Manager, Incident Response

Posted Yesterday
Be an Early Applicant
Draper, UT, USA
Hybrid
132K-166K Annually
Senior level
Artificial Intelligence • Big Data • Information Technology • Other • Software • Database • Biotech
Ancestry is the global leader in family history and consumer genomics.
The Role
Lead and mature an Incident Response team: manage end-to-end incident lifecycle (triage, containment, forensics, eradication, recovery), mentor responders, drive playbooks and automation, run post-incident reviews, report KPIs to leadership, and coordinate crisis communications with legal and PR.
Summary Generated by Built In

About Ancestry:


When you join Ancestry, you join a human-centered company where every person’s story is important. Ancestry®, the global leader in family history, connects everyone with their past so they can discover, preserve, and share their unique family stories. With our unparalleled collection of more than 65 billion records, over 3.5 million subscribers, and over 27 million people in our growing DNA network, customers can discover their family story and gain a new level of understanding about their lives. Over the past 40 years, we’ve built trusted relationships with millions of people who have chosen us as the platform for discovering, preserving, and sharing the most important information about themselves and their families.
We are committed to our location flexible work approach, allowing you to choose to work in the nearest office, from your home, or a hybrid of both (subject to location restrictions and roles that are required to be in the office- see the full list of eligible US locations
HERE). We will continue to hire and promote beyond the boundaries of our office locations, to enable broadened possibilities for employee diversity.
Together, we work every day to foster a work environment that's inclusive as well as diverse, and where our people can be themselves. Every idea and perspective is valued so that our products and services reflect the global and diverse clients we serve. 
Ancestry encourages applications from minorities, women, the disabled, protected veterans and all other qualified applicants. Passionate about dedicating your work to enriching people’s lives? Join the curious.

We are seeking a battle-tested, highly self-driven Manager, Incident Response to lead, inspire, and continuously mature our Incident Response Team. In this role, you will not just help to manage tickets, you will mentor a team of responders, threat hunters, and forensic analysts. We are looking for someone who refuses to stagnate, possessing an innate desire to constantly improve yourself, your team, and our organizational processes. You will serve as the strategic driver for our response capabilities, ensuring our organization can swiftly detect, contain, and eradicate advanced threats across a modern infrastructure.

This role requires a rare blend of deep technical capability, calm-under-fire crisis management, data-driven leadership, and the empathetic guidance required to support and grow a high-performing team in a fast-paced environment.

What you will do...

  • Team Leadership & Mentorship: Provide guidance and technical mentorship for our IR engineers. Foster a culture of psychological safety to combat security team burnout.

  • Incident Lifecycle Governance: Oversee end-to-end incident handling (triage, containment, forensics, eradication, and recovery) for high-impact or complex enterprise security incidents.

  • Operational Metrics & Reporting: Establish, track, and analyze key performance indicators (e.g., MTTD, MTTR, true/false positive ratios). Leverage this data to present compelling, risk-focused operational updates to leadership.

  • Crisis Management & Communication: Act as the primary coordinator during major incidents, translating complex technical findings into clear, actionable risk summaries for leadership, legal counsel, and PR.

  • Continuous Posture Evolution: Lead post-incident reviews (Root Cause Analysis) to transform lessons learned into tangible detections, architecture enhancements, and process improvements.

  • Playbook & Automation Strategy: Drive the creation and maturation of IR runbooks, leveraging automation to drastically reduce containment timelines.

Who you are...

  • Proven People Management: 3+ years of experience directly managing and mentoring incident response professionals.

  • Incident Response Depth: 6+ years of hands-on experience in enterprise-scale incident response, digital forensics, and advanced blue team operations.

  • Continuous Improvement Mindset: A highly self-driven individual with a proven track record of proactively identifying inefficiencies and spearheading initiatives to elevate personal skillsets, team dynamics, and operational processes.

  • Threat Landscape Mastery: Deep understanding of modern attacker tools, tactics, and procedures (TTPs), threat actor motivations, and the mapping of detections to the MITRE ATT&CK framework.

  • Crisis Composure & Presence: A proven track record of maintaining strategic focus and a calm demeanor while leading cross-functional teams through high-stress incidents, paired with exceptional communication skills.

  • Modern AI Familiarity: Core familiarity with utilizing modern AI tools and Large Language Models (LLMs) to enhance day-to-day productivity and augment technical workflows.

Core Technology Capabilities

An experienced manager in our environment should have strong operational familiarity with (and past hands-on experience utilizing) the following technical domains:

  • Enterprise EDR / XDR Solutions: Deep familiarity with industry-standard Endpoint Detection and Response platforms for rapid containment, host isolation, and endpoint telemetry analysis.

  • AWS Cloud Infrastructure: Operational understanding of Amazon Web Services (AWS) core environments and native security capabilities (e.g., CloudTrail, GuardDuty, IAM, etc) to investigate cloud-native threats.

  • Enterprise SIEM & Centralized Logging: Experience leveraging large-scale security information and event management systems to correlate disparate data sources and track adversarial movement.

  • SOAR & Automation Workflows: Conceptual or practical experience utilizing Security Orchestration, Automation, and Response tools to streamline repeatable containment processes.

  • Digital Forensics (DFIR): Familiarity with enterprise-grade host, memory, and network forensics tools required to extract artifacts and timeline malicious activity.

Preferred Qualifications & Expertise

  • Advanced Elasticsearch Data Analysis: Direct experience operating within or investigating out of a large-scale, Elasticsearch-driven security logging infrastructure. Proven capability with advanced search queries, data correlation, and optimizing analytics for incident investigations is highly valued.

  • AI-Driven Process Optimization: Experience leveraging AI utilities and workflows for security process optimization, accelerating documentation/runbook creation, or assisting in rapid development and scripting.

  • Industry Certifications: Advanced specialized security certifications such as GIAC (GCIH, GCFA, GNFA), CISSP, or CISM.

  • Adversarial Emulation: Experience organizing or participating in Purple Team exercises and tabletop simulations alongside Red Teams to validate detection engineering.

  • Cloud Forensics Specialization: Technical experience investigating compromises in containerized (Kubernetes/Docker) or serverless cloud environments.

Helping people discover their story is at the heart of ours. Ancestry is the largest provider of family history and personal DNA testing, harnessing a powerful combination of information, science and technology to help people discover their family history and stories that were never possible before. Ancestry’s suite of products includes: AncestryDNA, AncestryProGenealogists, Fold3, Newspapers.com, Find a Grave, Archives.com, and Rootsweb. We offer excellent benefits and a competitive compensation package. For additional information, regarding our benefits and career information, please visit our website at http://ancestry.com/careers

As a signatory of the ParityPledge in Support of Women and the ParityPledge in Support of People of Color, Ancestry values pay transparency and pay equity. We are pleased to share the base salary range for this position: $132,410 - $165,510 with eligibility for bonus, equity and comprehensive benefits including health, dental and vision. The actual salary will vary by geographic region and job experience. We will share detailed compensation data for a specific location during the recruiting process. Read more about our benefits HERE.

*Note: Disclosure as required by sb19-085(8-5-20) and sb1162(1-1-23).

Additional Information:

Ancestry is an Equal Opportunity Employer that makes employment decisions without regard to race, color, religious creed, national origin, ancestry, sex, pregnancy, sexual orientation, gender, gender identity, gender expression, age, mental or physical disability, medical condition, military or veteran status, citizenship, marital status, genetic information, or any other characteristic protected by applicable law. In addition, Ancestry will provide reasonable accommodations for qualified individuals with disabilities.

All job offers are contingent on a background check screen that complies with applicable law. For candidates who live in San Francisco, CA, pursuant to the San Francisco Fair Chance Ordinance, Ancestry will consider for employment qualified applicants with arrest and conviction records.

  

Ancestry is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at Ancestry via-email, the Internet or in any form and/or method without a valid written search agreement in place for this position will be deemed the sole property of Ancestry. No fee will be paid in the event the candidate is hired by Ancestry as a result of the referral or through other means.

Skills Required

  • 3+ years directly managing and mentoring incident response professionals
  • 6+ years hands-on enterprise incident response, digital forensics, and blue team operations
  • Operational familiarity with enterprise EDR/XDR platforms (endpoint containment, host isolation, telemetry)
  • Operational understanding of AWS security services (CloudTrail, GuardDuty, IAM) for cloud investigations
  • Experience leveraging enterprise SIEM and centralized logging for event correlation and threat tracking
  • Conceptual or practical experience with SOAR and automation workflows for IR playbooks
  • Familiarity with digital forensics tools for host, memory, and network forensics
  • Deep understanding of attacker TTPs and mapping detections to the MITRE ATT&CK framework
  • Proven crisis management, cross-functional coordination, and clear executive-level communication during major incidents
  • Core familiarity with modern AI tools and LLMs to augment security workflows
  • Advanced Elasticsearch data analysis experience (preferred for large-scale logging infrastructures)
  • Experience leveraging AI-driven process optimization for security workflows (preferred)
  • Industry certifications such as GIAC (GCIH, GCFA, GNFA), CISSP, or CISM (preferred)
  • Experience with purple team exercises, tabletop simulations, or adversarial emulation (preferred)
  • Cloud forensics experience in containerized (Kubernetes/Docker) or serverless environments (preferred)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Lehi, UT
1,300 Employees
Year Founded: 1983

What We Do

Ancestry is the global leader in family history and consumer genomics. Every day, around the world, we help curious people like you embark on journeys of personal discovery to enrich lives. With our unparalleled collection of more than 40 billion records from more than 80 countries and 23+ million people in our growing DNA network, Ancestry helps customers discover their family story and gain a new level of understanding about their lives. For 40 years, we’ve built trusted relationships with millions of people who have chosen us as the platform for discovering, preserving and sharing their story.

Why Work With Us

When you join Ancestry, you join a human-centered company where every person’s story is important. We believe that by discovering the struggles and triumphs of our past, we can foster deeper bonds and more meaningful connections among families and communities.

Gallery

Gallery

Similar Jobs

IMC Trading Logo IMC Trading

ISCA 2026

Fintech • Machine Learning • Software • Financial Services
Remote or Hybrid
United States
1954 Employees

Imprivata Logo Imprivata

Customer Success Manager

Healthtech • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
1372 Employees
135K-154K Annually

Imprivata Logo Imprivata

Vice President, Mid-Enterprise Healthcare Sales

Healthtech • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
1372 Employees
420K-480K Annually

SoFi Logo SoFi

Senior Operations & Supplier Testing Analyst

Fintech • Mobile • Software • Financial Services
Easy Apply
Hybrid
2 Locations
4500 Employees
99K-124K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account