Job Description
The Role
Canopius is a market-leading cyber insurer with an in-house Cyber Incident Management Team supporting policyholders through stressful and time-critical cyber events.
The Senior Cyber Incident Manager will act as a senior escalation point for complex or high-severity incidents, leading the coordination of response activity from notification through to resolution. The role sits between frontline incident response and global leadership, providing experienced operational oversight, guidance to junior responders and consistent service delivery across the global follow-the-sun model.
Working closely with Claims, Underwriting, Insights & Analytics and external response vendors, the role will help ensure incidents are managed with clarity, empathy and discipline, while translating live incident experience into practical insights that improve service, underwriting understanding and client preparedness.
Responsibilities
Incident coordination and escalation
- Lead and coordinate complex cyber incidents, including ransomware, business email compromise, data incidents, social engineering and operational disruption events.
- Triage incidents, assess severity, establish response plans and coordinate appropriate vendor support.
- Act as a senior escalation point for challenging or sensitive matters, escalating strategic or exceptional issues to the Global Head of Cyber Incident Management.
- Maintain clear incident timelines, actions, decisions, communications and next steps throughout the incident lifecycle.
- Provide calm, clear and empathetic guidance to policyholders, brokers and internal stakeholders during high-pressure situations.
Service delivery and operating discipline
- Support consistent service delivery across the global follow-the-sun model, including handovers, SLAs, case documentation and communication standards.
- Participate in rota and on-call arrangements as required to support global incident response coverage.
- Ensure incident files, metadata, outcomes and post-incident summaries are accurate, timely and complete.
- Identify process gaps, service issues and opportunities to improve incident workflows, templates and operating procedures.
Team support and stakeholder coordination
- Provide practical guidance and mentoring to junior Cyber Incident Responders during live incidents and day-to-day case management.
- Work closely with Claims to support coverage confirmation, claims progression and policyholder communication.
- Collaborate with Underwriting and Insights & Analytics to share incident trends, loss drivers, control observations and emerging threat themes.
- Support the development of client preparedness content, tabletop exercises, playbooks and lessons-learned outputs.
Vendor coordination and continuous improvement
- Coordinate external vendors during live incidents, including forensic firms, legal counsel, communications advisors and specialist response partners.
- Provide structured feedback on vendor responsiveness, quality, communication, cost management and policyholder experience.
- Help track vendor outcomes and identify recurring issues or opportunities for service improvement.
- Contribute to continuous improvement initiatives that enhance policyholder experience, operational consistency and the broader cyber proposition.
Skills and Experience
- Strong experience in cyber incident management, cyber claims, breach response coordination, crisis response, professional services or a similar client-facing environment.
- Proven ability to coordinate complex incidents involving multiple stakeholders, vendors and competing priorities.
- Good understanding of common cyber incidents, including ransomware, business email compromise, data breach, social engineering and operational disruption.
- Strong client service mindset, with excellent judgement, empathy and composure under pressure.
- Clear written and verbal communication skills, including the ability to explain technical issues in accessible business language.
- Strong organisational discipline, including case management, documentation, handovers and action tracking.
- Experience working with external response vendors, including forensic, legal, communications or advisory partners.
- Ability to support and guide junior colleagues without requiring full people-management accountability.
- Comfortable working across regions, time zones and functions in a global operating model.
- Hands-on forensic or deep technical investigation expertise is not required, but sufficient cyber understanding
Salary Range: $95,000 - $115,000
About Us
Our benefits
We offer all employees a comprehensive benefits package that focuses on their whole wellbeing. This includes hybrid working, a competitive base salary, non-contributory 401k, discretionary bonus, insurances including medical, dental and vision cover, and many other benefits to enhance financial, physical, social and psychological health.
About Canopius
Canopius is a global specialty lines (re)insurer. We are one of the leading insurers in the Lloyd’s of London insurance market with offices in the UK, US, Singapore, Australia and Bermuda.
At Canopius we foster a distinctive, positive culture which enables us to bring our whole selves to work to flourish as people, and build a business which delivers profitable, sustainable results.
Canopius operates a flexible, hybrid working model and is committed to providing an environment that challenges employees to be their best and where everyone's unique contributions are recognised, valued and respected.
We are fully committed to equal employment opportunities for all applicants and providing employees with a work environment free of discrimination and harassment. All employment decisions are made regardless of age, sex, gender identity, ethnicity, disability, sexual orientation, socio-economic background, religion or beliefs, marital or caring status, or any other status protected by the laws or regulations in the locations where we operate. We encourage and welcome applicants from all diverse backgrounds.
We make reasonable adjustments throughout the recruitment process and during employment. Please let us know if you require any information in an alternate format or any other reasonable adjustments.