SPE
Lead, Cyber Incident Response
Culver City, California
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Lead / management
- Stated salary
- $142,400 – $178,000 per year
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 25 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Sony Pictures Entertainment (SPE) is seeking an experienced Lead Cyber Incident Response professional to help protect the company's people, intellectual property, productions, technology platforms, and business operations from cyber threats.
This role leads complex cybersecurity investigations, coordinates response activities during significant security incidents, and advances SPE's incident response capabilities. The successful candidate will serve as a senior technical resource within the Incident Response team, leading investigations across corporate, cloud, identity, SaaS, and production environments while partnering with Security Operations, Threat Intelligence, Engineering, Legal, Privacy, People & Organization (P&O), Corporate Communications, and business stakeholders.
Key Responsibilities
Incident Response and Investigations
- Lead complex cybersecurity investigations from initial detection through containment, eradication, recovery, and post-incident review.
- Serve as incident commander for assigned incidents, coordinating technical responders and business stakeholders throughout the response lifecycle.
- Investigate ransomware, identity compromise, phishing, insider threats, data exposure, cloud security incidents, and other advanced cyber threats.
- Conduct digital forensic investigations to determine root cause, scope, business impact, and remediation requirements.
Business and Asset Protection
- Investigate threats affecting SPE intellectual property, content, productions, employees, technology platforms, third-party partners, and business operations.
- Assess cyber events from both technical and business-risk perspectives, balancing risk reduction with operational continuity.
- Partner with Legal, Privacy, People & Organization (P&O), Corporate Communications, and business leadership on sensitive investigations and response activities.
Security Operations and Continuous Improvement
- Collaborate with Security Operations, Threat Intelligence, Detection Engineering, and Security Engineering to enhance detection and response capabilities.
- Develop and improve incident response playbooks, runbooks, escalation procedures, investigative methodologies, and operational standards.
- Drive automation and workflow optimization through SOAR, scripting, AI-enabled capabilities, and emerging technologies.
- Lead post-incident reviews and translate lessons learned into measurable security and operational improvements.
Technical Leadership
- Serve as a senior escalation point for complex investigations and high-severity incidents.
- Mentor Incident Response analysts through case reviews, training, coaching, and knowledge sharing.
- Provide clear technical updates, executive-ready summaries, after-action reports, and risk-informed recommendations.
- Contribute to strategic initiatives that strengthen SPE cyber resilience and operational maturity.
Qualifications
Required
- 8+ years of cybersecurity experience, with significant focus on incident response, digital forensics, threat hunting, or security operations.
- Proven experience leading enterprise-scale cybersecurity investigations and incident response efforts.
- Strong knowledge of modern attack techniques, threat actor behavior, digital forensics, and investigative methodologies.
- Experience with cloud security, identity security, endpoint detection and response (EDR/XDR), SIEM, and SOAR platforms.
- Excellent analytical, communication, and stakeholder-management skills, including the ability to explain complex technical issues to executive and non-technical audiences.
Preferred
- Experience supporting global media, entertainment, technology, or other highly distributed enterprise environments.
- Experience investigating incidents involving intellectual property, insider threats, data exposure, or third-party compromise.
- Experience with Microsoft 365, Azure, AWS, modern SaaS environments, and identity platforms.
- Knowledge of Python, PowerShell, or other scripting and automation technologies.
- Relevant industry certifications such as CISSP, GCIH, GCFA, GCIA, GNFA, or equivalent.
The anticipated base salary for this position is $142,400 - $178,000. This role may also qualify for annual incentive and/or comprehensive benefits. The actual base salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location of the position.
Sony Pictures Entertainment is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status, age, sexual orientation, gender identity, or other protected characteristics.
SPE will consider qualified applicants with arrest or conviction records in accordance with applicable law.
Sony Pictures does not allow audio recording, video recording or use of AI note-taking tools during interviews. Please be aware these tools may be enabled as a default and can be difficult to disable once the interview has started, so we recommend you check your device and disable these tools prior to the start of your interview. If recording or the use of the tools occurs during the interview and cannot be promptly turned off or disabled, the interviewer may end the interview.
To request an accommodation for purposes of participating in the hiring process, you may contact us at SPE_Accommodation_Assistance@spe.sony.com.
Similar jobs
- Incident Response LeadToyota · Plano, TexasFirst seen yesterday
- Principal, Incident Response Lead | Principal, Incident Response LeadVerisk Verisk · Jersey City, NJ, United StatesFirst seen 2d ago
- Security Operations and Incident Response LeadOffice of the Chief Information Officer · Lakewood, Colorado, United StatesFirst seen 2d ago
- Incident Response LeadWhoop · Boston, MAFirst seen 5d ago
- Senior/Staff Security Engineer, Incident Response Grow Therapy · RemoteFirst seen 5d agoremote
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job