Why This Role Stands Out
As the Cyber Case Manager at iCapital, you will drive critical security incident resolution, gaining valuable experience in end-to-end case management within a growing Global Information Security team. This role is ideal for a proactive leader who thrives on accountability and ensuring efficient, documented processes to protect the organization. Embrace this opportunity to shape the future of cybersecurity operations and advance your career.
Quick Overview
Job Description
About the Role
iCapital is seeking a Cyber Case Manager to join the Global Information Security team within Cyber Security Operations. As the Security Operations Center (SOC) continues to grow, dedicated ownership of the case lifecycle has become essential to ensuring incidents and investigations are consistently tracked and driven to closure. The Cyber Case Manager serves as the single point of accountability for that lifecycle – from intake through resolution – ensuring every case is owned, prioritized, progressing, and documented. This individual-contributor will report to the Security Operations leader.
Responsibilities
- Own the end-to-end lifecycle of security cases including intake, ownership assignment, progress tracking, and driving cases to resolution and closure.
- Serve as the single point of accountability for case status across the SOC, maintaining an accurate, prioritized, real-time view of all open incidents and investigations.
- Exercise authority to assign, reprioritize, and escalate cases across SOC Analysts, Threat Detection Engineering, and Incident Response to keep work moving and eliminate stalled cases.
- Enforce case-handling SLAs and quality standards; proactively identify aging, blocked, or at-risk cases and escalate to the Security Operations Leader.
- Coordinate cross-functional workstreams spanning incident response, DFIR, insider-threat cases, vulnerability-remediation tracking, audit and GRC findings, and eDiscovery and legal-hold requests.
- Manage case documentation and evidence integrity – ensuring timelines, actions, decisions, and artifacts are captured consistently and remain audit-ready.
- Integrate case workflows with SIEM/SOAR so alerts, enrichment, and automated actions flow into and out of the case record without manual re-keying.
- Produce case metrics and leadership reporting, including MTTD, MTTR, backlog, aging, closure rates, and SLA adherence for SOC leadership and stakeholders.
- Build and continuously improve case-management processes, intake criteria, and runbooks to increase throughput and reduce manager overhead.
- Facilitate case reviews, shift and regional handoffs, and post-incident lessons-learned, ensuring action items are tracked to completion.
- Leverage the SOC’s SIEM and SOAR platforms, with Jira and Confluence as the system of record.
- Collaborate with Legal, Compliance, Human Resources, SOC Analysts, Security Engineering, Cloud Security, Incident Response, and business stakeholders to support sensitive investigations, maintain confidentiality and chain of custody, and strengthen iCapital’s overall cyber resiliency.
- Participate in incident-driven after-hours coordination as needed to keep high-priority cases moving.
Qualifications
- 3–6 years of experience in cyber security operations, incident response, or security case and program management
- Bachelor’s degree in information security, computer science, or information technology is preferred
- Experience in a regulated industry; financial services or fintech is preferred
- Hands-on experience managing incident or case queues in a SOC or incident response environment
- Working knowledge of SIEM and SOAR platforms and how alerts and cases flow through them
- Proficiency with Jira and Confluence for workflow management, tracking, and documentation
- Strong understanding of the incident response lifecycle and frameworks such as NIST and MITRE ATT&CK
- Demonstrated ability to coordinate across teams and drive work to closure through influence and follow-through, without direct reporting authority over those teams
- Familiar with handling sensitive investigations, evidence handling, and chain-of-custody principles
- Exceptional organization, prioritization, and attention to detail while managing many concurrent cases
- Excellent written and verbal communication skills, with the ability to report status clearly to both technical and executive audiences
- Relevant certifications (i.e. GCIH, GCFE, PMP, ITIL, or Splunk and SOAR) are preferred
- Experience with dedicated case-management or SOAR platforms (i.e. ServiceNow SIR, TheHive, Splunk SOAR and Phantom)
- Exposure to insider-threat, DFIR, eDiscovery, legal-hold, or GRC and audit workflows
- Familiar with cloud environments, AWS is preferred and knowledge of Agile frameworks is preferred
Benefits
The base salary range for this role is $100,000 to $130,000. iCapital offers a compensation package which includes salary, equity for all full-time employees, and an annual performance bonus. Employees also receive a comprehensive benefits package that includes an employer matched retirement plan, generously subsidized healthcare with 100% employer paid dental, vision, telemedicine, and virtual mental health counseling, parental leave, and unlimited paid time off (PTO).
We believe the best ideas and innovation happen when we are together. Employees in this role will work in the office Monday-Thursday, with the flexibility to work remotely on Friday.
For additional information on iCapital, please visit https://www.icapitalnetwork.com/about-us Twitter: @icapitalnetwork | LinkedIn: https://www.linkedin.com/company/icapital-network-inc | Awards Disclaimer: https://www.icapitalnetwork.com/about-us/recognition/
iCapital is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender, sexual orientation, gender identity, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
Similar jobs
- VE
Security Software Engineer, IAM
NewAuto ApplyVercel
Remote - United States🇺🇸$208k - $312k/yrRemote13 hours agoGCPNode.jsAWS+9Technology - TN
Senior Engineer, Cybersecurity
NewAuto ApplyThe New York Times
New York🇺🇸Hybrid3 hours agoGCPPackerAWS+7Technology - ST
Security Analyst
NewAuto ApplyStripe
US Remote🇺🇸Remote6 hours agoGCPSQLAWS+5Technology - MC
Security Engineer (Product & Business Enablement)
NewAuto ApplyMariner Careers
United States🇺🇸Remote10 hours agoEncryptionLESSOnboarding+1Technology - LA
Staff Security Architect
NewAuto ApplyLambda
Bellevue Office🇺🇸Hybrid4 hours agoEncryptionMachine LearningSOC 2+7Technology - GT
Asset Protection Specialist (Part Time), Carson City (Clearview)
NewAuto ApplyGreen Thumb
Carson City🇺🇸Hybrid6 hours agoBackground ChecksComplianceHIPAA+4 - GT
Asset Protection Specialist (Full Time)
NewAuto ApplyGreen Thumb
York🇺🇸Hybrid6 hours agoBackground ChecksComplianceHIPAA+4 - GT
Asset Protection Specialist (Full Time)
NewAuto ApplyGreen Thumb
Wyomissing🇺🇸Hybrid6 hours agoBackground ChecksComplianceHIPAA+4 - GT
Asset Protection Specialist (Part Time)
NewAuto ApplyGreen Thumb
Wyomissing🇺🇸Hybrid6 hours agoBackground ChecksComplianceHIPAA+4 - DA
Senior Product Security Engineer - AI Agents
NewAuto ApplyDatadog
Alabama🇺🇸Remote5 hours agoDatadogMental HealthTechnology - CT
Physical Access Control Systems (PACS) Engineer
NewAuto ApplyCapital Technology Group
Remote (US)🇺🇸$80k - $120k/yrRemote4 hours agoAgileEngineering - AI
Cyber Security Engineer (Expert) TO03, 32 PD 8 Job#927
NewAuto ApplyAllen Integrated Solutions
Reston🇺🇸Hybrid5 hours agoComplianceTechnology