Incident Management Lead, Data Center Security
About the role
The Lead for Crisis and Incident Management will build a program that defines and manages incidents across data center campuses worldwide. The program will include incident definitions, severity levels, partner buy-in, adoption, metrics, and reporting.
Responsibilities
Define incident definitions and severity levels with partners, ensuring clear thresholds, escalation criteria, notification requirements, and decision rights at each tier.
Bring partners into the definition work, establishing governance to keep the framework current as the fleet grows.
Turn the framework into playbooks, training, and exercises, ensuring responders know the right response before the next real incident.
Define incident metrics and build dashboards and reporting, providing leadership with regular, accurate pictures of how response is performing.
Hold vendors and managed services to defined performance standards, measuring and enforcing compliance.
Make severity calls quickly on incomplete information, defend decisions, and adjust as facts arrive.
Write clear incident reports under pressure, communicating effectively with executives.
Shape response across sites, vendors, and internal teams you don't control, using influence to drive adoption and improvement.
Requirements
Built or substantially rebuilt an incident management or crisis management program, including the definitions and severity model at its core.
Brought partners you don't control into agreeing on definitions and procedures, and kept that buy-in.
Driven adoption: took a framework from paper into playbooks, training, and exercises, and observed responders behaving differently as a result.
Defined incident metrics and built the reporting behind them, showing leadership something that mattered.
Worked physical security in or around data center or comparable critical-infrastructure operations, understanding the environment of operating partners, contractors, and 24/7 site activity.
Ran major incidents end to end, from activation to stand-down, and ran structured after-action reviews.
Held vendors or managed services to defined performance standards, with evidence rather than assurances.
Made the severity call quickly on incomplete information, defended it either way, and adjusted as facts arrived.
Wrote clearly under pressure, creating incident report-outs to executives without editing.
Worked through influence across sites, vendors, and internal teams you don't control, shaping response rather than waiting to be given authority.
Qualifications
Bachelor’s degree or equivalent combination of education, training, and/or experience in a field relevant to the role.
Experience building or substantially rebuilding an incident management or crisis management program, including the definitions and severity model at its core.
Experience bringing partners you don't control into agreeing on definitions and procedures, and keeping that buy-in.
Experience driving adoption: taking a framework from paper into playbooks, training, and exercises, and observing responders behaving differently as a result.
Experience defining incident metrics and building the reporting behind them, showing leadership something that mattered.
Experience working physical security in or around data center or comparable critical-infrastructure operations, understanding the environment of operating partners, contractors, and 24/7 site activity.
Experience running major incidents end to end: activation, multi-party coordination, leadership communication, stand-down, and after-action.
Experience holding vendors or managed services to defined performance standards, with evidence rather than assurances.
Experience making the severity call quickly on incomplete information, defending it either way, and adjusting as facts arrive.
Experience writing clearly under pressure, creating incident report-outs to executives without editing.
Experience working through influence across sites, vendors, and internal teams you don't control, shaping response rather than waiting to be given authority.
Benefits
Annual compensation range: $290,000—$365,000 USD
Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.
Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.
We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed.
Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work.
We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.
Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains.