Cyber Security Defense Manager - Incident Response
Fusion HCR is Hiring!
Position: Cyber Security Defense Manager – Incident Response
Location: Las Vegas, NV (Hybrid, Local Candidates Only)
Type: Direct Hire
Industry: Gaming
Position Overview
Client of Fusion HCR is seeking an experienced Cyber Security Defense Manager – Incident Response to oversee the full incident response lifecycle for a premier casino entertainment organization. This role will manage day-to-day incident response operations, drive continuous improvement of threat detection capabilities, and lead a critical transition of MSSP (Managed Security Service Provider) services to a new partner. The ideal candidate brings deep incident response leadership experience, strong technical detection knowledge, and proven success managing complex vendor transitions in a cybersecurity context.
Key Responsibilities
Incident Response Leadership
- Oversee the full incident response lifecycle: preparation, identification, containment, eradication, recovery, and post-incident lessons learned (per NIST SP 800-61 or similar frameworks)
- Manage day-to-day incident response operations, including triage, investigation coordination, forensic analysis, and executive-level reporting
- Develop, maintain, and regularly test incident response playbooks, runbooks, and escalation procedures
Detection Engineering & Capability Enhancement
- Drive continuous improvement of threat detection engineering, including SIEM rule tuning, EDR/XDR configuration, threat intelligence integration, and behavioral analytics
- Collaborate with SOC, threat hunting, and security engineering teams to reduce false positives and accelerate MTTD/MTTR
- Lead initiatives to mature internal blue-team capabilities across endpoints, cloud, identity, network, and email environments
MSSP Transition Management
- Lead the end-to-end transition of MSSP services from the current provider to a new partner, including planning, knowledge transfer, contract/SLA alignment, and cutover execution
- Conduct due diligence on the new MSSP, define transition success criteria, and mitigate risks during handover
- Establish governance for the new MSSP relationship, including performance monitoring, service reviews, and incident handoff protocols
- Ensure the transition strengthens rather than disrupts detection and response effectiveness
Team Leadership & Development
- Build, mentor, and lead a high-performing incident response team of internal analysts, responders, and cross-functional partners
- Provide performance management, career development, and technical coaching to team members
- Foster a culture of continuous learning through tabletop exercises, red/blue team simulations, and post-incident reviews
Stakeholder Collaboration & Reporting
- Serve as primary point of contact for major incidents, briefing executive leadership, legal, compliance, and external regulators as needed
- Coordinate with IT, legal, risk, business units, and external partners (e.g., law enforcement, forensics firms) during incidents
- Produce executive-level reports on incident trends, program maturity, detection improvements, and transition status
Program Maturity & Compliance
- Align incident response practices with industry standards (NIST, ISO 27001, MITRE ATT&CK, etc.) and regulatory requirements
- Drive metrics-driven improvements and maturity assessments for the IR program
- Contribute to enterprise-wide security initiatives, including vulnerability management, threat intelligence, and security awareness
Required Qualifications
- 10+ years of progressive cybersecurity experience, including 5+ years in incident response, digital forensics, or security operations leadership
- Proven experience leading cyber incident response teams and managing complex, high-impact incidents
- Demonstrated success in vendor/MSSP transitions or outsourcing handovers in a cybersecurity context
- Strong understanding of detection technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms)
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field (Master's preferred)
- Relevant certifications such as CISSP, CISM, GIAC GCFA/GCIH/GCTI, or similar
Preferred Qualifications
- Experience in a regulated industry (finance, healthcare, critical infrastructure, or gaming)
- Hands-on technical experience with tools such as Splunk, Elastic, CrowdStrike, Microsoft Defender, Sentinel, or similar
- Prior experience building or maturing an internal SOC/IR function while reducing MSSP dependency
Why Join?
This is a high-visibility leadership opportunity to build and mature a critical incident response function, lead a strategic MSSP transition, and shape long-term security program maturity for a premier gaming organization.