Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Incident Management Lead, Data Center Security

$290k - $365k

Anthropic

About Anthropic

Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About the role

Anthropic operates and is building data center campuses around the world, run day to day through operating partners, site vendors, and contracted security services. Things go wrong at those sites the way they go wrong at any critical infrastructure: access issues, contractor incidents, protests, weather, equipment failures, and occasionally something with the potential for global impact. Today, what counts as an incident, who gets told, and how it is reported vary by site and by vendor.

As Lead for Crisis and Incident Management, you will build the program that removes that variance, and you will build it with the people who have to live with it. The first job is definition: working with operating partners, site security vendors, managed-service providers, and internal teams to agree on what counts as a minor escalation versus a major incident of global impact, the severity levels in between, the thresholds that move an event from one level to the next, and who gets told, how fast, and in what format. The second job is adoption: turning those definitions into playbooks, training, and exercises so that responders at every site and vendor actually respond the right way, and running the after-action reviews that show where they did not. The third job is measurement: defining the incident metrics, building the reporting, and giving leadership a regular, accurate picture of how response is performing across the fleet. Underneath all three sits the cross-functional work of getting partners to buy in, because a framework no partner has signed up to is a document, not a program.

Continuous coverage is part of the picture. As the program matures, you will shape a 24/7 monitoring and response capability through GSOC-type managed services and site vendors, so that the framework holds at three in the morning at any site in the fleet. That build-out follows from the definitions and partner agreements above rather than replacing them. When a major incident does happen, you run it: activation, coordination, leadership communication, stand-down, and the after-action review that makes the program better.

This is a program-building role, not a shift-supervision role. The deliverable is a framework that partners have adopted, that works at any site, and that reports on itself, run largely through vendors and managed services rather than a large in-house team. Where existing processes and vendor arrangements don't support that, you will have the authority, and the expectation, to change them.

Role boundaries. This seat is distinct from the Data Center Security Delivery Lead (who owns security through construction, commissioning, and handover on new builds), from regional security operations leads (who own steady-state regional programs and vendor relationships site by site), and from the team's systems-engineering roles (who build platforms and tooling). This role owns the horizontal incident and crisis layer across the operating fleet: the incident definitions and severity framework, partner adoption and governance, incident reporting and metrics, major incident command, post-incident review, and, as it develops, the 24/7 coverage model, applied consistently across every site and vendor.

Key responsibilities

You will build and own the global crisis and incident management program for data center physical security.

  • Incident definition and severity framework: define, with partners, what counts as an incident and the tiers from minor site escalation to major incident of global impact, with clear thresholds, escalation and activation criteria, notification requirements, and decision rights at each tier. This is the foundation the rest of the program is built on.

  • Cross-functional partner buy-in and governance: bring operating partners, site security vendors, managed-service providers, and internal teams into the definition work so the framework is theirs as well as ours, and establish the governance (owners, review cadence, change process) that keeps it current as the fleet grows.

  • Adoption and response readiness: turn the framework into playbooks, training, and tabletop and functional exercises across sites and vendors, so responders know the right response before the next real incident and the escalation chain is tested by design.

  • Metrics and reporting: define the incident metrics that show whether definitions are being applied and whether response is improving, build the dashboards and reporting behind them, and own the executive reporting cadence, from real-time notification through leadership escalation and executive summaries.

  • Vendor and managed-service consistency: hold multiple vendors and GSOC-type providers to one standard: common definitions, common procedures, common reporting formats, common escalation triggers, with performance measured and enforced.

  • Major incident management: run the crisis process when an incident has multi-site or global impact: activation, coordination across sites, vendors, and internal teams, decision support to leadership, and formal stand-down.

  • Post-incident review and improvement: run structured after-action reviews, track corrective actions to closure, and feed lessons back into definitions, playbooks, procedures, and vendor contracts.

  • 24/7 coverage model: as the program matures, design and run an always-on monitoring, escalation, and response capability through GSOC-type managed services and site security vendors, achieving continuous coverage without building a large in-house shift operation.

Minimum qualifications

  • Have built or substantially rebuilt an incident management or crisis management program (not just operated within one), including the definitions and severity model at its core, and can describe what existed before you, what you changed, and how you know it worked.

  • Have brought partners you don't control (operators, vendors, internal teams) into agreeing on definitions and procedures, and can describe how you won that buy-in and kept it.

  • Have driven adoption: you have taken a framework from paper into playbooks, training, and exercises, and can point to responders behaving differently as a result.

  • Have defined incident metrics and built the reporting behind them, and can explain which measures actually told leadership something and which did not.

  • Know data centers: you have worked physical security in or around data center or comparable critical-infrastructure operations, and understand the environment of operating partners, contractors, and 24/7 site activity.

  • Have run major incidents end to end: activation, multi-party coordination, leadership communication, stand-down, and after-action, and can walk through specific ones.

  • Have held vendors or managed services (a GSOC, monitoring provider, or guard force) to defined performance standards, with evidence rather than assurances.

  • Can make the severity call quickly on incomplete information, defend it either way, and adjust as facts arrive.

  • Write clearly under pressure: your incident report-outs can go to executives without editing.

  • Work through influence across sites, vendors, and internal teams you don't control; you shape response rather than waiting to be given authority.

Preferred qualification

  • Experience designing incident taxonomies, severity models, or escalation frameworks that were adopted across multiple organizations or vendors.

  • Experience running an incident metrics program at scale (dashboards and an executive reporting cadence spanning multiple sites or vendors).

  • Incident command system experience (ICS/NIMS or comparable).

  • Experience standing up or running a global security operations center (GSOC) or equivalent 24/7 capability.

  • CPP (Certified Protection Professional), PSP (Physical Security Professional), CEM (Certified Emergency Manager), CBCP, or comparable certifications.

  • Hyperscaler, major colocation, or critical-infrastructure operator experience.

  • Business continuity or emergency management program background.

  • Experience in regulated or high-assurance environments.

The annual compensation range for this role is listed below. 

For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.

Annual Salary:

$290,000—$365,000 USD

Logistics

Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience

Required field of study:  A field relevant to the role as demonstrated through coursework, training, or professional experience

Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position

Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.

Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links—visit directly for confirmed position openings.

How we're different

We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact — advancing our long-term goals of steerable, trustworthy AI — rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills.

The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.

Come work with us!

Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues. Guidance on Candidates' AI Usage: Learn about our policy for using AI in our application process.

Vacancy posted 8 days ago
Similar jobs that could be interesting for youBased on the Incident Management Lead, Data Center Security in California vacancy
  •  ...Incident Response Lead Location: Downey, CA An Information Security Specialist interprets information security policies, standards...  ...for comprehensive systems and data protection; assess and...  ...strategic recommendations; and manages, supports, installs and maintains... 
    Suggested

    WATI

    Downey, CA
    5 days ago
  • $240k - $280k

     ...Responsibilities Will Include Obsidian Security is the leading SaaS security platform,...  ...access to sensitive data through integrations, creating...  ...anomalous OAuth token activity and manages integration risks. Major...  ...actions, and partner with incident response to operationalize... 
    Suggested
    Work from home

    Obsidian Security

    Palo Alto, CA
    1 day ago
  •  ...Chevron Corporation is seeking a Lead Security Operations Coordinator at the El Segundo refinery. You will lead a security team responsible...  ...federal and local regulators, internal stakeholders, and incident management teams to safeguard assets and personnel. Strong leadership... 
    Suggested
    Local area

    Chevron

    El Segundo, CA
    2 days ago
  •  ...Overview A law firm seeks an Incident Response Associate to join their...  ..., and compliance. Duties Lead all aspects of the incident response...  ..., including scoping calls and data mining efforts. Collaborate...  ...communication skills. Ability to manage caseloads and client... 
    Suggested
    Flexible hours

    BCG Attorney Search

    Irvine, CA
    1 day ago
  •  ...Orrick is seeking a Managing Associate to join our Cybersecurity & Incident Response practice. The role focuses on incident response leadership, governance, investigations, and advisory work for clients from startups to global enterprises. You will gain hands-on training... 
    Suggested

    Orrick Herrington & Suttcliffe

    San Francisco, CA
    3 days ago
  •  ...California Department of Industrial Relations seeks an Information Technology Specialist I to manage, track and assign incidents via ServiceNow, lead technical teams, and serve as the SME for incident resolution within the Office of Information Services Technical Support... 
    Work at office

    California Department of Industrial Relations

    Alameda, CA
    5 days ago
  •  ...United States Digital Space LLC is seeking an Incident & Crisis Management Lead to join the Global Safety, Intelligence, and Security team. The role focuses on operationalizing crisis response, coordinating cross-functional teams, and preparing for incidents across physical... 

    United States Digital Space LLC

    San Francisco, CA
    3 days ago
  • $183k - $252k

    Palo Alto Networks, Inc. is seeking a Senior Consultant for cybersecurity incident response. This senior-level role will lead breach investigations and serve as a hands-on technical leader for Unit 42 clients in various industries. Candidates should have over 10 years of... 

    Jobleads-US

    Burbank, CA
    2 days ago
  • $151k - $208k

     ...Principal Consultant in Burbank, California, responsible for leading incident response and digital forensics services. This role involves serving...  ...leader on investigations and guiding clients through security incidents with expertise and precision. Ideal candidates have... 
    Remote job

    Jobleads-US

    Burbank, CA
    2 days ago
  •  ...Surefox North America Inc in San Francisco is seeking an experienced Incident Commander. You will perform emergency response duties, work closely with clients, and ensure safety procedures are followed. The ideal candidate will have strong observational skills and the... 

    Surefox North America Inc

    San Francisco, CA
    5 days ago
  • Professional Search Group is seeking a Senior Security Analyst for its Malibu area Information Security team. This...  ...Security to protect critical infrastructure and sensitive data. The position emphasizes owning incidents, maturing response procedures, and collaborating with... 

    Professional Search Group

    Malibu, CA
    2 days ago
  • $109.9k - $187.45k

     ...talents to Ross, our leading off-price retail...  ...8 distribution centers nationwide. With 2...  ...with the Business management, IT teams, and...  ...translated into scalable, secure, and maintainable...  ...workflows, and data pipelines to ensure...  ...operations to resolve incidents in Production.... 
    Work at office
    Local area
    Remote work

    Ross Stores

    Dublin, CA
    more than 2 months ago
  •  ...Associate to maintain the health of deployed defense technology and coordinate incident resolution across mission operations, program management, engineering, and sustainment. The role focuses on data analysis, root cause investigations, and driving improvements to... 

    Anduril

    Costa Mesa, CA
    5 days ago
  • DoorDash is seeking a Safety Customer Experience leader to drive the strategy and execution for incident prevention, identification, and response on the platform. You will bridge Product, Operations, Policy, Analytics, and Customer Experience to design scalable solutions... 

    DoorDash

    Los Angeles, CA
    5 days ago
  •  ...Specialist I (ITS I) manages, tracks and assigns the...  ...Department’s reported incidents to the appropriate technical...  ...I also serves as a lead for the technical...  ...promoting a safe and secure work environment, free...  ...sites, including CDT’s Data Center (TMS). DIR does not participate... 
    Work at office
    Remote work

    California Department of Industrial Relations

    Alameda, CA
    1 day ago
  • Viking Cruises is looking for a Privacy Manager to join its Data Privacy Team in Woodland Hills, CA. This hybrid role will focus on privacy management, incident response, and compliance operations, requiring collaboration across the organization. The ideal candidate will... 

    Viking Cruises

    Los Angeles, CA
    3 days ago
  • Box is seeking a Senior Technical Duty Officer (Senior Incident Commander) to join the GTOC team in Redwood City, CA. You will lead high-severity incidents, build tooling, and improve observability to enhance site resiliency and reliability across critical services. You... 

    Box

    Redwood City, CA
    2 days ago
  •  ...California, seeks a Global Planning & Operations Escalation Manager responsible for managing high-severity incidents and escalated issues. The role requires a Bachelor'...  .... The position includes responsibilities like leading cross-functional teams, root cause analysis, and... 
    Remote work

    Lam Research

    Fremont, CA
    2 days ago
  • CrowdStrike, Inc. is seeking a Principal Consultant to lead incident response engagements and drive investigations against the world's most advanced threats. You will develop new hunting techniques and work closely with clients, counsel, and leadership to expose breaches... 
    Remote job

    CrowdStrike, Inc.

    Sunnyvale, CA
    3 days ago
  •  ...Triskele Labs are one of the leading providers of cybersecurity services...  ...boutiques to run a 24x7x365 Security Operations Team completely...  ...Labs Digital Forensics and Incident Response (DFIR) team assists...  ...an incident and find out if data has been compromised. As an end... 
    Remote job
    Work at office

    Triskele Labs

    Los Angeles, CA
    1 day ago
  •  ...role at the Fontana, CA facility. The position focuses on deploying Managing Environmental Safety and Health (MESH) initiatives, maintaining EHS systems, and reporting EHS metrics. You will lead incident investigations, support training programs (PPE, First Aid, Machine... 

    Eaton

    Fontana, CA
    1 day ago
  • $180k - $218k

    Cydecor, Inc. is seeking a Lead Cyber Mission Threat Analyst to support critical U.S. Navy cybersecurity operations in Port Hueneme,...  ...experience in cyber operations, particularly in threat detection and incident response. The ideal candidate will lead cybersecurity efforts,... 

    Cydecor, Inc.

    Port Hueneme, CA
    1 day ago
  • A technology services company is looking for an Incident and Problem Manager in California. The successful candidate will oversee incident management processes, lead a remote team, and drive continual improvement in service delivery. Key qualifications include 3+ years... 
    Remote job

    F3 Design

    Anaheim, CA
    5 days ago
  • Ultra Clean Technology in Fremont, CA seeks an experienced EHS Manager to lead safety and compliance programs in the semiconductor industry. You will actively manage permits, lead incident investigations, and foster a zero-incident culture at the site. The ideal candidate... 

    Ultra Clean Technology

    Fremont, CA
    1 day ago
  • $7.5k

     ...applying AI/ML to investment management. We have become a...  ...as handling large-scale data lifecycle processes...  ...You will be expected to lead by example—driving automation...  ...and ensure effective incident response processes are...  ...with co-located data center infrastructureAbility to... 
    For contractors
    Work at office
    Local area
    Remote work

    The Voleon Group

    Berkeley, CA
    5 days ago
  • $225k - $270k

     ...Deputy Chief Information Security Officer is the senior...  ...The Information Security Lead leads the security team...  ..., and serves as Incident Commander during security...  ...execution, project and program management, documentation,...  ...operational toolingApplication, Data & AI SecurityLead and... 
    Full time
    Work at office
    Remote work

    The TCW Group

    Los Angeles, CA
    2 days ago
  • $176k - $256k

    Lead evaluations of energy regulatory and policy environments in the U.S. Central region, focusing on Indiana, MISO, and PJM. Monitor...  ...and emerging tariffs to assess opportunities for Google’s data centers.Develop energy market solutions for Google’s supply needs in the... 
    Work at office
    Local area
    Remote work

    Google

    San Francisco, CA
    1 day ago
  • $192k - $278k

     ...program schedule and quality.Manage technical interactions with ASIC...  ...ASIC development.Experience leading cross-functional teams (physical...  ...from architecture to Graphic Data System II (GDSII).Experience managing...  ...Global Networking, Data Center operations, systems research,... 
    Worldwide

    Google

    Sunnyvale, CA
    4 days ago
  •  ...global energy demands grow. From massive data centers to modernizing transmission systems, our...  ...of System Protection & Studies Team Lead, we'll count on you to:Assist in the responsibility...  ...function as an Assistant Project Manager and assist in responsibility for... 
    Permanent employment
    Contract work
    Local area

    HDR

    Irvine, CA
    5 days ago
  • $180.64k - $261.58k

     ...mobility, healthcare, energy and data centers. With revenue of more than $1...  ...in high-performance power management solutions on cutting edge...  ...from you!Key Responsibilities:Lead project: own top-level design...  ...Commerce - Bureau of Industry and Security and/or the U.S. Department of... 
    Permanent employment
    Full time
    Work at office
    Day shift

    Analog Devices

    Milpitas, CA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Incident Management Lead, Data Center Security. Be the first to apply!