Incident Manager - Detection & Response

Anthropic Anthropic · AI Frontier · Zürich, Switzerland · Security

This role is for an Incident Manager focused on detection and response within Anthropic's security team. The primary responsibility is to own and mature the incident management program, including detection, response, escalation, communication, and remediation tracking. The role involves serving as incident commander, driving post-incident accountability, analyzing incident trends to identify systemic risks, and partnering with engineering teams to implement broad fixes. It also includes developing documentation, improving alert fidelity, defining KPIs, and supporting company-wide security awareness initiatives.

What you'd actually do

  1. Own the end-to-end D&R incident management program: detection workflows, response processes, escalation paths, communication standards, and remediation tracking.
  2. Serve as incident commander for security incidents, driving clear coordination across executive, engineering, security, legal, and other appropriate stakeholders.
  3. Establish and run incident commander rotations within D&R, ensuring clear ownership and effective coordination during incidents of varying severity.
  4. Drive post-incident accountability by defining how action items are captured, assigned, tracked, and completed across teams—ensuring follow-through on both tactical fixes and strategic improvements.
  5. Gather, analyze, and report on incident trends and patterns to surface systemic risks, recurring root causes, and areas where the organization is most vulnerable.

Skills

Required

  • 7+ years of experience in technical program management, incident management, or security operations
  • significant time spent in a detection & response or security incident response context
  • led or built incident response programs at a technology company
  • comfortable participating in on-call responsibilities and leading incident response during high-severity security events
  • strong analytical skills and experience with incident trend analysis, metrics reporting, and data-driven prioritization
  • highly organized with a knack for bringing structure to ambiguous, fast-moving situations
  • excellent communication skills, especially under pressure and when coordinating across technical and non-technical stakeholders, including executive leadership

Nice to have

  • experience in a high-growth or security-intensive environment
  • experience building and scaling operational processes from the ground up in environments where structure didn’t previously exist
  • Thrive in fast-paced environments where priorities shift and you’re often working with incomplete information.

What the JD emphasized

  • demonstrated track record of turning incident data into organizational improvements
  • building and scaling operational processes from the ground up
  • driving accountability and follow-through across multiple teams without direct authority