The opportunity
Deadline to apply: None. Applications will be received on a rolling basis.
What you'll do
Own the end-to-end D&R incident management program: detection workflows, response processes, escalation paths, communication standards, and remediation tracking.
Serve as incident commander for security incidents, driving clear: coordination across executive, engineering, security, legal, and other appropriate stakeholders.
Establish and run incident commander rotations within D&R, ensuring clear: ownership and effective coordination during incidents of varying severity.
Drive post-incident accountability by defining how action items are captured,: assigned, tracked, and completed across teams—ensuring follow-through on both tactical fixes and strategic improvements.
Gather, analyze, and report on incident trends and patterns to surface: systemic risks, recurring root causes, and areas where the organization is most vulnerable.
Translate trend analysis into actionable cross-functional initiatives: partner with engineering, infrastructure, security, and product teams to prioritize and implement broad fixes and preventive improvements that address root causes rather than symptoms.
What they're looking for
- Lead incident review forums (post-mortems, retrospectives) and ensure: learnings are captured, socialized, and acted upon across the organization.
- Develop and maintain D&R incident response documentation, playbooks,: runbooks, and training materials; keep them current as the threat landscape and our systems evolve.
- Partner with detection engineering to improve alert fidelity, reduce noise,: and shorten time-to-detection for security events.
- Define, develop, and track incident management KPIs and report regularly to D&R and Security leadership.