View all jobs

Cyber Security Defense Manager - Incident Response

  • Las Vegas, NV

Fusion HCR is Hiring!

Position: Cyber Security Defense Manager – Incident Response
Location: Las Vegas, NV (Hybrid, Local Candidates Only)
Type: Direct Hire
Industry: Gaming

Position Overview
Client of Fusion HCR is seeking an experienced Cyber Security Defense Manager – Incident Response to oversee the full incident response lifecycle for a premier casino entertainment organization. This role will manage day-to-day incident response operations, drive continuous improvement of threat detection capabilities, and lead a critical transition of MSSP (Managed Security Service Provider) services to a new partner. The ideal candidate brings deep incident response leadership experience, strong technical detection knowledge, and proven success managing complex vendor transitions in a cybersecurity context.

Key Responsibilities

Incident Response Leadership

  • Oversee the full incident response lifecycle: preparation, identification, containment, eradication, recovery, and post-incident lessons learned (per NIST SP 800-61 or similar frameworks)
  • Manage day-to-day incident response operations, including triage, investigation coordination, forensic analysis, and executive-level reporting
  • Develop, maintain, and regularly test incident response playbooks, runbooks, and escalation procedures

Detection Engineering & Capability Enhancement

  • Drive continuous improvement of threat detection engineering, including SIEM rule tuning, EDR/XDR configuration, threat intelligence integration, and behavioral analytics
  • Collaborate with SOC, threat hunting, and security engineering teams to reduce false positives and accelerate MTTD/MTTR
  • Lead initiatives to mature internal blue-team capabilities across endpoints, cloud, identity, network, and email environments

MSSP Transition Management

  • Lead the end-to-end transition of MSSP services from the current provider to a new partner, including planning, knowledge transfer, contract/SLA alignment, and cutover execution
  • Conduct due diligence on the new MSSP, define transition success criteria, and mitigate risks during handover
  • Establish governance for the new MSSP relationship, including performance monitoring, service reviews, and incident handoff protocols
  • Ensure the transition strengthens rather than disrupts detection and response effectiveness

Team Leadership & Development

  • Build, mentor, and lead a high-performing incident response team of internal analysts, responders, and cross-functional partners
  • Provide performance management, career development, and technical coaching to team members
  • Foster a culture of continuous learning through tabletop exercises, red/blue team simulations, and post-incident reviews

Stakeholder Collaboration & Reporting

  • Serve as primary point of contact for major incidents, briefing executive leadership, legal, compliance, and external regulators as needed
  • Coordinate with IT, legal, risk, business units, and external partners (e.g., law enforcement, forensics firms) during incidents
  • Produce executive-level reports on incident trends, program maturity, detection improvements, and transition status

Program Maturity & Compliance

  • Align incident response practices with industry standards (NIST, ISO 27001, MITRE ATT&CK, etc.) and regulatory requirements
  • Drive metrics-driven improvements and maturity assessments for the IR program
  • Contribute to enterprise-wide security initiatives, including vulnerability management, threat intelligence, and security awareness

Required Qualifications

  • 10+ years of progressive cybersecurity experience, including 5+ years in incident response, digital forensics, or security operations leadership
  • Proven experience leading cyber incident response teams and managing complex, high-impact incidents
  • Demonstrated success in vendor/MSSP transitions or outsourcing handovers in a cybersecurity context
  • Strong understanding of detection technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms)
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field (Master's preferred)
  • Relevant certifications such as CISSP, CISM, GIAC GCFA/GCIH/GCTI, or similar

Preferred Qualifications

  • Experience in a regulated industry (finance, healthcare, critical infrastructure, or gaming)
  • Hands-on technical experience with tools such as Splunk, Elastic, CrowdStrike, Microsoft Defender, Sentinel, or similar
  • Prior experience building or maturing an internal SOC/IR function while reducing MSSP dependency

Why Join?
This is a high-visibility leadership opportunity to build and mature a critical incident response function, lead a strategic MSSP transition, and shape long-term security program maturity for a premier gaming organization.