This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Manager, Security Incident Response based in United States.
This role sits at the center of security incident response, combining people leadership, technical depth, and operational strategy. You will build and lead a team of incident responders and security-focused builders who strengthen response through automation and intelligent tooling. The position offers the opportunity to shape incident response maturity, improve readiness, and guide teams through complex, high-severity security events. You will work closely with Detection Engineering, Threat Intelligence, Red Team, and other security functions to close gaps and strengthen resilience. Success requires calm judgment under pressure, strong cross-functional leadership, and a systems-oriented approach to security operations. It is an opportunity to protect people, data, and the business while helping evolve how modern security teams respond at scale.
Accountabilities:
- Lead, develop, and support a team of security incident responders and security builders, setting clear expectations, creating meaningful ownership, delegating effectively, and supporting career development and performance.
- Define and drive the security incident response roadmap and strategic priorities, including the development of agentic incident response, structured threat hunting, and insider risk investigations as scalable, sustained capabilities.
- Balance competing priorities across incident response, strategic initiatives, and team development, making tradeoffs transparent and challenging approaches or timelines that create unnecessary risk or unsustainable workloads.
- Scale response capabilities through automation and AI-assisted tooling for triage, enrichment, investigation, and other operational workflows while maintaining appropriate human oversight, approval controls, auditability, and rollback mechanisms.
- Oversee detection, triage, containment, remediation, and post-incident learning, serving as an escalation point and incident manager for complex or high-severity security events.
- Partner with Detection Engineering, Cyber Threat Intelligence, Red Team, and other teams to improve cross-functional processes and address detection and response gaps identified through investigations.
- Evolve incident response playbooks, training programs, tabletop exercises, metrics, and reporting to strengthen operational readiness and overall program maturity.
- Participate in the on-call rotation and provide leadership escalation or incident management during major or complex security incidents.
- Track and communicate incident trends, operational metrics, program maturity, and the measurable impact of automation and AI-assisted tooling on response time and coverage.
- Bring 5+ years of experience in security incident response, including at least 2 years as a people manager or technical leader responsible for career development, performance management, or technical team leadership.
- Demonstrate experience building or scaling incident response automation, security tooling, or AI-assisted workflows for activities such as triage, enrichment, and investigation, with sound judgment about where automation should and should not make decisions.
- Have experience setting clear expectations, defining ownership, delegating work, managing competing priorities, and measuring meaningful team and operational outcomes.
- Demonstrate the ability to manage high-pressure security incidents with clarity, structure, calm decision-making, and appropriate prioritization.
- Possess a strong understanding of cloud-native and SaaS environments, identity-driven attack techniques, and the security response strategies required to address them.
- Communicate complex security findings, tradeoffs, risks, and recommendations effectively to both technical and non-technical audiences.
- Have experience translating strategic security initiatives into actionable projects, coordinating team sprints, and managing delivery across competing priorities.
- Be a people-first leader who actively fosters psychological safety, team stability, professional growth, accountability, and high performance.
- Think like a builder and systems engineer, proactively identifying operational gaps, inefficiencies, and risks while developing practical solutions through automation, tooling, and process improvements.
- Demonstrate strong cross-functional influence, sound judgment, adaptability, and the ability to align teams with different priorities and perspectives.
- Be motivated by protecting people, data, and the business while continuously improving security operations and response capabilities.
- Annual base salary ranging from $192,000 to $278,000 USD, with compensation determined based on experience, skills, and internal equity.
- Immediate participation in a comprehensive benefits program, including health and dental coverage.
- 401(k) retirement program and additional employee benefits.
- Equity grant and, where applicable, participation in incentive programs.
- Generous paid time off policy.
- Maternity and parental leave top-up programs.
- Competitive health and wellbeing benefits.
- RSU program for most employees.
- Retirement matching program.
- Paid volunteer days and peer-to-peer recognition.
- Remote-first work environment with opportunities for in-person department, team, customer, and industry events.
- Free access to the company's password management service.
- Opportunity to lead a growing security function, shape incident response strategy, and work with advanced automation and AI-assisted security tooling.
- Collaborative, inclusive environment focused on transparency, psychological safety, continuous learning, and meaningful impact.

