Jobs · Utah

Manager, Incident Response

Ancestry · Draper, UT · 3 wk ago
HybridFull-time

When you join Ancestry, you join a human-centered company where every person’s story is important. Ancestry®, the global leader in family history, connects everyone with their past so they can discover, preserve, and share their unique family stories. With our unparalleled collection of more than 65 billion records, over 3.5 million subscribers, and over 27 million people in our growing DNA network, customers can discover their family story and gain a new level of understanding about their lives.

We are committed to a location-flexible work approach, allowing you to choose to work in the nearest office, from your home, or a hybrid of both (subject to location restrictions and roles that require in-office presence). We foster a work environment that is inclusive and diverse, where every idea and perspective is valued.

About the role

We are seeking a battle-tested, highly self-driven Manager, Incident Response to lead, inspire, and continuously mature our Incident Response Team. In this role, you will mentor a team of responders, threat hunters, and forensic analysts, driving strategic improvements to our response capabilities. You will ensure our organization can swiftly detect, contain, and eradicate advanced threats across a modern infrastructure.

Responsibilities

  • Provide guidance and technical mentorship for our Incident Response engineers, fostering a culture of psychological safety to combat security team burnout.
  • Oversee end-to-end incident handling (triage, containment, forensics, eradication, and recovery) for high-impact or complex enterprise security incidents.
  • Establish, track, and analyze key performance indicators (e.g., MTTD, MTTR, true/false positive ratios) to present risk-focused operational updates to leadership.
  • Act as the primary coordinator during major incidents, translating complex technical findings into clear, actionable risk summaries for leadership, legal counsel, and PR.
  • Lead post-incident reviews (Root Cause Analysis) to transform lessons learned into tangible detections, architecture enhancements, and process improvements.
  • Drive the creation and maturation of IR runbooks, leveraging automation to drastically reduce containment timelines.

Requirements

  • 3+ years of experience directly managing and mentoring incident response professionals.
  • 6+ years of hands-on experience in enterprise-scale incident response, digital forensics, and advanced blue team operations.
  • A highly self-driven individual with a proven track record of proactively identifying inefficiencies and spearheading initiatives to elevate personal skillsets, team dynamics, and operational processes.
  • Deep understanding of modern attacker tools, tactics, and procedures (TTPs), threat actor motivations, and mapping detections to the MITRE ATT&CK framework.
  • Proven track record of maintaining strategic focus and a calm demeanor while leading cross-functional teams through high-stress incidents, paired with exceptional communication skills.
  • Core familiarity with utilizing modern AI tools and Large Language Models (LLMs) to enhance productivity and augment technical workflows.

Skills

Core Technology Capabilities:

  • Enterprise EDR / XDR Solutions: Deep familiarity with industry-standard Endpoint Detection and Response platforms for rapid containment, host isolation, and endpoint telemetry analysis.
  • AWS Cloud Infrastructure: Operational understanding of Amazon Web Services (AWS) core environments and native security capabilities (e.g., CloudTrail, GuardDuty, IAM) to investigate cloud-native threats.
  • Enterprise SIEM & Centralized Logging: Experience leveraging large-scale security information and event management systems to correlate disparate data sources and track adversarial movement.
  • SOAR & Automation Workflows: Conceptual or practical experience utilizing Security Orchestration, Automation, and Response tools to streamline repeatable containment processes.
  • Digital Forensics (DFIR): Familiarity with enterprise-grade host, memory, and network forensics tools required to extract artifacts and timeline malicious activity.

Preferred Qualifications

  • Advanced Elasticsearch Data Analysis: Direct experience operating within or investigating out of a large-scale, Elasticsearch-driven security logging infrastructure, including advanced search queries and data correlation.
  • AI-Driven Process Optimization: Experience leveraging AI utilities and workflows for security process optimization, accelerating documentation/runbook creation, or assisting in rapid development and scripting.
  • Industry Certifications: Advanced specialized security certifications such as GIAC (GCIH, GCFA, GNFA), CISSP, or CISM.
  • Adversarial Emulation: Experience organizing or participating in Purple Team exercises and tabletop simulations alongside Red Teams to validate detection engineering.
  • Cloud Forensics Specialization: Technical experience investigating compromises in containerized (Kubernetes/Docker) or serverless cloud environments.

Benefits

We offer excellent benefits and a competitive compensation package, including health, dental, vision, bonus, and equity. For additional information, visit Ancestry Careers.

Pay

The base salary range for this position is $132,410 - $165,510, with eligibility for bonus, equity, and comprehensive benefits. The actual salary will vary by geographic region and job experience.

Similar jobs

Manager, Incident Response

PonduranceUnited States· 4 wk ago
RemoteInformation Technology$150k–$175k/yrapply on pondurance.applytojob.com