RingCentral is a leader in the UCaaS segment providing cloud-based communications of any kind: cloud PBX, cloud call center, cloud video & events, messaging, analytics and flexible billing services. Currently we are looking for an Incident Response Leader to fit in our Security Operations division and improve our immediate response to security incidents affecting provided services to RingCentral customers.
We are looking for an experienced Incident Response Lead to lead the organisation’s response to cybersecurity incidents from initial validation through containment, eradication, recovery, root cause analysis, and completion of corrective actions.
This is a leadership role that combines cybersecurity expertise, structured decision-making, crisis coordination, executive communication, and cross-functional influence.
The successful candidate does not need to be the deepest specialist in every security technology. However, they must be able to understand complex technical situations, challenge assumptions, establish clear priorities, facilitate difficult discussions, and lead multidisciplinary teams under pressure.
Role mission
Protect the organisation, its customers, and its services by ensuring that potential and confirmed cybersecurity incidents are identified, assessed, contained, investigated, communicated, and resolved in a timely, disciplined, and evidence-based manner.
Outcomes
Security incidents are identified and declared consistently
Major incidents are led with clarity and control
Threats are contained before additional harm occurs
Threats and root causes are eradicated
Services are recovered safely and deliberately
Incident impact is assessed accurately
Executives and governance teams receive decision-useful reporting
Root cause analyses produce meaningful improvements
Corrective actions are completed, not merely recorded
The incident response capability continuously improves
Key responsibilities
Security incidents are identified and declared consistently
Major incidents are led with clarity and control
Threats are contained before additional harm occurs
Threats and root causes are eradicated
Services are recovered safely and deliberately
Incident impact is assessed accurately
Executives and governance teams receive decision-useful reporting
Root cause analyses produce meaningful improvements
Corrective actions are completed, not merely recorded
The incident response capability continuously improves
Required experience
Significant professional experience in cybersecurity, incident response, security operations, digital forensics, threat detection, or a closely related discipline.
Demonstrated experience leading complex cybersecurity incidents involving multiple technical and business teams.
Experience coordinating containment, eradication, recovery, and impact assessment activities.
Experience communicating security incidents to senior leadership.
Experience leading or facilitating root cause analyses.
Experience tracking corrective actions through completion.
Practical experience working with modern production environments, such as cloud platforms, containers, enterprise identity systems, networks, or customer-facing applications.
Ability to participate in an on-call or major-incident escalation arrangement.
Experience in a multinational technology, telecommunications, cloud, SaaS, financial services, or other regulated organization.
Experience responding to incidents involving customer data or personal data.
Experience with cloud-native and Kubernetes-based environments.
Experience developing incident response playbooks, severity models, reporting standards, and tabletop exercises.
Strong written and spoken English.
Nice to have
Familiarity with NIST incident response guidance, ISO/IEC 27035, SANS incident handling practices, MITRE ATT&CK, or comparable frameworks.
Relevant certifications may include GCIH, GCFA, GCFE, CISSP, CISM, or equivalent practical experience.
What We Offer:
Well-coordinated professional team
Cutting edge technologies, interesting and challenging tasks, dynamic project, great opportunities for self-realization, professional and career growth
Additional Health and Life Insurance Package
Employee Assistance Program
25 vacation days
This role requires on-site presence at our office 4 days a week to support effective collaboration and teamwork
