incident response leadership, requiring a candidate who can anticipate emerging threats, drive strategic defenses, and lead teams through high-stakes cyber incidents.

The ideal candidate will oversee security monitoring and response capabilities, guide a team of analysts and responders, and partner cross-functionally to strengthen the organization’s security posture.

Key Responsibilities

Incident Response Leadership

  • Lead and manage end-to-end response efforts during active cyber incidents, including detection, containment, eradication, and recovery
  • Serve as incident commander for high-severity events, ensuring timely decision-making and stakeholder communication
  • Oversee deep-dive forensic investigations to determine root cause, scope, and business impact
  • Coordinate cross-functional response efforts with IT, Legal, Compliance, and business stakeholders
  • Establish, maintain, and continuously improve incident response playbooks, processes, and escalation protocols
  • Present post-incident findings, lessons learned, and risk mitigation plans to senior leadership

Threat Intelligence Strategy & Oversight

  • Lead the development and execution of the organization’s threat intelligence strategy
  • Oversee research and tracking of global threat actors, campaigns, and emerging attack techniques
  • Ensure analysis of adversary tactics, techniques, and procedures (TTPs) aligned to frameworks such as MITRE ATT&CK
  • Translate threat intelligence into actionable detection use cases, defensive strategies, and business risk insights
  • Drive integration of threat intelligence into security tooling, detection engineering, and response playbooks
  • Deliver executive-level briefings and intelligence reports tailored to diverse audiences

Detection Engineering & Proactive Defense

  • Provide leadership oversight for proactive monitoring across endpoints, networks, and cloud environments
  • Guide the development of detection logic, correlation rules, and alerting strategies
  • Direct threat hunting initiatives to identify advanced and persistent threats
  • Ensure continuous tuning and optimization of security controls to improve detection fidelity and reduce false positives
  • Partner with engineering and architecture teams to enhance security visibility and coverage

People Leadership & Program Management

  • Lead, mentor, and develop a team of incident responders, threat intelligence analysts, and SOC personnel
  • Establish performance expectations, career development plans, and ongoing coaching for team members
  • Drive operational excellence within the SOC and incident response functions
  • Manage vendor relationships and external partners (e.g., MSSPs, threat intelligence providers)
  • Develop metrics and KPIs to measure program effectiveness and maturity
  • Support budget planning and resource allocation for security operations

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
  • 12+ years of experience in incident response, threat intelligence, or security operations, with leadership experience preferred
  • Proven experience leading incident response efforts and managing high-impact security events
  • Strong understanding of attacker methodologies, malware analysis, and intrusion techniques
  • Experience mapping adversary behaviors to MITRE ATT&CK or similar frameworks
  • Demonstrated ability to communicate complex security concepts to both technical and executive audiences

Technical Expertise

  • Hands-on experience with Endpoint Detection & Response (EDR) tools such as:
    • CrowdStrike Falcon
    • SentinelOne
    • Microsoft Defender for Endpoint
  • Experience with NDR/XDR platforms, including:
    • ExtraHop
    • Cisco XDR
  • Deep familiarity with SIEM platforms, log analysis, and security monitoring tools
  • Strong knowledge of networking protocols, operating systems, and cloud security concepts
  • Experience driving detection engineering and threat hunting programs

Operational Expectations

  • Lead on-call rotation strategy and provide escalation support for critical incidents
  • Ensure rapid and effective response to high-severity threats and vulnerabilities
  • Maintain strong situational awareness of the evolving threat landscape
  • Collaborate with internal leadership and external stakeholders during security events
  • Foster a culture of continuous improvement and operational resilience

Preferred Qualifications

  • Relevant certifications (e.g., CISSP, GCIA, GCIH, GCFA, or equivalent)
  • Experience with scripting or automation (Python, PowerShell)
  • Background in threat hunting, malware analysis, or digital forensics
  • Experience building or scaling security operations or incident response programs

Offers of employment are conditional upon passage of screening criteria applicable to the job

EEO Statement

Integrated into our shared values is NCR Voyix’s commitment to equal employment opportunity.  All qualified applicants will receive consideration for employment without regard to sex, age, race, color, creed, religion, national origin, disability, sexual orientation, gender identity, veteran status, military service, genetic information, or any other characteristic or conduct protected by law.  NCR Voyix is committed to being a globally inclusive company where all people are treated fairly, recognized for their individuality, promoted based on performance and encouraged to strive to reach their full potential.  We believe in understanding and respecting differences among all people.  Every individual at NCR Voyix has an ongoing responsibility to respect and support a globally diverse environment.

Statement to Third Party Agencies
To ALL recruitment agencies: NCR Voyix only accepts resumes from agencies on the preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR Voyix employees, or any NCR Voyix facility. NCR Voyix is not responsible for any fees or charges associated with unsolicited resumes

“When applying for a job, please make sure to only open emails that you will receive during your application process that come from a @ncrvoyix.com email domain.”

Skills

PythonCybersecuritySIEMSOCComplianceProgram ManagementCISSP

Similar Jobs

16

Senior/Lead Cyber Security - Incident Response Engineer

Fico · Work from Home, United States, United States of America · Remote

5 days ago

Associate Manager - Cyber Security Incident Response

LON3 London - 51 Lime Street · London, London, United Kingdom, GB

1 week ago

Cyber Security Incident Co-Ordinator

DXC Technology · UK075 - Corsham, United Kingdom (UK075)

3 weeks ago

Cyber Security Incident Response Analyst (Panamá City, Panamá)

Signify · Panama City - Torre V · Onsite

1 month ago

Cyber Security Incident Response - Assistant Manager

LON3 London - 51 Lime Street · Madrid, Comunidad de Madrid, Spain, ES

1 month ago

Director, Cyber Security Incident Response Team (CSIRT)

Astrazeneca · US - Gaithersburg - MD, United States of America · Hybrid

1 month ago

Director, Cyber Security Incident Response Team (CSIRT)

AstraZeneca is · US - Gaithersburg - MD, United States of America · Hybrid

1 month ago

Senior Cyber Security Incident Response Analyst

Dentsuaegis · India - Karnataka - Bengaluru  - Richmond Road -  Alyssa Building- Level 0 +1

2 months ago

Lead Engineer, Cyber Security, Incident and Threat Responder

Dowjones · NSW - SHS 2 Holt Street Surry Hills, Australia +1

2 months ago

Cyber Security Incident Response

LON3 London - 51 Lime Street · Gurgaon, Haryana, India

3 months ago

Cyber Security Incident Response Expert

Pwc · Praha - Hvezdova 1734/2c, Czechia +1

5 months ago

Information Security Cyber Defense Incident Responder

Zillow · Bengaluru, India · Onsite

3 weeks ago

Cyber Security Operations Incident Responder/Swing- Shift Lead Analyst

Teksynap · Fort Belvoir, VA, US

1+ year ago

Senior Security Engineer – Cyber Hunting & Incident Response – 3rd Shift

Truist · Zebulon NC - 49 Green Pace Road, United States of America · Onsite

1 week ago

Senior Security Engineer – Cyber Hunting & Incident Response

Truist · Atlanta GA - 303 Peachtree Center Avenue - Garden Offices, United States of America +1 · Onsite

2 weeks ago

Cybersecurity Security Operations and Crisis / Incident Management | Director | Cyber Consulting | Advisory

Pwc · Dublin - One Spencer Dock, Ireland +1

6 months ago