Incident Response Manager, Security Operations Group | Worldwide Operations Security

Amazon Inc.

Greater London

Remote

GBP 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Amazon is seeking an Incident Response Manager for the Security Operations Group, Worldwide Operations Security. You will lead end-to-end response to SEV1/SEV2 incidents, own on-call rotations, and coordinate cross-functional efforts to protect life safety, continuity, and brand.

You will drive real-time actions across GSOC and IMTs and deliver post-incident reviews. The role requires senior-level incident management experience, strong stakeholder communication, and the ability to operate across

Qualifications

  • Bachelor’s degree or equivalent in Risk Management, Business Administration, Security Management, or a related field
  • Experience applying KPIs to analyses or building financial/operational reports to inform decisions
  • Experience building cross-functional partnerships and influencing stakeholders without direct reporting lines
  • Advanced knowledge of Microsoft Office products
  • Ability to prioritize multiple assignments and manage end-to-end projects
  • Strong written and verbal communication to executives and non-technical leaders
  • Experience in high-volume environments such as security operations or crisis management

Responsibilities

  • Lead end-to-end coordination of high severity incidents (SEV1/SEV2) from notification through mitigation and closure
  • Own 24/7/365 on-call rotation and respond to threats within the CTI Matrix per escalation procedures
  • Coordinate Immediate Mitigation calls with site Incident Commanders and IMTs
  • Execute tactical response protocols including video lockdown and OSINT analysis
  • Prepare site risk overviews and incident summaries to WWOS senior leadership within 4 hours
  • Manage Incident Room operations with real-time updates and stakeholder calls
  • Lead After Action Reviews within 3 days of incident conclusion
  • Maintain and validate high severity protocols, escalation workflows and timelines
  • Partner with GSOC, Regional S&LP, Operations, WHS, and PXT to influence decisions and IMT readiness

Skills

KPI analysis
Cross-functional partnerships
Executive communication
Project management
High-volume incident handling

Education

Bachelor’s degree in Risk Management / Security / Business Admin
Master’s degree in risk management / security (preferred)

Tools

Microsoft Office

Job description

Incident Response Manager, Security Operations Group | Worldwide Operations Security

Job ID: 10504661 | Amazon UK Services Ltd.

This position can be based from any EMEA Corporate Location or current site (pending site lead, PXT and Hiring manager approval).

Key job responsibilities
  • Lead end-to-end coordination of high severity incidents (SEV1/SEV2), managing the full lifecycle from initial notification through mitigation, stabilization, and closure
  • Own 24/7/365 on-call rotation, responding to threats and incidents within the CTI Matrix per SOG escalation procedures, including Slack channel activation and senior leadership notification
  • Coordinate Immediate Mitigation calls with site-level Incident Commanders and IMTs, assigning action items to ensure life safety, operational continuity, and brand protection
  • Execute tactical response protocols including video lockdown, ESU/Off-Duty deployments, and OSINT/SOCMINT analysis within established timelines
  • Prepare site risk overviews and deliver incident summaries to WWOS senior leadership within 4 hours of incident onset
  • Manage Incident Room operations including real-time updates, dynamic action tracking, EMT notifications, and stakeholder conference calls
  • Lead After Action Reviews within 3 days of incident conclusion, driving corrective actions and mechanism implementation to prevent recurrence
  • Maintain and validate high severity protocols, the CTI Matrix, escalation workflows, and response timelines through continuous improvement
  • Partner with GSOC, Regional S&LP, Operations, WHS, and PXT to influence decision-making and ensure site-level IMT readiness per WWOS Critical Incident Response standards
A day in the life

As an Incident Response Manager, your day begins by reviewing active Incident Rooms, monitoring the GSOC threat landscape, and independently assessing emerging threats against the Category, Type, and Item (CTI) matrix to determine escalation requirements. You drive strategic and tactical work simultaneously, supporting Immediate Mitigation (IM) calls with site-level Incident Commanders and IMTs, and leading real-time response actions.

Throughout the week, you engage senior stakeholders across WWOS, Ops, PXT, ER, WHS, and Ops Disruption leadership, supporting GSOC Conference Calls and guiding decision‑making during critical incidents. You own On‑Call rotation responsibilities, responding to emerging threats with direct mitigation support including coordinating ESU/Off‑Duty deployments, conducting OSINT/SOCMINT analysis, and delivering initial incident summaries to WWOS senior leadership within established SLAs. When high severity events arise, you exercise independent judgment to create site‑specific Slack channels, manage video lockdown tickets, prepare site risk overviews and hardening posture assessments, and lead After Action Reviews (AARs) within 3 days of incident conclusion.

About the team

The Operational Incident Response (OIR) team sits within the Security Operations Group (SOG) under Worldwide Operations Security (WWOS). The team provides 24/7/365 critical incident coordination across WWAS operations, serving as the central point for real‑time response to life safety events, operational disruptions, natural disasters, workplace violence, and facility security threats. Working through the GSOC, the team brings together key stakeholders, manages Incident Rooms, and drives resolution from first notification through post‑incident review.

OIR members are senior individual contributors who independently own the full incident lifecycle. They coordinate Immediate Mitigation calls with site‑level Incident Commanders and IMTs, facilitate GSOC Conference Calls for SEV1 events, and deliver incident summaries to WWOS senior leadership. Key partnerships include GSOC, Regional S&LP, Operations leadership, Legal, and cross‑functional business continuity stakeholders across highly diversified global environments.

The team operates as a service to the business, ensuring continuation of operations through risk oversight, contingency planning, and structured response. This role requires independent judgment under pressure, real‑time coordination across multiple time zones, and the ability to influence senior leadership during unfolding events where life safety is at stake.

Basic Qualifications
  • Bachelor's degree or equivalent in Risk Management, Business Administration, Security Management, or a related field
  • Experience applying key financial performance indicators (KPIs) to analyses, or experience in building financial and operational reports/data sets that inform business decision‑making
  • Experience building cross‑functional partnerships and influencing stakeholders across the organization to act without having a direct reporting relationship
  • Knowledge of Microsoft Office products and applications at an advanced level
  • Experience prioritizing and handling multiple assignments at any given time while maintaining commitment to deadlines, or experience with end‑to‑end project management
  • Experience in written and verbal communication with the ability to present complex technical information in a clear and concise manner to executives and non‑technical leaders
  • Experience in a high‑volume environment, such as a security operations center, event security, call center, or crisis management/emergency response center
Preferred Qualifications
  • Experience working in a fast‑paced and ambiguous environment, or experience delivering results for large, cross‑functional initiatives/projects
  • Master's degree in risk management, Security, Business Administration, or related field
  • A security/risk management industry certification (ASIS CPP, CRMP, CBCP, or equivalent)
  • Advanced experience with risk, business continuity, and data management platforms (BSI, Audit Board, etc.)
  • Direct user experience with geo‑spatial tools and platforms (ArcGIS, ESRI, Palantir, etc.)

Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( https://www.amazon.jobs/en/privacy_page ) to know more about how we collect, use and transfer the personal data of our candidates.

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Veterans, military spouses, and people with disabilities are encouraged to apply.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Response Manager, Security Operations Group | Worldwide Operations Security
Incident Response Manager, Security Operations Group | Worldwide Operations Security

Amazon • City Of London

Remote
GBP 85,000 - 120,000
Incident Response Manager, Security Operations Group | Worldwide Operations Security
Incident Response Manager, Security Operations Group | Worldwide Operations Security

Amazon • Greater London

Remote
GBP 90,000 - 130,000
Incident Response Manager, Security Operations Group | Worldwide Operations Security
Incident Response Manager, Security Operations Group | Worldwide Operations Security

Amazon.com, Inc • City of Westminster

On-site
GBP 90,000 - 150,000
Risk Manager, High Severity Intelligence
Risk Manager, High Severity Intelligence

Amazon • Greater London

On-site
GBP 90,000 - 120,000
Security Engineering Manager - Incident Response, AWS CloudOps
Security Engineering Manager - Incident Response, AWS CloudOps

Amazon Web Services (AWS) • Greater London

On-site
GBP 150,000 - 210,000
Security Engineering Manager - Incident Response, AWS CloudOps
Security Engineering Manager - Incident Response, AWS CloudOps

Amazon • City Of London

On-site
GBP 120,000 - 180,000
Risk Manager, High Severity Intelligence
Risk Manager, High Severity Intelligence

Amazon • City Of London

On-site
GBP 70,000 - 110,000
Physical SOC Analyst, Strategic Security Design and Operations (SSDO)
Physical SOC Analyst, Strategic Security Design and Operations (SSDO)

Amazon Web Services (AWS) • Greater London

On-site
GBP 40,000 - 60,000
Inclusive work culture
Career growth opportunities
Work-life balance initiatives
Security Engineering Manager - Incident Response, AWS CloudOps
Security Engineering Manager - Incident Response, AWS CloudOps

Amazon.com, Inc • City of Westminster

On-site
GBP 150,000 - 190,000
Security Engineer I, AWS Security Incident Response
Security Engineer I, AWS Security Incident Response

Amazon Inc. • Manchester

On-site
GBP 60,000 - 85,000