Incident Management Lead, Data Center Security

Anthropic$290K — $365K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Experience in building or substantially rebuilding incident management or crisis management programs
  • Proven success in getting buy-in from non-controlled partners on definitions and procedures
  • Strong history of driving framework adoption through playbooks and training
  • Ability to define incident metrics and create actionable reporting
  • Knowledge of physical security within data centers or comparable critical infrastructure
  • Expertise in managing major incidents through to conclusion and conducting thorough reviews
  • Demonstrated capability in holding vendors to defined performance standards

Responsibilities

  • Develop and oversee the global crisis and incident management program focused on data center physical security
  • Define incident criteria and severity levels in collaboration with partners
  • Engage cross-functional teams to ensure all stakeholders adopt the incident response framework
  • Create playbooks and training to improve emergency preparedness across sites
  • Establish metrics and reporting systems to track incident management performance
  • Lead and coordinate major incidents that affect multiple sites, ensuring effective response
  • Conduct post-incident reviews to refine processes and improve the program
  • Design and implement a 24/7 monitoring and response model as the program evolves

Benefits

  • Visa sponsorship available
  • Hybrid work policy requiring in-office presence 25% of the time
  • Opportunity to shape a critical business function
  • Engagement with diverse stakeholders and vendors across the industry
  • Challenging work in a cutting-edge technology environment
Full Job Description
About the role

Anthropic operates and is building data center campuses around the world, run day to day through operating partners, site vendors, and contracted security services. Things go wrong at those sites the way they go wrong at any critical infrastructure: access issues, contractor incidents, protests, weather, equipment failures, and occasionally something with the potential for global impact. Today, what counts as an incident, who gets told, and how it is reported vary by site and by vendor.

As Lead for Crisis and Incident Management, you will build the program that removes that variance, and you will build it with the people who have to live with it. The first job is definition: working with operating partners, site security vendors, managed-service providers, and internal teams to agree on what counts as a minor escalation versus a major incident of global impact, the severity levels in between, the thresholds that move an event from one level to the next, and who gets told, how fast, and in what format. The second job is adoption: turning those definitions into playbooks, training, and exercises so that responders at every site and vendor actually respond the right way, and running the after-action reviews that show where they did not. The third job is measurement: defining the incident metrics, building the reporting, and giving leadership a regular, accurate picture of how response is performing across the fleet. Underneath all three sits the cross-functional work of getting partners to buy in, because a framework no partner has signed up to is a document, not a program.

Continuous coverage is part of the picture. As the program matures, you will shape a 24/7 monitoring and response capability through GSOC-type managed services and site vendors, so that the framework holds at three in the morning at any site in the fleet. That build-out follows from the definitions and partner agreements above rather than replacing them. When a major incident does happen, you run it: activation, coordination, leadership communication, stand-down, and the after-action review that makes the program better.

This is a program-building role, not a shift-supervision role. The deliverable is a framework that partners have adopted, that works at any site, and that reports on itself, run largely through vendors and managed services rather than a large in-house team. Where existing processes and vendor arrangements don't support that, you will have the authority, and the expectation, to change them.

Role boundaries. This seat is distinct from the Data Center Security Delivery Lead (who owns security through construction, commissioning, and handover on new builds), from regional security operations leads (who own steady-state regional programs and vendor relationships site by site), and from the team's systems-engineering roles (who build platforms and tooling). This role owns the horizontal incident and crisis layer across the operating fleet: the incident definitions and severity framework, partner adoption and governance, incident reporting and metrics, major incident command, post-incident review, and, as it develops, the 24/7 coverage model, applied consistently across every site and vendor.
Key responsibilities

You will build and own the global crisis and incident management program for data center physical security.
  • Incident definition and severity framework: define, with partners, what counts as an incident and the tiers from minor site escalation to major incident of global impact, with clear thresholds, escalation and activation criteria, notification requirements, and decision rights at each tier. This is the foundation the rest of the program is built on.
  • Cross-functional partner buy-in and governance: bring operating partners, site security vendors, managed-service providers, and internal teams into the definition work so the framework is theirs as well as ours, and establish the governance (owners, review cadence, change process) that keeps it current as the fleet grows.
  • Adoption and response readiness: turn the framework into playbooks, training, and tabletop and functional exercises across sites and vendors, so responders know the right response before the next real incident and the escalation chain is tested by design.
  • Metrics and reporting: define the incident metrics that show whether definitions are being applied and whether response is improving, build the dashboards and reporting behind them, and own the executive reporting cadence, from real-time notification through leadership escalation and executive summaries.
  • Vendor and managed-service consistency: hold multiple vendors and GSOC-type providers to one standard: common definitions, common procedures, common reporting formats, common escalation triggers, with performance measured and enforced.
  • Major incident management: run the crisis process when an incident has multi-site or global impact: activation, coordination across sites, vendors, and internal teams, decision support to leadership, and formal stand-down.
  • Post-incident review and improvement: run structured after-action reviews, track corrective actions to closure, and feed lessons back into definitions, playbooks, procedures, and vendor contracts.
  • 24/7 coverage model: as the program matures, design and run an always-on monitoring, escalation, and response capability through GSOC-type managed services and site security vendors, achieving continuous coverage without building a large in-house shift operation.
Minimum qualifications
  • Have built or substantially rebuilt an incident management or crisis management program (not just operated within one), including the definitions and severity model at its core, and can describe what existed before you, what you changed, and how you know it worked.
  • Have brought partners you don't control (operators, vendors, internal teams) into agreeing on definitions and procedures, and can describe how you won that buy-in and kept it.
  • Have driven adoption: you have taken a framework from paper into playbooks, training, and exercises, and can point to responders behaving differently as a result.
  • Have defined incident metrics and built the reporting behind them, and can explain which measures actually told leadership something and which did not.
  • Know data centers: you have worked physical security in or around data center or comparable critical-infrastructure operations, and understand the environment of operating partners, contractors, and 24/7 site activity.
  • Have run major incidents end to end: activation, multi-party coordination, leadership communication, stand-down, and after-action, and can walk through specific ones.
  • Have held vendors or managed services (a GSOC, monitoring provider, or guard force) to defined performance standards, with evidence rather than assurances.
  • Can make the severity call quickly on incomplete information, defend it either way, and adjust as facts arrive.
  • Write clearly under pressure: your incident report-outs can go to executives without editing.
  • Work through influence across sites, vendors, and internal teams you don't control; you shape response rather than waiting to be given authority.
Preferred qualification
  • Experience designing incident taxonomies, severity models, or escalation frameworks that were adopted across multiple organizations or vendors.
  • Experience running an incident metrics program at scale (dashboards and an executive reporting cadence spanning multiple sites or vendors).
  • Incident command system experience (ICS/NIMS or comparable).
  • Experience standing up or running a global security operations center (GSOC) or equivalent 24/7 capability.
  • CPP (Certified Protection Professional), PSP (Physical Security Professional), CEM (Certified Emergency Manager), CBCP, or comparable certifications.
  • Hyperscaler, major colocation, or critical-infrastructure operator experience.
  • Business continuity or emergency management program background.
  • Experience in regulated or high-assurance environments.


The annual compensation range for this role is listed below.

For sales roles, the range provided is the role's On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.

Annual Salary:

$290,000-$365,000 USD

Logistics

Minimum education: Bachelor's degree or an equivalent combination of education, training, and/or experience

Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience

Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position

Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

About Anthropic

Anthropic is an artificial intelligence research lab that focuses on developing AI systems that are safe, reliable, and trustworthy. The company was founded in 2019 by Dr. Yoshua Bengio, a leading AI researcher and winner of the Turing Award. Anthropic's research is focused on developing AI systems that can learn from small amounts of data, reason about complex systems, and interact with humans in a natural way. The company is based in New York City and has a team of experienced AI researchers and engineers.
Learn more about Anthropic
Size
50 employees
Industry
Founded
2019

More Jobs at Anthropic

More Information Technology Jobs

Find similar Incident Management Lead, Data Center Security jobs: