Skip to content
FluidstackFluidstack

Manager, Incident Response

Lead incident response as senior commander and escalation lead for AI compute infrastructure. Build and manage 24/7 IR team and on-call program from scratch, handling cross-domain (cyber/physical/OT) incidents with executive, legal, and regulatory communications.

About the job

Role Scope

  • Lead incidents as a senior incident commander in the on-call rotation, and serve as the escalation backstop when a case rises above the responders on call.
  • Own the 24/7 coverage model, rotation discipline, and response SLAs for your US region, keeping the program humane and the bar high at the same time.
  • Build and develop a team of senior incident responders, setting the on-call expectations and quality bar they operate to.
  • Drive executive, legal, and customer communications during declared incidents, including regulated reporting and disclosure timelines.
  • Own the joint operating relationship with Physical Security and Data Center Operations for incidents that cross cyber, physical, and OT surfaces.
  • Run the post-incident review cadence and drive remediation to completion across detection, response, and infrastructure.
  • Hold the bar on the agentic triage layer, defining what the agent escalates and feeding incident learnings back to detection engineering and threat intelligence.

Requirements

  • Led material incidents end to end as a senior incident commander at organizations with sophisticated, well-resourced threat actors.
  • Managed and grown a team of senior responders while staying in the on-call rotation yourself.
  • Designed or run a 24/7 on-call program: coverage models, rotation discipline, acknowledgement and response SLAs, and escalation chains.
  • Move between technical containment and executive, legal, or customer-facing communications during a declared incident without losing the thread.
  • Made disclosure-grade calls under regulatory and customer reporting clocks.
  • Built operating relationships across security, infrastructure, and physical or facilities teams, and led incidents that crossed those boundaries.
  • Well-founded opinions on what makes an on-call program humane and an incident response process effective, and ready to build one from a small senior core.

Nice-to-Haves

  • Incident response bridging cyber, physical, and OT or ICS surfaces.
  • Experience at critical-infrastructure operators, data centers, or 24/7 high-availability environments.
  • Standing up or scaling an IR team and on-call program from scratch.
  • Operating under FedRAMP, SEC, or similar regulated incident-reporting regimes.
  • Agent-augmented IR, including triage, investigation, or response automation.

Skills

Incident Response, Incident Command, On-Call Management, Threat Intelligence, Regulatory Reporting, Ot Security, Ics Security, FedRAMP, Physical Security, Detection Engineering

Anthropic

Anthropic

Washington, DC
Safeguards Enforcement Lead, Cyber Harms
$285k+/yrHybridSecurity Engineering

Leads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.

Anthropic

Anthropic

San Francisco, CA
Platform Security Engineer, DRTM / Secure Launch
$320k+/yrHybrid8+ YOESecurity Engineering

Owns DRTM adoption, attestation, and platform hardening across x86 and ARM infrastructure, working across firmware, bootloaders, kernels, hardware, and silicon security. The role requires deep systems-security experience, upstream Linux or firmware contributions, and strong vendor and OEM leadership.

OpenAI

OpenAI

San Francisco, CA

Software Security Architect, Operating Systems | Consumer Devices
$268k+/yrOn-site7+ YOESecurity Engineering

Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.

OpenAI

OpenAI

San Francisco, CA

Cyber Operations Lead, Critical Harm Operations
$252k+/yrHybrid8+ YOESecurity Engineering

Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.

Mercor

Mercor

San Francisco, CA

Security GRC Lead
$350k+/yrOn-site7+ YOESecurity Engineering

Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.