10279 - Security Incident Response Manager
10279- Manager, Security Incident Response
Location: Irvine, HQ
Company Overview
Hyundai AutoEver America (HAEA) is the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis.
HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group.
At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations.
If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation.
Website: www.haeaus.com
Role Overview
The Incident Response Manager is a senior cybersecurity professional responsible for coordinating and supporting enterprise-wide incident response activities across Hyundai AutoEver America's technology environment. This role plays a critical part in identifying, investigating, containing, and remediating cybersecurity incidents while helping strengthen organizational resilience against evolving cyber threats.
This role coordinates enterprise-wide incident response efforts and serves as a key contributor throughout the incident lifecycle, partnering with internal teams, external vendors, and managed security service providers to ensure timely and effective response activities.
Key Responsibilities
- Support enterprise-wide cybersecurity incident response activities throughout the incident lifecycle, including detection, investigation, containment, remediation, and documentation.
- Coordinate and participate in security investigations involving internal teams, third-party vendors, and MSSPs.
- Monitor, analyze, and evaluate server, endpoint, network, and security event data to identify suspicious activity and emerging threats.
- Investigate security alerts and indicators of compromise using SIEM, EDR, and related security tools.
- Support incident communications, escalation activities, and stakeholder coordination during cybersecurity events.
- Maintain and enhance the Security Incident Response Plan (SIRP) in alignment with NIST, ISO 27035, and MITRE ATT&CK.
- Participate in tabletop exercises and readiness assessments.
- Leverage threat intelligence to improve detection and response effectiveness.
- Track incident response metrics, KPIs, and operational reporting requirements.
Basic Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline, or equivalent work experience, and 8+ years of experience in cybersecurity operations, incident response, security monitoring, threat detection, or a related information security function.
- Experience participating in and coordinating cybersecurity incident investigations and remediation efforts.
- Strong understanding of threat landscapes, attack vectors, malware behavior, indicators of compromise, and incident response methodologies.
- Experience utilizing and interpreting security data from SIEM, EDR, and other security monitoring technologies.
- Ability to analyze security events and communicate findings to stakeholders.
Preferred Qualifications
- Master's degree or higher in Cybersecurity, Information Technology, Computer Science, or a related discipline, or equivalent work experience, and 8+ years of experience in cybersecurity operations, incident response, threat detection, security monitoring, or a related information security function.
- Industry-recognized certifications such as GCIH, GCFA, GCIA, GNFA, CISSP, CISM, Security+, or CySA+.
- Experience working with MSSPs.
- Experience supporting SIRP, readiness initiatives, and tabletop exercises.
- Familiarity with AWS, Azure, and GCP.
Salary Range: $118,650 - $182,710
In addition to a competitive salary, this position offers a fantastic benefits package that includes comprehensive medical/dental coverage, generous PTO, education assistance, and annual merit increase eligibility in a growth-focused work environment.