Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Manager - Cyber Operations & Assurance- Incident Response

$123k - $215.25k

American Express

Job ID: 26012722Posted: 2026-08-19Location: Phoenix, AZ, United States; Atlanta, GA, United States; Palo Alto, CA, United States; Salt Lake City, UT, United States; Sunrise, FL, United States; Charlotte, NC, United States; New York, NY, United StatesSalary: $123000 - $215250 annually + bonus + benefitsJob Function: CybersecuritySchedule: Full timeShift: DayWorkplace: HybridCareer Area: TechnologyCompany: American ExpressDescriptionJoining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.The Technology organization enables and accelerates the company’s growth strategies, delivering global capabilities and services in support of Amex’s customers and colleagues, while maintaining 24/7 servicing and availability to ensure an uninterrupted, high-quality customer experience. Technology provides the foundation for everything we do in the company while driving differentiation through building and leveraging innovative technology and data insights.At American Express, our mission is to deliver the world’s best customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a foundation of trust, service, and security. We leverage advanced technologies and data-driven insights to stay ahead of an evolving threat landscape. We foster a culture of passion, curiosity, and courage—empowering you to innovate, grow, and help shape the future of a Fortune 100 company.Trust. Service. Security.American Express seeks to recruit a passionate and experienced Leader for its Incident Response team. This is a senior-level, hands-on, highly technical role performing incident response activities ranging from pre-incident preparation, active incident response, and post-incident analysis and recovery. You will be a key technical resource conducting investigations, performing advanced analysis, identifying attacker TTPs, building attack narratives, and executing response actions.As part of our evolution toward a Next Generation Agentic SOC, this role will also help drive the adoption of AI-enabled security operations, intelligent automation, and autonomous analyst workflows. The ideal candidate combines deep incident response expertise with curiosity and practical experience in AI-assisted detection, security automation, and modern SOC engineering practices.You are a motivated leader who will directly manage, mentor, and develop a team of SOC analysts while driving the people, processes, and technology that empower the team to investigate sophisticated threats at scale. This role requires critical thinking, innovative problem solving, technical leadership, people leadership, and effective communication across both technical and executive audiences.ResponsibilitiesPeople Leadership & Team Development Directly lead and manage a team of SOC analysts, including hiring, onboarding, day-to-day supervision, performance management, and career development, fostering a high-performing and engaged team culture.Conduct regular 1:1s, performance reviews, and goal-setting with direct reports; provide timely, constructive feedback and coaching to accelerate individual and team growth.Mentor and develop junior and mid-level analysts, building technical skills, investigative rigor, and professional capabilities across the team; create clear career progression pathways from Tier 1 through senior roles.Manage shift schedules, on-call rotations, and workload distribution to ensure 247 operational coverage while proactively mitigating analyst burnout and maintaining team morale.Drive a culture of continuous learning by identifying training opportunities, encouraging pursuit of industry certifications (e.g., GCIH, GCFA, GCIA), facilitating hands-on exercises (e.g., Immersive Labs, tabletop exercises), and championing knowledge-sharing across the team.Recruit and retain top talent by partnering with HR and hiring managers to define role requirements, conduct interviews, and build a diverse and skilled analyst pipeline.Incident Response & Technical Operations Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations and escalations from junior analysts across Windows, Mac, Linux, Cloud, SaaS, and hybrid environments.Participate in incident response, cyber crisis management, and enterprise-wide security events.Advise leadership on containment, eradication, and recovery strategies during incident response.Fully scope incidents through proper identification of all affected systems, identities, applications, and/or accounts.Recognize attacker tactics, techniques, and procedures (TTPs) as well as Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) applicable to current and future investigations.Serve as a technical escalation point for the analyst team, providing real-time guidance on complex or high-severity investigations and ensuring quality and consistency of investigative outputs.Contribute to team projects, process improvement, and development of new security operations capabilities.Help curate a world-class security operations and incident response program with a relentless focus on innovation, intelligent automation, and continuous improvement.Assess and develop incident response best practices to help mature the overall security operations and AI-assisted defense capabilities of the organization.Produce high-quality written and verbal reports, recommendations, executive briefings, and technical findings.Participate in on-call rotation and provide after-hours support on an as-needed basis.AI-Enabled Security Operations & Automation Partner with detection engineering, threat intelligence, data science, and security engineering teams to operationalize AI-driven detection and response capabilities.Assist in the design, tuning, and oversight of AI-enabled SOC workflows, analyst copilots, and autonomous or semi-autonomous response agents.Develop and optimize prompts, workflows, and guardrails for large language model (LLM) and AI-agent-assisted investigations and triage processes.Evaluate and validate AI-generated investigative outputs to ensure operational accuracy, reliability, explainability, and security.Help identify opportunities to leverage AI/ML, orchestration, and automation technologies to reduce analyst toil and accelerate response times.Participate in development and integration of SOAR playbooks, AI-assisted enrichment pipelines, and security automation frameworks.Contribute to AI governance and operational risk management efforts related to AI-enabled security tooling and workflows.Champion AI adoption within the team by training analysts on AI-assisted tools and workflows, gathering analyst feedback to drive iterative improvements, and ensuring responsible use aligned with organizational governance.Stay current on industry trends, attack techniques, AI-enabled threats, adversarial AI risks, mitigation techniques, and emerging security technologiesQualifications3+ years of experience in information security, security operations, incident response, threat hunting, or cyber defense.Experience with host, network, and/or memory forensics.Experience with various network and/or host-based security tools used to detect and respond to security events (e.g., SIEM, EDR, NDR, SOAR, web proxy, IDS/IPS, cloud-native security platforms, etc.).Theoretical and practical security knowledge and investigation experience with Mac, Linux, Windows, and cloud environments.Strong understanding of incident response lifecycles, attacker methodologies, and cyber kill chain concepts.Experience performing analysis of complex security incidents in enterprise environments.Familiarity with scripting or programming languages such as Python, PowerShell, Go, or similar.Ability to convey complex technical concepts to audiences with varying levels of technical expertise.Strong analytical, investigative, documentation, and communication skills.Demonstrated curiosity and adaptability toward emerging AI-enabled security technologies and workflows.Demonstrated ability to lead, motivate, and develop technical teams in high-tempo, operationally demanding environments.Strong interpersonal and conflict-resolution skills, with the ability to foster a collaborative, inclusive, and psychologically safe team environment.Preferred:1+ years of experience in a people leadership, team lead, or supervisory role, including direct responsibility for coaching, mentoring, or managing technical staff.Experience working within a modern SOC leveraging AI-assisted analysis, security automation, and/or SOAR technologies.Familiarity with AI/ML concepts and practical applications within cybersecurity operations.Experience with prompt engineering, LLM-assisted workflows, or AI copilots for security investigations and operational efficiency.Understanding of AI agent architecture, orchestration frameworks, retrieval-augmented generation (RAG), vector databases, or autonomous workflow concepts.Experience integrating APIs, automation pipelines, or AI-enabled tooling into SOC workflows.Knowledge of adversarial AI threats, prompt injection risks, model misuse, or AI security governance principles.Experience building or operationalizing automated detection, enrichment, triage, or response capabilities.Knowledge and investigation experience in a global, multi-cloud environment.Experience with detection engineering, threat hunting, or behavioral analytics.Familiarity with cloud-native security technologies and telemetry sources.Multiple applicable certifications (GSE, GDAT, GCIA, GCIH, GCFA, GNFA, GCFE, GREM, CCSP, CISSP, CEH, etc.).AI-related certifications or hands-on experience with enterprise AI platforms, orchestration frameworks, or automation tooling.Experience managing performance cycles, conducting calibrations, and building talent development plans within a security operations or SOC environment.Experience managing geographically distributed or shift-based teams supporting 247 operations.Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.

Vacancy posted 7 hours ago
Similar jobs that could be interesting for youBased on the Senior Manager - Cyber Operations & Assurance- Incident Response in Palo Alto, CA vacancy
  • $160k - $200k

     ...and effectively triage incidents. The role will involve...  ...to spearhead the response and resolution efforts...  ...for critical customer operational issues across the globe...  ...customer engagements and managing the execution of industry...  ...forensic analysis, cyber threat intelligence, or... 
    Cyber
    Senior

    Gruve

    Redwood City, CA
    4 days ago
  • $210.6k - $305.1k

     ...team builds and operates our US GovCloud platform...  .... This team is responsible for architecting,...  ...Experience Assurance platform that empowers...  ...vision for the management and continued...  ...identifying and analyzing cyber security risks,...  ...management, and incident response... 
    Cyber
    Senior
    Full time
    Temporary work
    Local area
    Flexible hours

    CISCO Systems

    Los Altos, CA
    3 days ago
  • $157.59k - $203.94k

     ...lives of patients for generations to come.  As the Sr Manager Quality Assurance - GMP Operations at Gilead, you will provide Quality leadership and...  ...professional organizations is preferred.Specific Job Responsibilities:Manages, prioritizes, and participates in batch... 
    Senior
    Full time
    Contract work
    For contractors
    Local area

    GILEAD Sciences

    Foster, CA
    1 day ago
  • $80 - $87 per hour

    Operations Manager - Resilience & Incident Management Operations Manager - Resilience & Incident...  ...sources to triggers, response decisions, and actions, clearly...  ..., Cloud migrations, Cyber-Security and Engineering....  ...Training arm - Cognixia. Seniority level Seniority level Associate... 
    Cyber
    Contract work
    Work at office

    Collabera

    Mountain View, CA
    1 day ago
  • $207k - $301k

    Google is seeking a Security Engineer to manage incident response operations and improve cybersecurity resilience. Ideal candidates possess deep experience in threat containment and network forensics. This role involves working with software engineers to identify and fix... 
    Senior

    Google

    Sunnyvale, CA
    1 day ago
  • $181k - $253.67k

     ...connected risk across data, cyber, identity, and AI. The...  ...Cloud is a fully managed, cloud-native SaaS...  ...About the TeamOur HR team operates with a "one-team"...  ...collaborative, hands-on Senior Manager, HR Operations...  ...function. This role is responsible for delivering operational... 
    Cyber
    Senior
    Permanent employment
    Full time
    H1b
    Local area

    Druva

    Santa Clara, CA
    1 day ago
  • $190k - $284k

     ...have fun together.The Company operates Snapchat, a visual messaging...  ...Security Technical Program Manager to join Snap! The Security...  ...risk programs that improve cyber maturity across core security...  ...as vulnerability management, incident response, detection and response effectiveness... 
    Cyber
    Senior
    Full time
    Live in
    Work at office
    Local area

    Snap

    Palo Alto, CA
    4 days ago
  • $145k - $210k

    Senior Cyber Security EngineerCooley is seeking a Senior Cyber Security...  ...to the technical or operational responsibilities outlined later in this document...  ...will implement and manage security systems and tools...  ...systemsAs a member of the Incident Response team respond to alerts... 
    Cyber
    Senior
    Full time
    Temporary work
    Work at office
    Flexible hours
    Weekend work

    Cooley

    Palo Alto, CA
    1 day ago
  • $112k - $209k

     ...Gates LLP is seeking a Senior Security Engineer to...  ..., automation, incident response, and technical leadership...  ...measures and optimize operational efficiency across the...  ...RELATIONSHIPSDirector, Security; Manager, Security Operations;...  ...threat hunting, and cyber threat actor tactics,... 
    Cyber
    Senior
    Full time
    Temporary work
    Work experience placement
    Local area
    Remote work

    K&L Gates

    Palo Alto, CA
    7 hours ago
  • Aurora in Mountain View, CA seeks a Senior Manager of Detection & Response to lead a growing team protecting vehicles, cloud, and enterprise systems. This hands-on leader fosters strategy, detections, incident response, and SOC improvements in a fast-paced hybrid setting... 
    Senior

    Aurora

    Mountain View, CA
    2 days ago
  • $74.73 - $99.04 per hour

     ...strategic and innovative Senior Program Manager to help shape the...  ...business resilience, operational continuity, IT...  ...resilience, continuity, incident management, recovery,...  ...disaster recovery and cyber resilience strategies...  ...that support incident response, executive decision-making... 
    Cyber
    Senior
    Hourly pay
    Full time
    Local area
    Shift work
    Night shift

    Stanford Health Care

    Menlo Park, CA
    7 days ago
  • $160k - $200k

    An innovative software services startup in Redwood City is seeking an Incident Response Lead to tackle complex problems and engage directly with customers. You will lead investigations, develop playbooks, and ensure compliance with SLAs. The ideal candidate has 6+ years... 
    Senior

    Gruve

    Redwood City, CA
    1 day ago
  • $136k - $221k

     ...Investigations is seeking a Senior Technical...  ...support our work managing fraud and scams. In...  ...technology as we operate an AI-first trust...  ...investigation and incidents, using case insights...  ..., coordinating response and ensuring timely...  ...QualificationsBS/BA in cyber security, criminal... 
    Cyber
    Senior
    For contractors
    Work at office
    Flexible hours

    Linkedin

    Mountain View, CA
    3 days ago
  •  ...Legal and Compliance manages all legal and regulatory...  ...Coursera is seeking a Senior Privacy Counsel to...  ...products and services. Key responsibilities include advising on...  ...privacy impact assessments, incident response, data subject...  ...privacy, AI, and cyber issues and provide pragmatic... 
    Cyber
    Senior

    Coursera

    Mountain View, CA
    3 days ago
  • $212k - $307k

     ...looking forWe’re searching for a Senior Manager of our Detection & Response (D&R) team under our Technical Assurance division. This role leads...  ..., detection design, and incident response.In this role you...  ...Detection Engine, Security Operations Center workflows and improvements... 
    Senior
    Work at office
    Local area
    3 days per week

    Aurora Innovation

    Mountain View, CA
    2 days ago
  • This position reports to the Cyber Security Manager and is responsible for reviewing and analyzing threat feeds...  ...must analyze escalated security incidents from linear departments to validate...  ...Experience working with a Security Operation Center Experience in full life... 
    Cyber
    Senior

    Bay Side

    Santa Clara, CA
    1 day ago
  • $134.5k - $182k

     ...seeking a highly motivated, strategic, and detail-oriented Senior Business Operations Manager (Financial Operations) to oversee organizational budget...  ...operations, and process optimization. This role is responsible for end-to-end budget management, financial modeling, procurement... 
    Senior
    Worldwide

    Intuit

    Mountain View, CA
    1 day ago
  • $72k - $184.44k

    The Opportunity As a Digital Assurance & Transparency - IT Audit Senior Associate, you will focus on providing...  ...In this role at PwC, you will be responsible for evaluating compliance with regulations...  ...assessing governance and risk management processes and related controls.... 
    Senior
    Full time
    H1b

    PwC

    Palo Alto, CA
    3 days ago
  • $171.4k - $257k

    Senior Manager, Social Media and Digital Content Rubrik...  ...B2B, enterprise AI, cyber, or technology sectors...  ...social and digital response during sensitive or high...  ...moments, security incidents, industry news cycles...  ...the Security and AI Operations Company, leads at the... 
    Cyber
    Senior
    Full time
    Local area

    Rubrik

    Palo Alto, CA
    15 days ago
  • $183k - $256k

    Foster City, CAFleet Operations - Fleet Operations Program Management /Full-time /HybridZoox's Fleet...  ..., forward-thinking Senior / Staff Program Manager...  ...System Design & Mission Assurance and other safety teams to...  ...analyzing resumes, or assessing responses and identifying... 
    Senior
    Full time
    Temporary work
    Relocation package

    Zoox

    Foster, CA
    2 days ago
  •  ...owns site and data center operations programs supporting...  ...coordination, and metrics/KPIs.Responsibilities Own end-to-end...  ...commissioning, change management, and break/fix workflowsLead incident reviews and postmortems...  ...and operational risks to senior leadershipRequired Background... 
    Senior

    Cerebras Systems

    Sunnyvale, CA
    1 day ago
  • $243.1k - $314.6k

     ...improving health equity worldwide, while operating in a responsible and sustainable manner. Corporate...  ...patients, communities, and society.The Senior Director, Corporate Responsibility Operations...  ...Performance ManagementEstablish and manage key performance indicators (KPIs) and... 
    Senior
    Full time
    For contractors
    Local area
    Worldwide

    GILEAD Sciences

    Foster, CA
    3 days ago
  • $262k - $364k

     ...threat detection and incident response capabilities, preparing...  ...platforms and operational standards, driving widespread...  ...outcomes for senior leadership.Recognized...  ...Cloud Platform (GCP) Cyber Defense Center (GCDC)...  ...vulnerability, and cloud-abuse management across Google Cloud.... 
    Cyber
    Senior

    Google

    Sunnyvale, CA
    7 hours ago
  • $160k - $240k

     ...in Sunnyvale and help operate financial platforms at...  ...call rotations and lead incident response activities; run and...  ...define SLIs and SLOs, manage error budgets and translate...  ...or DevOps at a mid-to-senior level.Strong shell...  ...postings may be used by cyber criminals to target... 
    Cyber
    Senior
    Full time

    Fiserv

    Sunnyvale, CA
    7 hours ago
  • $138.1k - $172.6k

     ...highly motivated Senior Scientist with a...  ...patients.PRIMARY RESPONSIBILITIES:Design, develop and...  .... Mentor and manage the functional activities...  ...and Quality Assurance to ensure that developed...  ..., laboratory operations, bioinformatics,...  .... Natera takes cyber crimes seriously,... 
    Cyber
    Senior
    Immediate start
    Worldwide

    Natera

    San Carlos, CA
    1 day ago
  • $163.8k - $225.25k

     ...proactive leader who brings both operational discipline and a continuous...  ...travel program and managing our corporate card operations...  ...and transparent reporting to senior leadership.Reporting to the...  ...and external regulations.Key Responsibilities:Leadership & OperationsLead... 
    Senior
    Full time
    Work at office
    Work from home

    Guardant Health

    Palo Alto, CA
    2 days ago
  • $218.3k - $327.5k

     ...Direct team helps customers manage and analyze petabytes of data...  ...inclusive team culture. You will be responsible for setting clear goals,...  ...(RBRK), the Security and AI Operations Company, leads at the intersection of data protection, cyber resilience, and enterprise AI... 
    Cyber
    Senior
    Work at office
    Local area

    Rubrik

    Palo Alto, CA
    3 days ago
  • $155k - $175k

     ...New Jersey, the UK, and Ireland. Overview Senior Manager, Global Collaborations Business Operations, is an action-role delivering operational execution...  ...-paced, high-impact environment. Role And Responsibilities Study Start-up & Management Primary focus... 
    Senior
    Full time

    Summit Therapeutics, Inc.

    Palo Alto, CA
    17 days ago
  •  ...experienced leader for its Infrastructure & Network Services team in Mountain View. You will manage a high-performing group of engineers and vendor agents, drive incident response, and govern ITIL processes while overseeing deployment of critical security and networking... 
    Senior

    Waymo

    Mountain View, CA
    2 days ago
  • $148.4k - $222.6k

     ...all things People! Our Senior People Partner role is...  ...enabler to our people managers. This role is business...  ...HR. Your primary responsibilities will involve providing...  ...and Inclusion, People Operations to identify and enable...  ...intersection of data protection, cyber resilience, and... 
    Cyber
    Senior
    Local area
    Remote work
    Shift work

    Rubrik

    Palo Alto, CA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Manager - Cyber Operations & Assurance- Incident Response. Be the first to apply!