Incident Manager - Detection & Response

Anthropic Anthropic · AI Frontier · San Francisco, CA · Security

This role is for an Incident Manager focused on detection and response within a security team at Anthropic. The primary responsibility is to own and evolve the incident management program, including detection, response, escalation, communication, and remediation tracking. A key aspect is driving organizational improvements based on incident data and trends, and partnering with various teams to implement fixes. The role also involves leading incident reviews, developing documentation, improving detection, defining KPIs, and supporting security awareness initiatives.

What you'd actually do

  1. Own the end-to-end D&R incident management program: detection workflows, response processes, escalation paths, communication standards, and remediation tracking.
  2. Serve as incident commander for security incidents, driving clear coordination across executive, engineering, security, legal, and other appropriate stakeholders.
  3. Establish and run incident commander rotations within D&R, ensuring clear ownership and effective coordination during incidents of varying severity.
  4. Drive post-incident accountability by defining how action items are captured, assigned, tracked, and completed across teams—ensuring follow-through on both tactical fixes and strategic improvements.
  5. Gather, analyze, and report on incident trends and patterns to surface systemic risks, recurring root causes, and areas where the organization is most vulnerable.

Skills

Required

  • 7+ years of experience in technical program management, incident management, or security operations
  • significant time spent in a detection & response or security incident response context
  • led or built incident response programs at a technology company
  • comfortable participating in on-call responsibilities and leading incident response during high-severity security events
  • strong analytical skills and experience with incident trend analysis, metrics reporting, and data-driven prioritization
  • highly organized with a knack for bringing structure to ambiguous, fast-moving situations
  • excellent communication skills, especially under pressure and when coordinating across technical and non-technical stakeholders, including executive leadership

Nice to have

  • experience in a high-growth or security-intensive environment
  • Thrive in fast-paced environments where priorities shift and you’re often working with incomplete information.

What the JD emphasized

  • demonstrated track record of turning incident data into organizational improvements
  • building and scaling operational processes from the ground up
  • driving accountability and follow-through across multiple teams without direct authority