Senior Manager, Incident Response
Newell Brands
- Location
- Atlanta, Georgia, US
- Work model
- On-Site
- Level
- Senior
Skills
About this role
Job ID: 17075 Alternate Locations: Newell Brands is a leading consumer products company with a portfolio of iconic brands like Graco®, Coleman®, Oster®, Rubbermaid®, Sharpie® and Yankee Candle® - and 24,000 talented teammates around the world. Our culture is built on values in action: Integrity, Teamwork, Passion for Winning, Ownership, and Leadership. We work together to win, grow, and make a real impact—supported by a high-performing, inclusive, and collaborative environment where you can be your best, every day. Job Summary The Cyber Security Senior Manager, Incident Response reports to the Senior Manager of Security Operations and serves as the senior-most technical leader within the Newell Brands Security Operations function. This role is the primary Incident Commander for the Cyber Security Incident Response Plan (CSIRP) — owning end-to-end response coordination for high-severity and critical security incidents across Newell's global environment. Beyond incident response, the Senior Manager sets the technical direction for Security Operations, leading detection engineering, automation and control-improvement initiatives while directing the team's day-to-day operational execution. This is a hands-on leadership role: the right candidate pairs deep, current IR and engineering expertise with the operational judgment to run a modern SOC and translate lessons learned into durable, scalable process improvements. Key Responsibilities Incident Command & Response
Serve as primary Incident Commander in accordance with the Newell Brands CSIRP, leading response activities across all CSIRT functional teams for high-severity and critical incidents. Make and communicate time-sensitive decisions to contain incidents, prevent escalation and restore normal operations as quickly and efficiently as possible. Coordinate response activities across Security Operations, IT, Legal, HR, Corporate Communications, Privacy and other cross-functional teams, ensuring alignment with CSIRP priorities. Partner with the CISO to brief executive leadership, the Information Security Governance Committee, and other key stakeholders on incident status, business impact and response actions. Determine when to activate external IR retainer resources, manage those vendor relationships throughout an engagement, and ensure evidentiary integrity. Lead post-incident reviews and after-action analysis; document findings and drive implementation of corrective actions to reduce recurrence. Maintain and continuously improve CSIRP documentation, incident runbooks and playbooks; conduct tabletop exercises and simulation drills at least annually.
Security Engineering & Control Improvement
Develop and recommend security control improvements based on incident findings, threat intelligence and gap assessments across endpoint, network, identity and cloud environments. Design, build and maintain detection engineering content — SIEM correlation rules, behavioral analytics and custom signatures — to improve fidelity and reduce mean time to detect. Lead automation initiatives across Security Operations workflows including alert triage, enrichment, containment actions and case management integrations (SOAR/XSOAR or equivalent). Evaluate emerging security technologies and make evidence-based recommendations for tooling investments that improve detection and response capabilities. Collaborate with IT and infrastructure teams to validate that security controls are implemented correctly and test them through adversary simulation and purple team activities.
Security Operations
Lead day-to-day Security Operations, directing SOC monitoring, alerting and triage to ensure operational coverage and response readiness across global time zones. Set the technical direction and continuous-improvement roadmap for the SOC, prioritizing the work that most reduces risk and improves detection and response performance.