Title: Lead, Incident Operations
Long Island City, NY, US, 11101 Salt Lake City, UT, US, 84121 Washington, DC, US, 20005 Orlando, FL, US, 32827 Boston, MA, US, 02128

Position Summary:
At JetBlue, cyber security operates across a complex IT environment, encompassing traditional data centers, Software as a Service (SaaS) services, multiple cloud providers, e-commerce platforms, and a diverse end-user environment.
We are seeking an Incident Operations Lead to support the Cyber Security Incident Response function through incident coordination, stakeholder communication, readiness, documentation, and post-incident follow-through. The ideal candidate is security-fluent, highly organized, comfortable operating during high-pressure events, and able to translate technical findings into clear actions and leadership-ready updates.
This role works closely with technical Incident Response analysts, but is focused on continuous improvement of and leading the operational execution of Incident Response and supporting the technical investigators.
Essential Responsibilities:
- Lead the operational coordination of cybersecurity incidents, including bridge management, stakeholder communication, action tracking, handoffs, documentation, and leadership-ready status updates.
- Coordinate response activity across Incident Response, Threat Intelligence, Detection Engineering, Security Monitoring, IT Operations, Identity, Infrastructure, application teams, Legal, Communications, vendors, and other stakeholders as needed.
- Support incident declaration, escalation, severity alignment, communication cadence, and response workflow execution in accordance with established incident response procedures.
- Translate technical findings, timelines, risks, containment actions and remediation status into clear summaries for leadership and non-technical stakeholders.
- Maintain accurate incident records, including timelines, key decisions, attendees, action items, evidence references, follow-up owners, and closure documentation.
- Drive post-incident follow-through by converting lessons learned, gaps, and corrective actions into tracked issues with owners, due dates, updates, and closure evidence.
- Identify gaps in incident readiness, including access, tooling, logging, escalation paths, contact lists, documentation, playbooks, templates, evidence handling, and cross-team dependencies.
- Develop, maintain, and improve incident response procedures, bridge guidance, communication templates, after-action processes, tabletop materials, and response readiness documentation.
- Coordinate tabletop exercises, readiness reviews, control tests and follow-up tracking to improve the organization’s ability to respond to cybersecurity incidents.
- Support operational prioritization during high-volume periods or active incidents by helping organize response activity, reduce coordination friction, and maintain visibility into outstanding work.
- Provide guidance to analysts and stakeholders on incident documentation, communication expectations, escalation hygiene, and action tracking during response activities.
- Other duties as assigned.
Minimum Experience and Qualifications:
- Bachelor’s Degree in Cyber Security, Information Technology, Computer Science, Business, Emergency Management, or other relevant discipline; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience in cyber security operations, incident response, technology incident management, enterprise IT operations, or a related field.
- Four (4) years of experience coordinating or supporting cybersecurity incidents, technology incidents, security operations, or similar high-priority operational response activities.
- Demonstrated security fluency, including the ability to understand incident response concepts, common security events, severity/risk, containment, remediation, evidence handling, and escalation needs.
- Experience managing incident calls, operational bridges, action trackers, status updates, stakeholder communications, or cross-team response coordination.
- Strong written and verbal communication skills, including the ability to summarize complex technical information clearly for technical and non-technical audiences.
- Ability to organize ambiguous information into clear priorities, owners, actions, timelines, risks, and decisions during time-sensitive events.
- Ability to work effectively with technical responders without micromanaging investigation steps, while ensuring response activity remains structured, documented, and moving forward.
- Strong problem-solving, judgment, ownership, and follow-through skills in a fast-paced operational environment.
- Ability to manage multiple priorities, stakeholders, issues, and deadlines at once.
- Ability to pass a live scenario-based interview or skills demonstration with JetBlue Crew Members.
- Available and willing to participate in periodic on-call duties and off-hours Incident Response as required.
- Available for occasional overnight travel (10%).
- Must pass a pre-employment drug test.
- Must be legally eligible to work in the country in which the position is located.
- Authorization to work in the United States is required. This position is not eligible for visa sponsorship.
- Must be eligible to hold a US government security clearance if JetBlue deems it relevant to the role.
Preferred Experience and Qualifications
- Five (5) or more years of experience in cybersecurity operations, incident response, security operations, technology incident management, crisis management, or a similar operational leadership function.
- Experience serving as an Incident Commander, Incident Manager, Cyber Incident Coordinator, Response Lead, Major Incident Manager, CSIRT Coordinator, or similar role.
- Experience working in or closely with a SOC, Incident Response team, Threat Detection team, managed security provider, or enterprise cyber security organization.
- Familiarity with SIEM, EDR, SOAR, case management, ticketing, identity, email security, cloud security, endpoint security, and network security concepts.
- Experience with platforms such as Splunk, Microsoft Defender, SentinelOne, XSOAR, ServiceNow, Jira, or similar investigation, response, and work tracking tools.
- Experience developing or maintaining incident response playbooks, runbooks, communication templates, after-action reports, tabletop exercises, metrics, dashboards, or process documentation.
- Familiarity with cybersecurity incident response frameworks or practices such as NIST SP 800-61, CSIRT operating models, MITRE ATT&CK, ITIL Major Incident Management, or similar guidance.
- Experience coordinating legal, communications, executive leadership, vendor, or external partner involvement during significant incidents or operational events.
- Experience tracking corrective actions, remediation items, issue backlogs, control gaps, or cross-team dependencies to closure.
- Airline, transportation, critical infrastructure, or large-enterprise experience in Security Operations, Incident Response, Threat Detection, Technology Operations, or Crisis Management.
- Relevant certifications such as Security+, CISSP, GCIH, GCIA, GCFA, PMP, ITIL, or similar security, incident management, or project management credentials.
- Strong sense of urgency, professionalism, ownership, and desire to continuously improve incident response readiness and execution.
Crewmember Expectations:
- Regular attendance and punctuality.
- Potential need to work flexible hours and be available to respond on short notice.
- Able to maintain a professional appearance.
- When working or traveling on JetBlue flights, and if time permits, all capable crewmembers are asked to assist with light cleaning of aircraft.
- Organizational fit for the JetBlue culture, that is, exhibit JetBlue’s values of Safety, Caring, Integrity, Fun and Passion.
- Promote JetBlue's #1 value of safety as a Safety Ambassador, supporting JetBlue's Safety Management System (SMS) components, Safety Policy and behavioral standards.
- Must fulfill safety accountabilities as prescribed by JetBlue's Safety Management System.
- Responsible for adhering to all applicable laws, regulations (FAA, OSHA, DOT, etc.) and Company policies, procedures and risk controls.
- Responsible for ensuring crewmembers have requisite training, resources and support to achieve safety objectives.
- Identify safety and security concerns, issues, incidents or hazards that should be reported and report them whenever possible and by any means necessary including JetBlue's confidential reporting systems (Aviation Safety Action Program (ASAP) or Safety Action Report (SAR)).
- The use of ChatGPT or any other automated tool during the interview process will disqualify a candidate from being considered for the position.
Equipment:
- Computer and other office equipment.
Work Environment:
- Traditional office environment.
Physical Effort:
- Generally not required, or up to 10 pounds occasionally, 0 pounds frequently. (Sedentary)
Compensation:
- The base pay range for this position is between $100,000 and $166,000 per year. Base pay is one component of JetBlue’s total compensation package, which may also include access to healthcare benefits, a 401(k) plan and company match, crewmember stock purchase plan, short-term and long-term disability coverage, basic life insurance, free space available travel on JetBlue, and more.
#LI-AC1
#LI-Hybrid
Nearest Major Market: Brooklyn
Nearest Secondary Market: New York City