We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Incident Response Team Lead

Tyler Technologies
United States, Maine, Yarmouth
Feb 17, 2026

Incident Response Team Lead

Apply Online

The Incident Response Team Lead supports day-to-day security incident investigations while providing technical guidance and task coordination for a small team of analysts and engineers. This role serves as a bridge between individual contributors and management, combining hands-on incident response work with entry-level leadership responsibilities.
The Team Lead is expected to have a solid foundation in security incident response and digital forensics, with the ability to guide investigations, assist with decision-making, and help junior analysts develop their skills under the direction of senior leadership.
The Incident Response Team Lead is accountable for supporting the effective execution of security incident investigations and helping maintain consistent investigative quality across the team. While not responsible for setting overall strategy, this role contributes directly to operational effectiveness by ensuring incidents are handled efficiently, documented properly, and escalated appropriately.
Through hands-on involvement and peer leadership, the Team Lead helps reduce investigation delays, improve team capability, and support the organization's broader security objectives.
organizational risk, minimizing operational disruption, and protecting both staff and customers from the impact of security incidents.
Location

Plano, Texas | Yarmouth, Maine | Overland Park, Kansas | Orono, Maine

Responsibilities
  • Serve as a hands-on responder for security incidents, participating in investigation, containment, eradication, recovery, and post-incident activities.
  • Provide day-to-day technical guidance and task coordination for Incident Response analysts during investigations, ensuring work is completed accurately and on time.
  • Assist in triaging and prioritizing incidents based on severity, impact, and available resources, escalating issues to management as appropriate.
  • Support the creation, development, and maintenance of incident response procedures, playbooks, and documentation to promote consistent investigative practices.
  • Review investigative findings, evidence collection, and documentation produced by team members for accuracy and completeness.
  • Communicate investigation status and findings to management and cross-functional partners in a clear and timely manner.
  • Collaborate with internal teams such as IT, Legal, Privacy, and Compliance during incident response activities.
  • Support post-incident reviews by helping identify lessons learned and opportunities for process or technical improvements.
  • Mentor and support junior analysts by sharing knowledge, providing feedback, and assisting with skill development.
Complexity
The Incident Response Team Lead must be able to:
  • Operate effectively in high-pressure incident response situations while maintaining attention to detail and sound judgment.
  • Balance personal investigative work with team coordination and mentoring responsibilities.
  • Communicate technical information clearly to non-technical stakeholders with guidance from senior team members.
  • Manage multiple concurrent incidents or tasks while meeting defined timelines and quality expectations.
  • Follow established policies and procedures while recognizing when escalation or additional support is required.
Qualifications
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent practical experience.
  • 2-4 years of experience in security incident response, digital forensics, or a related cybersecurity role.
  • Demonstrated experience participating in security incident investigations across multiple stages of the incident lifecycle.
  • Prior experience acting as a peer lead, mentor, or primary investigator on incidents is preferred.
  • One or more relevant security certifications preferred (e.g., GCIH, GCFA, Security+, or comparable).
  • Working knowledge of core Incident Response domains, including:
    • Incident Response and Evidence Handling
    • Digital Forensics Fundamentals
    • Endpoint and Network Investigation Techniques
    • Common Attack Vectors and Threat Actor Behaviors
  • Familiarity with enterprise environments, including cloud services, SaaS platforms, and modern endpoint technologies.
  • Strong analytical, documentation, and problem-solving skills.
  • Clear written and verbal communication skills, with the ability to contribute to investigation reports and team briefings.
Great Place to Work & Grow Your Career

Come join us as we transform the public sector! Our mission, vision, and values guide everything we do. We're also frequently recognized as a great workplace locally and nationally. See our many awards and accolades.

Taking Care of You & Your Family

Your health and well-being are important to us. That's why we invest in our team members by offering competitive benefits to support their health and financial wellness. Learn more about how we care for our people.

Tyler is subject to regulations, guidelines, and/or client requirements relating to the qualifications of Tyler personnel performing certain client work. Because of the nature of this position, it is a requirement that the candidate can successfully pass a federal background check at the time an offer is extended and over the course of employment with Tyler.

Apply Online

Requisition Number:2026-8339

#LI-Hybrid

#LI-SB1


Tyler Technologies is proud to be an equal opportunity employer. All qualified applicants will receive consideration without regard to race, creed, gender, marital status, sexual orientation, citizenship status, color, religion, national origin, age, disability, protected veteran status, or any other status protected under local, state, or federal laws. If you require reasonable accommodation for any part of the application or hiring process due to a disability, please submit your request by emailing jobs@tylertech.com or by calling 800.646.2633 ext. 791008. Please keep in mind these methods are reserved for individuals who require accommodation due to a disability.
Applied = 0

(web-54bd5f4dd9-cz9jf)