SlipstreamJobsFresh Startup & VC-Backed Jobs

Incident Management Lead, Data Center Security

Anthropic - San Francisco, CA, United States - Hybrid - posted 2026-08-27

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Anthropic is building a global crisis and incident management program for its data center physical security operations. As Incident Management Lead, you will design and own the horizontal incident framework applied consistently across Anthropic's operating fleet worldwide. The role has three core pillars. First, you will define what constitutes an incident and establish a severity framework with clear thresholds, escalation criteria, and notification requirements—from minor site escalations to incidents of global impact. This foundational work involves close collaboration with operating partners, site security vendors, managed-service providers, and internal teams to ensure shared ownership and buy-in. Second, you will drive adoption of the framework through playbooks, training, tabletop exercises, and functional drills across all sites and vendors. You'll run after-action reviews to identify gaps and continuously improve response readiness. Third, you will establish metrics and reporting that measure whether definitions are being applied correctly and whether response performance is improving. You'll own executive reporting cadences, from real-time incident notification through leadership escalation and formal summaries. As the program matures, you will shape a 24/7 monitoring and response capability through GSOC-type managed services and site vendors, ensuring the framework holds consistently across time zones and geographies. When major incidents occur, you run the crisis process: activation, cross-site coordination, decision support to leadership, and formal stand-down. This is a program-building role focused on creating a scalable, vendor-led framework rather than building a large in-house team. You will have the authority and expectation to change existing processes and vendor arrangements where they don't support the program. The role is distinct from regional security operations leads, construction/commissioning leads, and systems-engineering roles—you own the horizontal incident and crisis layer across the entire operating fleet.

Similar roles