Director, Security Incident Response

Intuit
Atlanta, GA

Overview

You will lead the organization responsible for security incident response, bringing together monitoring, detection engineering, investigations, containment/eradication, and validation of defensive capabilities. Your mission is to reduce business impact from incidents while continuously proving and improving defensive capability through measurable outcomes (for example: MTTD/MTTR improvement and validated detection coverage).


Responsibilities

Lead Incident Response & Security Operations Outcomes

  • Own the end-to-end incident lifecycle: triage, investigation, containment, eradication, recovery, and post-incident review, including evidence handling and executive communications.

  • Run and mature monitoring, triage, and escalation processes, ensuring consistent severity classification and fast, repeatable response.

  • Partner with engineering, on-call operations, and security stakeholders to drive durable remediation and prevent recurrence (lessons learned into controls, detections, and playbooks).

  • Scale detection AI-enabled engineering and response to reduce analyst toil and shrink time-to-containment.

Defensive Capability Validation and Testing

  • Run continuous, scoped validation of defensive controls using targeted attack-surface tests and technique-level checks.

  • Oversee penetration testing management, including coverage planning, vendor governance, retesting, and cost control.

Strategy, Metrics, and Executive Reporting

  • Establish a metrics program covering MTTD, MTTR, containment speed, detection quality, ATT&CK-informed coverage, and remediation SLAs, with board-ready narratives.

  • Provide regular incident and validation readouts to executive and product leadership to support risk-based decision-making.

  • Coordinate with GRC/Legal to support breach notification obligations and provide incident evidence for audits and compliance.

Build the Team & Operating Model

  • Lead managers and senior ICs across SOC/IR, detection engineering, automation, and adversary management/validation.

  • Set on-call and incident command expectations, develop career paths, hire and retain talent, and manage budget and tooling (SIEM/SOAR/EDR, threat intel, validation platforms).


Qualifications

Minimum Qualifications

  • 10+ years in security with significant depth in incident response and security operations, including leading major incidents as an incident commander.

  • Strong technical knowledge across cloud and enterprise environments (identity, endpoints, network, logging/telemetry, and common attacker tradecraft).

  • Proven ability to brief executives clearly during high-pressure events and drive alignment across engineering, IT, legal, and risk stakeholders.

Preferred Qualifications

  • Hands-on expertise with SIEM/SOAR engineering, detection-as-code, and automation; familiarity with MITRE ATT&CK and threat-informed defense measurement.

How Success Will Be Measured

  • Reduced MTTD/MTTR and fewer repeat incident classes due to durable fixes.

  • Increased validated detection/response coverage and signal quality, with faster containment.

Working Relationships

Close partnership with Cloud Operations, Product Security, Identity/Endpoint teams, and GRC/Legal for incident coordination, evidence handling, and reporting.

Intuit provides a competitive compensation package with a strong pay for performance rewards approach. This position may be eligible for a cash bonus, equity rewards and benefits, in accordance with our applicable plans and programs (see more about our compensation and benefits at [1] Intuit: Careers | Benefits). Pay offered is based on factors such as job-related knowledge, skills, experience, and work location. To drive ongoing fair pay for employees, Intuit conducts regular comparisons across categories of ethnicity and gender. The expected base pay range for this position: Bay Area California $307,000- 415,500 Southern California $276,500- 374,000 References Visible links 1. Mountain View $307000 - $415500
Atlanta, GA $267500- $361500
San Diego, CA $276500- $374000

Posted 2026-04-14

Recommended Jobs

Unbranded Sales Intern (Summer 2026)

RaceTrac
Atlanta, GA

The Unbranded Sales Intern will support Gulf Inc’s Supply and Trading team. This role provides exposure to multiple areas of the business and is ideal for a student interested in energy markets, anal…

View Details
Posted 2025-12-02

School Technology Specialist - Atlanta, GA

Inspiroz
Atlanta, GA

Inspiroz is seeking a driven, detail-oriented School Technology Specialist (STS) to join our on-site IT support team in Atlanta. As an STS, you will play a crucial role in supporting the day-to-day t…

View Details
Posted 2026-01-15

Dairy Queen Maintenance Tech

Meadowbrook Treats
Blue Ridge, GA

Meadowbrook has been an established company since 1932, when then founder Fred Weir Sr. opened his restaurant to provide all the missing elements in our world today. He desired to provide a place w…

View Details
Posted 2025-08-18

Patient Experience Specialist

MaKai Consulting, LLC
Statesboro, GA

At Chatham Oral Surgery, the Patient Experience Specialist will interact with our valuable patients by addressing inquiries and resolving complaints. You will be able to connect with a patient in a v…

View Details
Posted 2026-03-19

Engineer II

Marriott
Atlanta, GA

POSITION SUMMARY Respond and attend to guest repair requests. Communicate with guests/customers to resolve maintenance issues with little to no supervision. Perform preventive maintenance on tools…

View Details
Posted 2026-03-20

Primary Care - Savannah, GA

National Health Partners
Savannah, GA

Job Description Job Description Primary Care – Savannah , Georgia & Surrounding South Carolina Full-time employed openings available now with a hospital-affiliated medical group. Highlight…

View Details
Posted 2026-04-08

Part Time Dairy Frozen Clerk

Harris Teeter
Stockbridge, GA

  This is a part time position.  Responsible for processing/stocking products according to Dairy/Frozen Standards, cleaning work areas, providing customer service, unloading stock, and reloading salv…

View Details
Posted 2026-04-08

HIM Associate I

Piedmont Healthcare Inc.
Augusta, GA

Overview: This position is onsite-Augusta, GA Responsibilities: RESPONSIBLE FOR: Responsible and accountable for prepping, scanning and indexing of all clinical documents received in the HIM de…

View Details
Posted 2026-04-15

QSR MAINTENANCE

Jones Petroleum Co
Palmetto, GA

Job Description Job Description Description: Job Title: QSR Maintenance Company: Convenience Stores Inc | Jones Petroleum Direct Link to apply: jonespetroleum.com Pay: Based on experien…

View Details
Posted 2026-03-17

Marketing Assistant

SS Solutions
Georgia

Social Status Solutions is seeking a vibrant, energetic, and dedicated entry-level Marketing Assistant to join our growing team! Our firm has been in the Atlanta area and was founded on the principle…

View Details
Posted 2026-02-17