Ancestry

Manager, Incident Response

Ancestry$132K — $165K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years of managing and mentoring incident response professionals
  • 6+ years in enterprise-scale incident response, digital forensics, and blue team operations
  • Track record of identifying inefficiencies and initiating improvements
  • Deep understanding of attacker tools, tactics, and the MITRE ATT&CK framework
  • Calm and strategic during high-stress incidents with excellent communication skills
  • Familiarity with modern AI tools and LLMs to enhance workflows

Responsibilities

  • Lead and mentor the Incident Response team to foster a supportive culture
  • Oversee incident lifecycle from triage to recovery for complex security incidents
  • Track and analyze operational metrics to report to leadership
  • Coordinate communication during major incidents, simplifying technical details for stakeholders
  • Conduct post-incident reviews to implement lessons learned
  • Develop and enhance IR playbooks, focusing on automation to improve efficiency

Benefits

  • Comprehensive health, dental, and vision coverage
  • Strong commitment to diversity and pay equity
  • Competitive compensation and bonus opportunities
  • Opportunities for professional growth and development
  • Access to a suite of family history and DNA testing products
Full Job Description
We are seeking a battle-tested, highly self-driven Manager, Incident Response to lead, inspire, and continuously mature our Incident Response Team. In this role, you will not just help to manage tickets, you will mentor a team of responders, threat hunters, and forensic analysts. We are looking for someone who refuses to stagnate, possessing an innate desire to constantly improve yourself, your team, and our organizational processes. You will serve as the strategic driver for our response capabilities, ensuring our organization can swiftly detect, contain, and eradicate advanced threats across a modern infrastructure. This role requires a rare blend of deep technical capability, calm-under-fire crisis management, data-driven leadership, and the empathetic guidance required to support and grow a high-performing team in a fast-paced environment. What you will do... • Team Leadership & Mentorship: Provide guidance and technical mentorship for our IR engineers. Foster a culture of psychological safety to combat security team burnout. • Incident Lifecycle Governance: Oversee end-to-end incident handling (triage, containment, forensics, eradication, and recovery) for high-impact or complex enterprise security incidents. • Operational Metrics & Reporting: Establish, track, and analyze key performance indicators (e.g., MTTD, MTTR, true/false positive ratios). Leverage this data to present compelling, risk-focused operational updates to leadership. • Crisis Management & Communication: Act as the primary coordinator during major incidents, translating complex technical findings into clear, actionable risk summaries for leadership, legal counsel, and PR. • Continuous Posture Evolution: Lead post-incident reviews (Root Cause Analysis) to transform lessons learned into tangible detections, architecture enhancements, and process improvements. • Playbook & Automation Strategy: Drive the creation and maturation of IR runbooks, leveraging automation to drastically reduce containment timelines. Who you are... • Proven People Management: 3+ years of experience directly managing and mentoring incident response professionals. • Incident Response Depth: 6+ years of hands-on experience in enterprise-scale incident response, digital forensics, and advanced blue team operations. • Continuous Improvement Mindset: A highly self-driven individual with a proven track record of proactively identifying inefficiencies and spearheading initiatives to elevate personal skillsets, team dynamics, and operational processes. • Threat Landscape Mastery: Deep understanding of modern attacker tools, tactics, and procedures (TTPs), threat actor motivations, and the mapping of detections to the MITRE ATT&CK framework. • Crisis Composure & Presence: A proven track record of maintaining strategic focus and a calm demeanor while leading cross-functional teams through high-stress incidents, paired with exceptional communication skills. • Modern AI Familiarity: Core familiarity with utilizing modern AI tools and Large Language Models (LLMs) to enhance day-to-day productivity and augment technical workflows. Core Technology Capabilities An experienced manager in our environment should have strong operational familiarity with (and past hands-on experience utilizing) the following technical domains: • Enterprise EDR / XDR Solutions: Deep familiarity with industry-standard Endpoint Detection and Response platforms for rapid containment, host isolation, and endpoint telemetry analysis. • AWS Cloud Infrastructure: Operational understanding of Amazon Web Services (AWS) core environments and native security capabilities (e.g., CloudTrail, GuardDuty, IAM, etc) to investigate cloud-native threats. • Enterprise SIEM & Centralized Logging: Experience leveraging large-scale security information and event management systems to correlate disparate data sources and track adversarial movement. • SOAR & Automation Workflows: Conceptual or practical experience utilizing Security Orchestration, Automation, and Response tools to streamline repeatable containment processes. • Digital Forensics (DFIR): Familiarity with enterprise-grade host, memory, and network forensics tools required to extract artifacts and timeline malicious activity. Preferred Qualifications & Expertise • Advanced Elasticsearch Data Analysis: Direct experience operating within or investigating out of a large-scale, Elasticsearch-driven security logging infrastructure. Proven capability with advanced search queries, data correlation, and optimizing analytics for incident investigations is highly valued. • AI-Driven Process Optimization: Experience leveraging AI utilities and workflows for security process optimization, accelerating documentation/runbook creation, or assisting in rapid development and scripting. • Industry Certifications: Advanced specialized security certifications such as GIAC (GCIH, GCFA, GNFA), CISSP, or CISM. • Adversarial Emulation: Experience organizing or participating in Purple Team exercises and tabletop simulations alongside Red Teams to validate detection engineering. • Cloud Forensics Specialization: Technical experience investigating compromises in containerized (Kubernetes/Docker) or serverless cloud environments. Helping people discover their story is at the heart of ours. Ancestry is the largest provider of family history and personal DNA testing, harnessing a powerful combination of information, science and technology to help people discover their family history and stories that were never possible before. Ancestry’s suite of products includes: AncestryDNA, AncestryProGenealogists, Fold3, Newspapers.com, Find a Grave, Archives.com, and Rootsweb. We offer excellent benefits and a competitive compensation package. For additional information, regarding our benefits and career information, please visit our website at As a signatory of the ParityPledge in Support of Women and the ParityPledge in Support of People of Color, Ancestry values pay transparency and pay equity. We are pleased to share the base salary range for this position: $132,410 - $165,510 with eligibility for bonus, equity and comprehensive benefits including health, dental and vision. The actual salary will vary by geographic region and job experience. We will share detailed compensation data for a specific location during the recruiting process. Read more about our benefits . *Note: Disclosure as required by sb19-085(8-5-20) and sb1162(1-1-23).

About Ancestry

Ancestry is a genealogy company that provides online access to historical records, family trees, and DNA testing services. The company was founded in 1983 and is headquartered in Lehi, Utah. Ancestry has a database of over 20 billion historical records and has helped millions of people discover their family history. The company offers a variety of subscription plans that provide access to different types of records and features. Ancestry also offers DNA testing services that can help people discover their ethnic origins and connect with relatives they may not have known about. Ancestry is one of the largest genealogy companies in the world.
Learn more about Ancestry
Size
1,300 employees
Industry
Founded
1983

Similar Jobs

More Jobs at Ancestry

More Information Technology Jobs

Find similar Manager, Incident Response jobs: