SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
iCapital is seeking a Cyber Case Manager to join the Global Information Security team within Cyber Security Operations. This is an individual-contributor role reporting to the Security Operations leader, responsible for owning the end-to-end lifecycle of security cases from intake through resolution.
Key responsibilities include:
- Own case lifecycle management including intake, assignment, progress tracking, and closure, serving as the single point of accountability for case status across the SOC
- Exercise authority to assign, reprioritize, and escalate cases across SOC Analysts, Threat Detection Engineering, and Incident Response teams to eliminate bottlenecks
- Enforce case-handling SLAs and quality standards; proactively identify aging, blocked, or at-risk cases and escalate to leadership
- Coordinate cross-functional workstreams spanning incident response, digital forensics/incident response (DFIR), insider-threat investigations, vulnerability remediation, audit/GRC findings, and eDiscovery/legal-hold requests
- Manage case documentation and evidence integrity, ensuring timelines, actions, decisions, and artifacts are captured consistently and remain audit-ready
- Integrate case workflows with SIEM/SOAR platforms so alerts and automated actions flow seamlessly into case records
- Produce case metrics and leadership reporting including MTTD, MTTR, backlog, aging, closure rates, and SLA adherence
- Build and continuously improve case-management processes, intake criteria, and runbooks to increase throughput
- Facilitate case reviews, shift handoffs, and post-incident lessons-learned sessions
- Leverage SIEM/SOAR platforms with Jira and Confluence as the system of record
- Collaborate with Legal, Compliance, HR, SOC Analysts, Security Engineering, Cloud Security, and business stakeholders on sensitive investigations
- Participate in incident-driven after-hours coordination as needed
Required qualifications: 3–6 years in cyber security operations, incident response, or security case/program management. Bachelor's degree in information security, computer science, or IT preferred. Hands-on experience managing incident/case queues in a SOC or incident response environment. Working knowledge of SIEM and SOAR platforms. Proficiency with Jira and Confluence. Strong understanding of incident response lifecycle and frameworks (NIST, MITRE ATT&CK). Demonstrated ability to coordinate across teams and drive work to closure through influence without direct reporting authority. Familiarity with sensitive investigations, evidence handling, and chain-of-custody principles. Exceptional organization, prioritization, and attention to detail. Excellent written and verbal communication skills.
Preferred: Experience in regulated industries or fintech. Relevant certifications (GCIH, GCFE, PMP, ITIL, Splunk, SOAR). Experience with dedicated case-management or SOAR platforms (ServiceNow SIR, TheHive, Splunk SOAR, Phantom). Exposure to insider-threat, DFIR, eDiscovery, legal-hold, or GRC/audit workflows. Familiarity with cloud environments, particularly AWS.