Hiring.Camp

Manager, Incident Response

Ancestry

·

Yesterday

Salary
$132k – $166k
Location
Draper, Utah, United States of America
Workplace
Hybrid
Type
Full-time
Seniority
Manager
Experience
3+ years
Source
Workday

Description

About Ancestry:


When you join Ancestry, you join a human-centered company where every person’s story is important. Ancestry®, the global leader in family history, connects everyone with their past so they can discover, preserve, and share their unique family stories. With our unparalleled collection of more than 65 billion records, over 3.5 million subscribers, and over 27 million people in our growing DNA network, customers can discover their family story and gain a new level of understanding about their lives. Over the past 40 years, we’ve built trusted relationships with millions of people who have chosen us as the platform for discovering, preserving, and sharing the most important information about themselves and their families.

We are committed to our location flexible work approach, allowing you to choose to work in the nearest office, from your home, or a hybrid of both (subject to location restrictions and roles that are required to be in the office- see the full list of eligible US locations
HERE). We will continue to hire and promote beyond the boundaries of our office locations, to enable broadened possibilities for employee diversity.

Together, we work every day to foster a work environment that's inclusive as well as diverse, and where our people can be themselves. Every idea and perspective is valued so that our products and services reflect the global and diverse clients we serve. 

Ancestry encourages applications from minorities, women, the disabled, protected veterans and all other qualified applicants. Passionate about dedicating your work to enriching people’s lives? Join the curious.

We are seeking a battle-tested, highly self-driven Manager, Incident Response to lead, inspire, and continuously mature our Incident Response Team. In this role, you will not just help to manage tickets, you will mentor a team of responders, threat hunters, and forensic analysts. We are looking for someone who refuses to stagnate, possessing an innate desire to constantly improve yourself, your team, and our organizational processes. You will serve as the strategic driver for our response capabilities, ensuring our organization can swiftly detect, contain, and eradicate advanced threats across a modern infrastructure.

This role requires a rare blend of deep technical capability, calm-under-fire crisis management, data-driven leadership, and the empathetic guidance required to support and grow a high-performing team in a fast-paced environment.

What you will do...

  • Team Leadership & Mentorship: Provide guidance and technical mentorship for our IR engineers. Foster a culture of psychological safety to combat security team burnout.

  • Incident Lifecycle Governance: Oversee end-to-end incident handling (triage, containment, forensics, eradication, and recovery) for high-impact or complex enterprise security incidents.

  • Operational Metrics & Reporting: Establish, track, and analyze key performance indicators (e.g., MTTD, MTTR, true/false positive ratios). Leverage this data to present compelling, risk-focused operational updates to leadership.

  • Crisis Management & Communication: Act as the primary coordinator during major incidents, translating complex technical findings into clear, actionable risk summaries for leadership, legal counsel, and PR.

  • Continuous Posture Evolution: Lead post-incident reviews (Root Cause Analysis) to transform lessons learned into tangible detections, architecture enhancements, and process improvements.

  • Playbook & Automation Strategy: Drive the creation and maturation of IR runbooks, leveraging automation to drastically reduce containment timelines.

Who you are...

  • Proven People Management: 3+ years of experience directly managing and mentoring incident response professionals.

  • Incident Response Depth: 6+ years of hands-on experience in enterprise-scale incident response, digital forensics, and advanced blue team operations.

  • Continuous Improvement Mindset: A highly self-driven individual with a proven track record of proactively identifying inefficiencies and spearheading initiatives to elevate personal skillsets, team dynamics, and operational processes.

  • Threat Landscape Mastery: Deep understanding of modern attacker tools, tactics, and procedures (TTPs), threat actor motivations, and the mapping of detections to the MITRE ATT&CK framework.

  • Crisis Composure & Presence: A proven track record of maintaining strategic focus and a calm demeanor while leading cross-functional teams through high-stress incidents, paired with exceptional communication skills.

  • Modern AI Familiarity: Core familiarity with utilizing modern AI tools and Large Language Models (LLMs) to enhance day-to-day productivity and augment technical workflows.

Core Technology Capabilities

An experienced manager in our environment should have strong operational familiarity with (and past hands-on experience utilizing) the following technical domains:

  • Enterprise EDR / XDR Solutions: Deep familiarity with industry-standard Endpoint Detection and Response platforms for rapid containment, host isolation, and endpoint telemetry analysis.

  • AWS Cloud Infrastructure: Operational understanding of Amazon Web Services (AWS) core environments and native security capabilities (e.g., CloudTrail, GuardDuty, IAM, etc) to investigate cloud-native threats.

  • Enterprise SIEM & Centralized Logging: Experience leveraging large-scale security information and event management systems to correlate disparate data sources and track adversarial movement.

  • SOAR & Automation Workflows: Conceptual or practical experience utilizing Security Orchestration, Automation, and Response tools to streamline repeatable containment processes.

  • Digital Forensics (DFIR): Familiarity with enterprise-grade host, memory, and network forensics tools required to extract artifacts and timeline malicious activity.

Preferred Qualifications & Expertise

  • Advanced Elasticsearch Data Analysis: Direct experience operating within or investigating out of a large-scale, Elasticsearch-driven security logging infrastructure. Proven capability with advanced search queries, data correlation, and optimizing analytics for incident investigations is highly valued.

  • AI-Driven Process Optimization: Experience leveraging AI utilities and workflows for security process optimization, accelerating documentation/runbook creation, or assisting in rapid development and scripting.

  • Industry Certifications: Advanced specialized security certifications such as GIAC (GCIH, GCFA, GNFA), CISSP, or CISM.

  • Adversarial Emulation: Experience organizing or participating in Purple Team exercises and tabletop simulations alongside Red Teams to validate detection engineering.

  • Cloud Forensics Specialization: Technical experience investigating compromises in containerized (Kubernetes/Docker) or serverless cloud environments.

Helping people discover their story is at the heart of ours. Ancestry is the largest provider of family history and personal DNA testing, harnessing a powerful combination of information, science and technology to help people discover their family history and stories that were never possible before. Ancestry’s suite of products includes: AncestryDNA, AncestryProGenealogists, Fold3, Newspapers.com, Find a Grave, Archives.com, and Rootsweb. We offer excellent benefits and a competitive compensation package. For additional information, regarding our benefits and career information, please visit our website at http://ancestry.com/careers

As a signatory of the ParityPledge in Support of Women and the ParityPledge in Support of People of Color, Ancestry values pay transparency and pay equity. We are pleased to share the base salary range for this position: $132,410 - $165,510 with eligibility for bonus, equity and comprehensive benefits including health, dental and vision. The actual salary will vary by geographic region and job experience. We will share detailed compensation data for a specific location during the recruiting process. Read more about our benefits HERE.

*Note: Disclosure as required by sb19-085(8-5-20) and sb1162(1-1-23).

Additional Information:

Ancestry is an Equal Opportunity Employer that makes employment decisions without regard to race, color, religious creed, national origin, ancestry, sex, pregnancy, sexual orientation, gender, gender identity, gender expression, age, mental or physical disability, medical condition, military or veteran status, citizenship, marital status, genetic information, or any other characteristic protected by applicable law. In addition, Ancestry will provide reasonable accommodations for qualified individuals with disabilities.

All job offers are contingent on a background check screen that complies with applicable law. For candidates who live in San Francisco, CA, pursuant to the San Francisco Fair Chance Ordinance, Ancestry will consider for employment qualified applicants with arrest and conviction records.

  

Ancestry is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at Ancestry via-email, the Internet or in any form and/or method without a valid written search agreement in place for this position will be deemed the sole property of Ancestry. No fee will be paid in the event the candidate is hired by Ancestry as a result of the referral or through other means.

Skills

AWSDockerKubernetesElasticsearchSIEMCISSP

Similar Jobs

30

Manager, Incident Response

Pondurance · McLean, VA · Remote

1 week ago

Manager, Incident Response

NBCUniversal · New York, NEW YORK, United States · Remote

1 week ago

Manager, Incident Response

Fluidstack · San Francisco, CA +1 · Onsite

1 month ago

Incident Response Manager

Crowe Careers · Sarasota, United States of America +4

1 month ago

Incident Response Manager

Depository Trust Company · Chennai, India

3 months ago

Incident Response Manager

Depository Trust Company · Manila, Philippines · Remote, Hybrid, Onsite

7 months ago

Incident Response Manager

Speedcast is · Australia - Tasmania

1+ year ago

Incident Response Manager, Security Operations Group | Worldwide Operations Security

Amazon

1 week ago

Product Security Incident Response Manager (m/f/d)

Job Listings · Glasgow, United Kingdom +1

2 weeks ago

Sr. Service Delivery Manager (Incident Response)

Trendmicro · Tokyo, Japan

2 weeks ago

Technical Program Manager, Incident Response

Harvey · San Francisco · Hybrid

1 month ago

Technical Program Manager, Incident Response

Harvey · New York · Hybrid

1 month ago

Disaster Recovery and Major Incident Response Manager

HSS - Hospital for Special Surgery · HSS 777, United States of America · Hybrid

1 month ago

Cybersecurity, Privacy and Forensics - Cyber Incident Response - Manager

Pwc · Austin - 835 West 6th Street, United States of America +6

1 month ago

Incident Response Manager & Lead Threat Hunter

Bullhorn · Remote NOAM - Massachusetts, United States of America · Remote

2 months ago

Senior Incident Response Manager, Public Safety

Axon · New York, New York, United States

2 months ago

Senior Cyber Defense Manager - Incident Response

Boyd Gaming · Las Vegas, United States

3 months ago

Incident Response Manager - Product & Engineering

Anthropic · New York City, NY; San Francisco, CA | New York City, NY; Seattle, WA +1 · Onsite

3 months ago

Product Security Incident Response Manager (m/f/d)

Job Listings · Gratkorn, Austria +3

3 months ago

Project Manager (Incident Response)

MOXFIVE · Remote · Remote

5 months ago

Senior Manager, Incident Response

Sophos · Japan · Remote

6 months ago

Cyber Incident Response Manager

Bbh · Boston, United States of America +1

9 months ago

Security Operations Center and Incident Response Manager

Pwc · Makati - 29th Floor Philamlife Tower, Philippines

1+ year ago

Security Operations Center and Incident Response Manager

Pwc · Makati - 29th Floor Philamlife Tower, Philippines

1+ year ago

Cybersecurity Program Manager (PgM) & Incident Response (IR) Lead

ShorePoint · Albuquerque, New Mexico

2 days ago

Manager, Security Incident Response

hubinternational · Chicago - IL - 200 N. La Salle St - Suite 1700, United States of America · Hybrid

5 days ago

Digital Forensics and Incident Response, Senior Manager

Booz Allen Hamilton · USA, DC, Washington (1201 I St NW), United States of America

1 week ago

Cyber Security Incident Response - Assistant Manager

LON3 London - 51 Lime Street · Madrid, Comunidad de Madrid, Spain, ES

1 month ago

Senior Manager, Cyber Incident Response Team

Adobe · Lehi, United States of America +2

2 months ago

US Cyber Monitoring & Incident Response Team Manager

Depository Trust Company · Tampa, FL, United States, US

3 months ago