Incident Manager - Detection & Response
Leads and scales the security incident management lifecycle for Detection & Response, serving as incident commander and driving post-incident accountability, trend analysis, systemic improvements, and cross-functional coordination. Requires 7+ years of relevant experience, strong analytical and communication skills, and a bachelor’s degree or equivalent experience.
About the job
Responsibilities
- Own the end-to-end Detection & Response incident management program, including detection workflows, response processes, escalation paths, communications, and remediation tracking.
- Serve as incident commander for security incidents and coordinate executive, engineering, security, legal, and other stakeholders.
- Establish and run incident commander rotations within Detection & Response.
- Capture, assign, track, and close incident action items across teams, including tactical fixes and strategic improvements.
- Analyze incident trends, recurring root causes, systemic risks, and organizational vulnerabilities.
- Lead cross-functional initiatives with engineering, infrastructure, security, and product teams to implement preventive improvements.
- Lead post-mortems and retrospectives and ensure learnings are documented, shared, and acted upon.
- Maintain incident response documentation, playbooks, runbooks, and training materials.
- Partner with detection engineering to improve alert fidelity, reduce noise, and shorten time to detection.
- Define and track incident management KPIs and report to Detection & Response and Security leadership.
- Support security awareness initiatives, including tabletop exercises, training, and talks.
Requirements
- 7+ years of experience in technical program management, incident management, or security operations, including significant Detection & Response or security incident response experience.
- Experience leading or building incident response programs at a technology company.
- Demonstrated ability to turn incident data into organizational improvements and drive systemic fixes across teams.
- Willingness to participate in on-call responsibilities and lead high-severity security incidents, including off-hours.
- Experience building and scaling operational processes from the ground up.
- Ability to drive accountability and follow-through across multiple teams without direct authority.
- Strong analytical skills, including incident trend analysis, metrics reporting, and data-driven prioritization.
- Excellent organization and communication skills, including coordination with technical, non-technical, and executive stakeholders.
- Bachelor’s degree or equivalent combination of education, training, and experience.
Compensation
- Annual salary: $290,000–$365,000 USD
- Hybrid policy: staff are expected to work from an office at least 25% of the time; some roles may require more.
- Visa sponsorship may be available.
Skills
Incident Management, Incident Response, Technical Program Management, Security Operations, Incident Command, Post-Mortems, Root Cause Analysis, Trend Analysis, Metrics Reporting, On-Call, Runbooks, Tabletop Exercises
Similar jobs
Technical Program Management jobsLeads cross-functional programs for billing platform foundations, commercial launches, promotions, charge-pipeline changes, and payments operations. Requires 6+ years of technical program management experience and the ability to coordinate engineering, finance, treasury, product, and support teams.
Leads end-to-end delivery of custom AI-agent deployments for enterprise customers in regulated industries, coordinating technical teams, executive stakeholders, product scoping, architecture decisions, and value measurement. Requires production AI/ML deployment experience, enterprise delivery expertise, and strong executive presence.
Leads secure, end-to-end AI delivery programs for U.S. Intelligence Community customers, translating mission priorities into deployable solutions and measurable outcomes. Requires 10+ years of technical program delivery, direct IC experience, TS/SCI clearance, executive presence, and fluency in AI architectures and secure environments.
Owns portfolio-level milestone tracking, reporting, data quality, and capacity projections for large-scale data center delivery programs. The role requires 7+ years in project controls or scheduling, strong scheduling and BI-tool fluency, and the ability to communicate insights to executive and technical audiences.
Leads integrated demand, supply, and deployment planning for first-party AI hardware infrastructure, aligning site power, configurations, XPU requirements, manufacturing capacity, and supplier commitments. Requires significant experience in complex hardware planning or operations, strong analytical judgment, and cross-functional program leadership.