Incident Management Lead, Data Center Security
Leads a global physical-security incident and crisis management program for data center operations, standardizing severity frameworks, partner adoption, reporting, vendor performance, and major-incident command. Requires experience building programs across critical infrastructure, vendors, and multiple sites.
About the job
Responsibilities
- Build and own the global crisis and incident management program for data center physical security.
- Define incident categories, severity tiers, thresholds, escalation and activation criteria, notification requirements, and decision rights with operating partners, security vendors, managed-service providers, and internal teams.
- Establish governance, including ownership, review cadence, and change-management processes.
- Convert the framework into playbooks, training, tabletop exercises, and functional exercises across sites and vendors.
- Define incident metrics, build dashboards and reporting, and own the executive reporting cadence from real-time notifications through leadership escalation and executive summaries.
- Standardize procedures, reporting, escalation triggers, and performance expectations across vendors and GSOC-type providers.
- Lead major incidents, including activation, coordination, leadership communication, decision support, stand-down, and after-action reviews.
- Run structured post-incident reviews, track corrective actions to closure, and incorporate lessons into frameworks, playbooks, procedures, and vendor contracts.
- Design and operate an always-on monitoring, escalation, and response capability through managed services and site security vendors as the program matures.
- Build cross-functional partner buy-in and drive adoption across organizations and vendors without direct authority.
Requirements
- Experience building or substantially rebuilding an incident or crisis management program, including its definitions and severity model.
- Experience securing partner agreement on shared definitions and procedures across operators, vendors, and internal teams.
- Experience driving framework adoption through playbooks, training, and exercises.
- Experience defining incident metrics, building reporting, and establishing executive reporting cadences.
- Experience with physical security in or around data centers or comparable critical infrastructure.
- Experience managing major incidents end to end, including activation, multi-party coordination, leadership communication, stand-down, and after-action review.
- Experience holding GSOCs, monitoring providers, guard forces, or other managed services to measurable performance standards.
- Ability to make and defend severity decisions quickly with incomplete information and revise them as facts develop.
- Ability to write clear incident reports for executives.
- Ability to influence sites, vendors, and internal teams without direct authority.
Nice-to-haves
- Experience designing incident taxonomies, severity models, or escalation frameworks adopted across multiple organizations or vendors.
- Experience running incident metrics programs at scale across multiple sites or vendors.
- Incident Command System (ICS), National Incident Management System (NIMS), or comparable experience.
- Experience standing up or running a global security operations center.
Compensation
- Annual salary range: $290,000–$365,000.
Skills
Incident Management, Crisis Management, Severity Models, Incident Taxonomies, Escalation Frameworks, Incident Command System, Nims, Gsoc, Physical Security, Data Centers, Vendor Management, Executive Reporting, Incident Metrics, Tabletop Exercises, After-Action Reviews