Incident Manager - Detection & Response
Leads and scales the security incident management lifecycle for Detection & Response, serving as incident commander and driving post-incident accountability, trend analysis, systemic improvements, and cross-functional coordination. Requires 7+ years of relevant experience, strong analytical and communication skills, and a bachelor’s degree or equivalent experience.
$290k – $365k/yr
Hybrid7+ YOETechnical Program Management
About the job
Responsibilities
- Own the end-to-end Detection & Response incident management program, including detection workflows, response processes, escalation paths, communications, and remediation tracking.
- Serve as incident commander for security incidents and coordinate executive, engineering, security, legal, and other stakeholders.
- Establish and run incident commander rotations within Detection & Response.
- Capture, assign, track, and close incident action items across teams, including tactical fixes and strategic improvements.
- Analyze incident trends, recurring root causes, systemic risks, and organizational vulnerabilities.
- Lead cross-functional initiatives with engineering, infrastructure, security, and product teams to implement preventive improvements.
- Lead post-mortems and retrospectives and ensure learnings are documented, shared, and acted upon.
- Maintain incident response documentation, playbooks, runbooks, and training materials.
- Partner with detection engineering to improve alert fidelity, reduce noise, and shorten time to detection.
- Define and track incident management KPIs and report to Detection & Response and Security leadership.
- Support security awareness initiatives, including tabletop exercises, training, and talks.
Requirements
- 7+ years of experience in technical program management, incident management, or security operations, including significant Detection & Response or security incident response experience.
- Experience leading or building incident response programs at a technology company.
- Demonstrated ability to turn incident data into organizational improvements and drive systemic fixes across teams.
- Willingness to participate in on-call responsibilities and lead high-severity security incidents, including off-hours.
- Experience building and scaling operational processes from the ground up.
- Ability to drive accountability and follow-through across multiple teams without direct authority.
- Strong analytical skills, including incident trend analysis, metrics reporting, and data-driven prioritization.
- Excellent organization and communication skills, including coordination with technical, non-technical, and executive stakeholders.
- Bachelor’s degree or equivalent combination of education, training, and experience.
Compensation
- Annual salary: $290,000–$365,000 USD
- Hybrid policy: staff are expected to work from an office at least 25% of the time; some roles may require more.
- Visa sponsorship may be available.
Skills
Incident ManagementIncident ResponseTechnical Program ManagementSecurity OperationsIncident CommandPost-MortemsRoot Cause AnalysisTrend AnalysisMetrics ReportingOn-CallRunbooksTabletop Exercises