Lead, Incident Operations at JetBlue Airways Corporation | Boston, MA, US | Rezi

Lead, Incident Operations at JetBlue Airways Corporation

Lead, Incident Operations

JetBlue Airways Corporation · Boston, MA, US

1 weeks ago

Lead, Incident Operations

JetBlue Airways Corporation · Boston, MA, US

12 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

At JetBlue, cyber security operates across a complex IT environment. We are seeking an Incident Operations Lead to support the Cyber Security Incident Response function through incident coordination, stakeholder communication, readiness, documentation, and post-incident follow-through. The ideal candidate is security-fluent, highly organized, comfortable operating during high-pressure events, and able to translate technical findings into clear actions and leadership-ready updates. This role works closely with technical Incident Response analysts, but is focused on continuous improvement of and leading the operational execution of Incident Response and supporting the technical investigators.

Responsibilities

  • Lead the operational coordination of cybersecurity incidents, including bridge management, stakeholder communication, action tracking, handoffs, documentation, and leadership-ready status updates.
  • Coordinate response activity across Incident Response, Threat Intelligence, Detection Engineering, Security Monitoring, IT Operations, Identity, Infrastructure, application teams, Legal, Communications, vendors, and other stakeholders as needed.
  • Support incident declaration, escalation, severity alignment, communication cadence, and response workflow execution in accordance with established incident response procedures.
  • Translate technical findings, timelines, risks, containment actions and remediation status into clear summaries for leadership and non-technical stakeholders.
  • Maintain accurate incident records, including timelines, key decisions, attendees, action items, evidence references, follow-up owners, and closure documentation.
  • Drive post-incident follow-through by converting lessons learned, gaps, and corrective actions into tracked issues with owners, due dates, updates, and closure evidence.
  • Identify gaps in incident readiness, including access, tooling, logging, escalation paths, contact lists, documentation, playbooks, templates, evidence handling, and cross-team dependencies.
  • Develop, maintain, and improve incident response procedures, bridge guidance, communication templates, after-action processes, tabletop materials, and response readiness documentation.
  • Coordinate tabletop exercises, readiness reviews, control tests and follow-up tracking to improve the organization’s ability to respond to cybersecurity incidents.
  • Support operational prioritization during high-volume periods or active incidents by helping organize response activity, reduce coordination friction, and maintain visibility into outstanding work.
  • Provide guidance to analysts and stakeholders on incident documentation, communication expectations, escalation hygiene, and action tracking during response activities.
  • Other duties as assigned.

Requirements

  • Bachelor’s Degree in Cyber Security, Information Technology, Computer Science, Business, Emergency Management, or other relevant discipline; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience in cyber security operations, incident response, technology incident management, enterprise IT operations, or a related field.
  • Four (4) years of experience coordinating or supporting cybersecurity incidents, technology incidents, security operations, or similar high-priority operational response activities.
  • Demonstrated security fluency, including the ability to understand incident response concepts, common security events, severity/risk, containment, remediation, evidence handling, and escalation needs.
  • Experience managing incident calls, operational bridges, action trackers, status updates, stakeholder communications, or cross-team response coordination.
  • Strong written and verbal communication skills, including the ability to summarize complex technical information clearly for technical and non-technical audiences.
  • Ability to organize ambiguous information into clear priorities, owners, actions, timelines, risks, and decisions during time-sensitive events.
  • Ability to work effectively with technical responders without micromanaging investigation steps, while ensuring response activity remains structured, documented, and moving forward.
  • Strong problem-solving, judgment, ownership, and follow-through skills in a fast-paced operational environment.
  • Ability to manage multiple priorities, stakeholders, issues, and deadlines at once.
  • Ability to pass a live scenario-based interview or skills demonstration with JetBlue Crew Members.
  • Available and willing to participate in periodic on-call duties and off-hours Incident Response as required.
  • Available for occasional overnight travel (10%).
  • Must pass a pre-employment drug test.
  • Must be legally eligible to work in the country in which the position is located.
  • Authorization to work in the United States is required.
  • This position is not eligible for visa sponsorship.
  • Must be eligible to hold a US government security clearance if JetBlue deems it relevant to the role.

Skills

  • Security fluency
  • Incident coordination
  • Stakeholder communication
  • Readiness
  • Documentation
  • Post-incident follow-through
  • SIEM
  • EDR
  • SOAR
  • Case management
  • Ticketing
  • Identity
  • Email security
  • Cloud security
  • Endpoint security
  • Network security
  • Splunk
  • Microsoft Defender
  • SentinelOne
  • XSOAR
  • ServiceNow
  • Jira
  • NIST SP 800-61
  • CSIRT operating models
  • MITRE ATT&CK
  • ITIL Major Incident Management

Location

  • Hybrid

Work Type

  • Hybrid
  • Full-time

Experience Level

  • Mid-level
  • Senior-level

Education Level

  • Bachelor's Degree in Cyber Security, Information Technology, Computer Science, Business, Emergency Management, or other relevant discipline
  • High School Diploma/GED with relevant work experience

Salary/Compensations

  • $100,000 - $166,000 per year

Benefits

  • Access to healthcare benefits
  • 401(k) plan and company match
  • Crewmember stock purchase plan
  • Short-term and long-term disability coverage
  • Basic life insurance
  • Free space available travel on JetBlue

About the Company

  • At JetBlue, cyber security operates across a complex IT environment, encompassing traditional data centers, Software as a Service (SaaS) services, multiple cloud providers, e-commerce platforms, and a diverse end-user environment.
  • JetBlue's values are Safety, Caring, Integrity, Fun and Passion.

Equal Opportunity

  • The use of ChatGPT or any other automated tool during the interview process will disqualify a candidate from being considered for the position.