Skip to content
AnthropicAnthropicSan Francisco, CA

Incident Manager - Detection & Response

Leads and scales the security incident management lifecycle for Detection & Response, serving as incident commander and driving post-incident accountability, trend analysis, systemic improvements, and cross-functional coordination. Requires 7+ years of relevant experience, strong analytical and communication skills, and a bachelor’s degree or equivalent experience.

$290k – $365k/yr
Hybrid7+ YOETechnical Program Management

About the job

Responsibilities

  • Own the end-to-end Detection & Response incident management program, including detection workflows, response processes, escalation paths, communications, and remediation tracking.
  • Serve as incident commander for security incidents and coordinate executive, engineering, security, legal, and other stakeholders.
  • Establish and run incident commander rotations within Detection & Response.
  • Capture, assign, track, and close incident action items across teams, including tactical fixes and strategic improvements.
  • Analyze incident trends, recurring root causes, systemic risks, and organizational vulnerabilities.
  • Lead cross-functional initiatives with engineering, infrastructure, security, and product teams to implement preventive improvements.
  • Lead post-mortems and retrospectives and ensure learnings are documented, shared, and acted upon.
  • Maintain incident response documentation, playbooks, runbooks, and training materials.
  • Partner with detection engineering to improve alert fidelity, reduce noise, and shorten time to detection.
  • Define and track incident management KPIs and report to Detection & Response and Security leadership.
  • Support security awareness initiatives, including tabletop exercises, training, and talks.

Requirements

  • 7+ years of experience in technical program management, incident management, or security operations, including significant Detection & Response or security incident response experience.
  • Experience leading or building incident response programs at a technology company.
  • Demonstrated ability to turn incident data into organizational improvements and drive systemic fixes across teams.
  • Willingness to participate in on-call responsibilities and lead high-severity security incidents, including off-hours.
  • Experience building and scaling operational processes from the ground up.
  • Ability to drive accountability and follow-through across multiple teams without direct authority.
  • Strong analytical skills, including incident trend analysis, metrics reporting, and data-driven prioritization.
  • Excellent organization and communication skills, including coordination with technical, non-technical, and executive stakeholders.
  • Bachelor’s degree or equivalent combination of education, training, and experience.

Compensation

  • Annual salary: $290,000–$365,000 USD
  • Hybrid policy: staff are expected to work from an office at least 25% of the time; some roles may require more.
  • Visa sponsorship may be available.

Skills

Incident ManagementIncident ResponseTechnical Program ManagementSecurity OperationsIncident CommandPost-MortemsRoot Cause AnalysisTrend AnalysisMetrics ReportingOn-CallRunbooksTabletop Exercises