About this role
Incident Response & Cyber Resilience Lead (Contract)
ascio is hiring an Incident Response & Cyber Resilience Lead to support our cybersecurity preparedness, incident response planning and resilience work.
This role will assess incident response capability, develop plans and playbooks, design and facilitate exercises, and help organizations strengthen their ability to respond to and recover from cybersecurity incidents.
Responsibilities- Assess incident response capability against recognized cybersecurity and incident management frameworks.
- Develop incident response plans covering roles, escalation, severity classification, communications and decision-making.
- Develop playbooks for ransomware, business email compromise, data breach, insider misuse, denial-of-service and third-party compromise scenarios.
- Design and facilitate executive tabletop exercises and technical functional exercises.
- Conduct after-action reviews and develop practical corrective action plans.
- Review incident escalation, communications and coordination processes.
- Advise on cyber incident recovery priorities, including backup validation and restoration planning.
- Support planning for privacy, regulatory, contractual and insurance-related notification requirements.
- Prepare clear reports and recommendations for technical, executive and governance audiences.
- Eight or more years of experience in incident response, security operations, cybersecurity or organizational resilience.
- Strong experience developing incident response plans and playbooks.
- Knowledge of NIST SP 800-61 and ISO/IEC 27035.
- Experience designing exercises with defined objectives, injects and evaluation criteria.
- Experience facilitating executive tabletop exercises and technical response exercises.
- Strong understanding of security operations tooling, including SIEM and EDR technologies.
- Knowledge of forensic evidence preservation and incident documentation.
- Experience with ransomware response planning, backup validation and recovery prioritization.
- Experience coordinating incident response across technical, legal, privacy, communications and management functions.
- Strong written and verbal communication skills.
- One or more current professional certifications such as GCIH, GCFA, GCIA, CISM, CISSP, CBCP or an equivalent cybersecurity or resilience credential.
- Applicants must be able to provide certification status and expiry or renewal dates, where applicable.
- Degree or diploma in cybersecurity, information systems or a related field, or equivalent professional experience.
- Emergency management, exercise design or incident command training is considered an asset.
- Live cyber incident handling.
- Security Operations Centre leadership.
- Business continuity and ISO 22301.
- Cyber insurance and breach response coordination.
- Operational technology or industrial control system incident response.
- Executive crisis management.
- Cloud security incident response.
- Remote within Canada.
- Some assignments may require occasional onsite work or travel within Canada.
- Applicants must be based in Canada and legally entitled to work in Canada.
- A criminal record check may be required before access to sensitive systems, information or environments.
Compensation Details
$95.00/hour
Ready to apply?
Pay shown up front. Free for job seekers, always.