Information Security Incident Manager

Rippling, Inc.

United States

Remote

USD 120,000 - 140,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Nexcess is seeking an Information Security Incident Manager to lead the organization’s Security Incident Management program across infrastructure and platform operations. You will be the central coordinator during incidents, service disruptions, and high-severity events, driving response, communication, and accountability.

You will partner with Infrastructure, Platform Engineering, Security, Support, and Leadership to improve incident response maturity through post-incident reviews, IOAR

Qualifications

  • 4+ years of experience in IT, infrastructure operations, hosting operations, platform reliability, or related technical environments.
  • Bachelor’s Degree in Information Technology, Business Administration, or related field, or equivalent practical experience.
  • Proven history of Linux Incident Response & Forensics.
  • Ability to perform Advanced Log Analysis & System Auditing.
  • Ability to perform Network & Socket Triage.
  • Experience managing escalations and coordinating cross-functional technical teams.
  • Excellent written and verbal communication skills.
  • Strong organizational, analytical, and problem-solving abilities.

Responsibilities

  • Lead and coordinate operational incident response activities for infrastructure, platform, hosting, and customer-impacting events.
  • Serve as Security Incident Commander or facilitate incident coordination during high-severity operational events.
  • Ensure incident response processes are consistently followed including identification, escalation, engagement, assessment, resolution, communication, and post-mortem review.
  • Facilitate operational bridge calls, escalation management, stakeholder coordination, and incident tracking activities.
  • Monitor active incidents to ensure accountability, urgency, and proper escalation procedures are maintained.
  • Assist with after-hours escalation coordination as necessary during major operational events.
  • Contribute to IOAR meetings and post-mortem reviews.
  • Analyze incidents, outages, and trends to identify recurring failures and improvement opportunities.
  • Develop and maintain incident response documentation, procedures, escalation workflows, and governance standards.
  • Produce monthly reporting related to incidents, service disruptions, response metrics, and operational trends.
  • Partner with operational leadership to improve incident response maturity, communication standards, and accountability.
  • Communicate effectively with technical and non-technical stakeholders during high-pressure events.

Skills

Incident response
Log analysis
Network triage
Communication skills
Cross-functional coordination

Education

Bachelor’s degree or equivalent experience

Tools

Linux
Monitoring/Observability tools

Job description

Nexcess provides specialty cloud solutions for organizations where performance and compliance have to coexist. We serve businesses worldwide, from agencies scaling client sites to enterprises running mission-critical operations. We've built our reputation on deep technical expertise and genuine partnership with every client we work with. Behind every environment we manage is a team of people who take the craft seriously and keep showing up when it matters.

Overview

The Information Security Incident Manager is responsible for leading and coordinating the organization’s Security Incident Management program to ensure timely response, effective communication, operational accountability, and continuous improvement across infrastructure and platform operations. This role serves as the central coordination point during operational incidents, service disruptions, and high-severity events impacting internal systems, infrastructure, or customer environments.

The Security Incident Manager will have a hands-on role and partner closely with Infrastructure, Platform Engineering, Security Engineering, Support, Incident Management, and Leadership teams to drive incident response processes, facilitate communication, coordinate escalations, and ensure operational standards are consistently followed. This position is also responsible, along with the incident management team, for improving incident management maturity through trend analysis, post-incident review processes, reporting, and corrective action tracking.

This role requires strong organizational leadership, operational judgment, communication skills, and the ability to remain composed in high-pressure operational environments.

Compensation: The compensation range for this position is between $120k-$140k

Responsibilities
  • Lead and coordinate operational incident response activities for infrastructure, platform, hosting, and customer-impacting events
  • Serve as Security Incident Commander or facilitate incident coordination during high-severity operational events
  • Ensure incident response processes are consistently followed including identification, escalation, engagement, assessment, resolution, communication, and post-mortem review
  • Facilitate operational bridge calls, escalation management, stakeholder coordination, and incident tracking activities
  • Monitor active incidents to ensure accountability, urgency, and proper escalation procedures are maintained
  • Assist with after-hours escalation coordination as necessary during major operational events
  • Contribute to Incident Outcomes and Action Review (IOAR) meetings and post-mortem reviews
  • Analyze operational incidents, outages, and trends to identify recurring failures and improvement opportunities
  • Develop and maintain incident response documentation, operational procedures, escalation workflows, and governance standards
  • Produce monthly reporting related to incidents, service disruptions, response metrics, and operational trends
  • Partner with operational leadership to improve incident response maturity, communication standards, and organizational accountability
  • Communicate effectively with both technical and non-technical stakeholders during high-pressure operational events
  • Promote operational transparency, accountability, and process adherence across teams
  • Assist with reinforcing best practices related to incident handling, escalation management, and operational communication
  • Additional duties as assigned
Requirements
  • 4+ years of experience in Information Technology, Infrastructure Operations, Hosting Operations, Platform Reliability, or related technical environments
  • Bachelor’s Degree in Information Technology, Business Administration, or related field, or equivalent practical experience
  • Proven history of Linux Incident Response & Forensics
  • Ability to perform Advanced Log Analysis & System Auditing
  • Ability to perform Network & Socket Triage
  • Experience managing escalations and coordinating cross-functional technical teams
  • Excellent written and verbal communication skills
  • Strong organizational, analytical, and problem-solving abilities
  • Ability to manage multiple priorities and remain composed in high-pressure operational situations
  • Experience facilitating post-mortem reviews and corrective action tracking
  • Ability to exercise independent judgment during operational incidents and escalations
Preferred Qualifications
  • Experience working within hosting, cloud infrastructure, managed services, SaaS, or enterprise operations environments
  • Familiarity with monitoring, alerting, observability, and operational workflow platforms
  • Experience supporting 24x7 operational environments
  • Project Management or operational governance experience

The physical demands described here are representative of those that must be met by an individual to successfully perform the essential duties of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential duties.

  • While performing the essential duties of this job, the individual is regularly required to speak and hear
  • While performing the essential duties of this job, the individual is regularly required to use hands for keyboarding, gross manipulation, and fine manipulation
  • Works at a desk and computer screen for extended periods of time
  • Works in a traditional climate controlled office environment or from home
  • Works in a highly stressful environment dealing with a wide variety of challenges, deadlines and diverse employee population
Disclaimer

This job description is only a summary of the typical functions of the position. It is not intended to be an exhaustive or comprehensive list of all job responsibilities, tasks, or duties. Additional duties and tasks may be assigned as part of the job function. Liquid Web Inc. reserves the right to modify, interpret, or apply this job description in a way that best supports the organizational needs. The job description in no way creates or implies an employment contract. The employment contract remains "at will".

Equal Employment Opportunity Policy: Liquid Web is committed to offering equal employment opportunity without regard to age, color, disability, gender, gender identity, genetic information, marital status, military status, national origin, race, religion, sexual orientation, veteran status, or any other legally protected characteristic.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Technical Enterprise Incident Manager
Technical Enterprise Incident Manager

Peraton • Reston (VA)

On-site
USD 86,000 - 138,000
Incident Manager (Midlevel)
Incident Manager (Midlevel)

Node.Digital LLC • Arlington (VA)

On-site
USD 100,000 - 130,000
Medical
Dental
Vision
+3
Technical Enterprise Incident Manager
Technical Enterprise Incident Manager

Peraton • Linthicum (MD)

Remote
USD 120,000 - 160,000
Technical Enterprise Incident Manager
Technical Enterprise Incident Manager

Peraton • Herndon (VA)

On-site
USD 86,000 - 138,000
IT Incident Response Lead
IT Incident Response Lead

Nexlogica • Downey (CA)

On-site
USD 140,000 - 170,000
Technology Incident Manager
Technology Incident Manager

Horizontal Talent • Brooklyn (OH)

On-site
USD 69,000 - 77,000
Medical insurance
Dental insurance
Vision insurance
+1
Cybersecurity - Incident Manager - NIST, CND, Data 7/3/2026 Arlington, VA VA - ESS
Cybersecurity - Incident Manager - NIST, CND, Data 7/3/2026 Arlington, VA VA - ESS

Erias Ventures, LLC • Arlington (VA)

On-site
USD 110,000 - 145,000
Above Market Hourly Pay
11% 401k with Immediate Vesting
100% Company Paid Medical, Vision, and Dental
+1
Systems Engineer III
Systems Engineer III

NISC • Atlanta (GA)

On-site
USD 120,000 - 180,000
Night Shift Incident Manager
Night Shift Incident Manager

Computer World Services Corp. • Bethesda (MD)

On-site
USD 87,000 - 100,000
Hybrid work arrangement
On-site in Bethesda, MD
Incident Manager (Midlevel)
Incident Manager (Midlevel)

Node • United States

On-site
USD 120,000 - 180,000
Medical
Dental
Vision
+6