yoinka

Incident Management Lead, Data Center Security

Anthropic

RemoteRemote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NYSenior$290k/yr
Sign in to applyVerified 2h ago
Location
Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY
Work model
Remote
Level
Senior
Salary
$290k/yr
Posted
2h ago

Skills

REST

About this role

About Anthropic

Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About the role

Anthropic operates and is building data center campuses around the world, run day to day through operating partners, site vendors, and contracted security services. Things go wrong at those sites the way they go wrong at any critical infrastructure: access issues, contractor incidents, protests, weather, equipment failures, and occasionally something with the potential for global impact. Today, what counts as an incident, who gets told, and how it is reported vary by site and by vendor.

As Lead for Crisis and Incident Management, you will build the program that removes that variance, and you will build it with the people who have to live with it. The first job is definition: working with operating partners, site security vendors, managed-service providers, and internal teams to agree on what counts as a minor escalation versus a major incident of global impact, the severity levels in between, the thresholds that move an event from one level to the next, and who gets told, how fast, and in what format. The second job is adoption: turning those definitions into playbooks, training, and exercises so that responders at every site and vendor actually respond the right way, and running the after-action reviews that show where they did not. The third job is measurement: defining the incident metrics, building the reporting, and giving leadership a regular, accurate picture of how response is performing across the fleet. Underneath all three sits the cross-functional work of getting partners to buy in, because a framework no partner has signed up to is a document, not a program.

Continuous coverage is part of the picture. As the program matures, you will shape a 24/7 monitoring and response capability through GSOC-type managed services and site vendors, so that the framework holds at three in the morning at any site in the fleet. That build-out follows from the definitions and partner agreements above rather than replacing them. When a major incident does happen, you run it: activation, coordination, leadership communication, stand-down, and the after-action review that makes the program better.

This is a program-building role, not a shift-supervision role. The deliverable is a framework that partners have adopted, that works at any site, and that reports on itself, run largely through vendors and managed services rather than a large in-house team. Where existing processes and vendor arrangements don't support that, you will have the authority, and the expectation, to change them.

Role boundaries. This seat is distinct from the Data Center Security Delivery Lead (who owns security through construction, commissioning, and handover on new builds), from regional security operations leads (who own steady-state regional programs and vendor relationships site by site), and from the team's systems-engineering roles (who build platforms and tooling). This role owns the horizontal incident and crisis layer across the operating fleet: the incident definitions and severity framework, partner adoption and governance, incident reporting and metrics, major incident command, post-incident review, and, as it develops, the 24/7 coverage model, applied consistently across every site and vendor.

Key responsibilities

You will build and own the global crisis and incident management program for data center physical security.

• Incident definition and severity framework: define, with partners, what counts as an incident and the tiers from

Listing verified 2h ago. Applications go through the company's official careers site.

← Back to Yoinka

Incident Management Lead, Data Center Security at Anthropic, Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY | Yoinka