SlipstreamJobsFresh Startup & VC-Backed Jobs

Cyber Case Manager - Assistant Vice President

iCapital - Salt Lake City, UT, United States - In-office - posted 2026-08-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

iCapital is seeking a Cyber Case Manager to join the Global Information Security team within Cyber Security Operations. This is an individual-contributor role reporting to the Security Operations leader, responsible for owning the end-to-end lifecycle of security cases from intake through resolution. Key responsibilities include: - Own case lifecycle management including intake, assignment, progress tracking, and closure, serving as the single point of accountability for case status across the SOC - Exercise authority to assign, reprioritize, and escalate cases across SOC Analysts, Threat Detection Engineering, and Incident Response teams to eliminate bottlenecks - Enforce case-handling SLAs and quality standards; proactively identify aging, blocked, or at-risk cases and escalate to leadership - Coordinate cross-functional workstreams spanning incident response, digital forensics/incident response (DFIR), insider-threat investigations, vulnerability remediation, audit/GRC findings, and eDiscovery/legal-hold requests - Manage case documentation and evidence integrity, ensuring timelines, actions, decisions, and artifacts are captured consistently and remain audit-ready - Integrate case workflows with SIEM/SOAR platforms so alerts and automated actions flow seamlessly into case records - Produce case metrics and leadership reporting including MTTD, MTTR, backlog, aging, closure rates, and SLA adherence - Build and continuously improve case-management processes, intake criteria, and runbooks to increase throughput - Facilitate case reviews, shift handoffs, and post-incident lessons-learned sessions - Leverage SIEM/SOAR platforms with Jira and Confluence as the system of record - Collaborate with Legal, Compliance, HR, SOC Analysts, Security Engineering, Cloud Security, and business stakeholders on sensitive investigations - Participate in incident-driven after-hours coordination as needed Required qualifications: 3–6 years in cyber security operations, incident response, or security case/program management. Bachelor's degree in information security, computer science, or IT preferred. Hands-on experience managing incident/case queues in a SOC or incident response environment. Working knowledge of SIEM and SOAR platforms. Proficiency with Jira and Confluence. Strong understanding of incident response lifecycle and frameworks (NIST, MITRE ATT&CK). Demonstrated ability to coordinate across teams and drive work to closure through influence without direct reporting authority. Familiarity with sensitive investigations, evidence handling, and chain-of-custody principles. Exceptional organization, prioritization, and attention to detail. Excellent written and verbal communication skills. Preferred: Experience in regulated industries or fintech. Relevant certifications (GCIH, GCFE, PMP, ITIL, Splunk, SOAR). Experience with dedicated case-management or SOAR platforms (ServiceNow SIR, TheHive, Splunk SOAR, Phantom). Exposure to insider-threat, DFIR, eDiscovery, legal-hold, or GRC/audit workflows. Familiarity with cloud environments, particularly AWS.

Similar roles