Manager, Incident Response

AncestryDraper, UT
$132,410 - $165,510Hybrid

About The Position

Ancestry is seeking a battle-tested, highly self-driven Manager, Incident Response to lead, inspire, and continuously mature our Incident Response Team. In this role, you will not just help to manage tickets, you will mentor a team of responders, threat hunters, and forensic analysts. We are looking for someone who refuses to stagnate, possessing an innate desire to constantly improve yourself, your team, and our organizational processes. You will serve as the strategic driver for our response capabilities, ensuring our organization can swiftly detect, contain, and eradicate advanced threats across a modern infrastructure. This role requires a rare blend of deep technical capability, calm-under-fire crisis management, data-driven leadership, and the empathetic guidance required to support and grow a high-performing team in a fast-paced environment.

Requirements

  • 3+ years of experience directly managing and mentoring incident response professionals.
  • 6+ years of hands-on experience in enterprise-scale incident response, digital forensics, and advanced blue team operations.
  • A highly self-driven individual with a proven track record of proactively identifying inefficiencies and spearheading initiatives to elevate personal skillsets, team dynamics, and operational processes.
  • Deep understanding of modern attacker tools, tactics, and procedures (TTPs), threat actor motivations, and the mapping of detections to the MITRE ATT&CK framework.
  • A proven track record of maintaining strategic focus and a calm demeanor while leading cross-functional teams through high-stress incidents, paired with exceptional communication skills.
  • Core familiarity with utilizing modern AI tools and Large Language Models (LLMs) to enhance day-to-day productivity and augment technical workflows.
  • Deep familiarity with industry-standard Endpoint Detection and Response platforms for rapid containment, host isolation, and endpoint telemetry analysis.
  • Operational understanding of Amazon Web Services (AWS) core environments and native security capabilities (e.g., CloudTrail, GuardDuty, IAM, etc) to investigate cloud-native threats.
  • Experience leveraging large-scale security information and event management systems to correlate disparate data sources and track adversarial movement.
  • Conceptual or practical experience utilizing Security Orchestration, Automation, and Response tools to streamline repeatable containment processes.
  • Familiarity with enterprise-grade host, memory, and network forensics tools required to extract artifacts and timeline malicious activity.

Nice To Haves

  • Direct experience operating within or investigating out of a large-scale, Elasticsearch-driven security logging infrastructure.
  • Proven capability with advanced search queries, data correlation, and optimizing analytics for incident investigations is highly valued.
  • Experience leveraging AI utilities and workflows for security process optimization, accelerating documentation/runbook creation, or assisting in rapid development and scripting.
  • Advanced specialized security certifications such as GIAC (GCIH, GCFA, GNFA), CISSP, or CISM.
  • Experience organizing or participating in Purple Team exercises and tabletop simulations alongside Red Teams to validate detection engineering.
  • Technical experience investigating compromises in containerized (Kubernetes/Docker) or serverless cloud environments.

Responsibilities

  • Provide guidance and technical mentorship for our IR engineers.
  • Foster a culture of psychological safety to combat security team burnout.
  • Oversee end-to-end incident handling (triage, containment, forensics, eradication, and recovery) for high-impact or complex enterprise security incidents.
  • Establish, track, and analyze key performance indicators (e.g., MTTD, MTTR, true/false positive ratios).
  • Leverage this data to present compelling, risk-focused operational updates to leadership.
  • Act as the primary coordinator during major incidents, translating complex technical findings into clear, actionable risk summaries for leadership, legal counsel, and PR.
  • Lead post-incident reviews (Root Cause Analysis) to transform lessons learned into tangible detections, architecture enhancements, and process improvements.
  • Drive the creation and maturation of IR runbooks, leveraging automation to drastically reduce containment timelines.

Benefits

  • health, dental and vision
  • bonus
  • equity
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service