Head of Cyber Crisis & Critical Incident Management - USDS
Listed on 2026-09-01
-
IT/Tech
IT Project Manager, Cybersecurity, Security Management & Operations
Responsibilities
The Threat Detection and Response pillar evaluates Tik Tok's cybersecurity ecosystem to identify both internal and external threats, determining the most effective mitigation strategies. Our mission is to build a security, privacy, and trust framework that not only defends against threats but also fosters and preserves trust with users and stakeholders, including Global and USDS JV teams.
The Head of Enterprise Incident Managemenet is responsible for leading the response to high-severity enterprise and operational incidents that may affect business continuity, customer trust, regulatory obligations, or executive priorities. This role combines strong incident command, technical depth, and executive communication. The ideal candidate brings substantial experience in the technology industry, a proven record of hands‑on technical investigation and response, and the judgment to coordinate cross‑functional teams during fast‑moving, high‑stakes events.
This position partners closely with Security, Engineering, Infrastructure, Product, Legal, Compliance, Public Policy, Communications, and executive stakeholders to drive effective incident response, clear decision‑making, and continuous improvement.
Responsibilities- Manage a team that can lead end-to-end command and coordination for high‑severity enterprise incidents, including triage, escalation, stakeholder alignment, mitigation tracking, and resolution management.
- Serve as the central incident leader during complex or high‑stakes events, ensuring the right technical and business teams are engaged quickly and operating against a clear response structure.
- Work hands‑on with technical teams to investigate active incidents, analyze system behavior, review logs, validate hypotheses, identify dependencies, and support effective containment and recovery actions.
- Coordinate response activities across Engineering, Site Reliability, Security, Infrastructure, Product, Support, Legal, Compliance, Communications, and leadership teams.
- Drive high-quality executive communications during incidents, including concise status updates, decision memos, risk summaries, and post‑incident briefings.
- Prepare and deliver incident reporting for executive leadership, board‑level audiences, and government stakeholders when required, ensuring accuracy, clarity, and alignment with legal and regulatory expectations.
- Establish and maintain incident governance processes, severity frameworks, escalation paths, communications standards, and operational playbooks.
- Facilitate incident reviews and postmortems, ensuring root causes, contributing factors, lessons learned, and remediation plans are clearly documented and tracked to completion.
- Identify trends across incidents and near misses to improve resilience, readiness, observability, escalation quality, and cross‑functional response maturity.
- Improve the quality and speed of incident response by refining tooling, workflows, and metrics that support detection, coordination, reporting, and leadership visibility.
- Act as a trusted advisor during sensitive events where technical, business, regulatory, and reputational considerations must be balanced in real time.
Minimum Qualification(s):
- Bachelor’s degree or equivalent practical experience.
- Minimum 5 years experience in the technology industry, with direct exposure to production operations, enterprise platforms, infrastructure, cybersecurity, or large‑scale service environments, while leading a team.
- Demonstrated experience leading or coordinating major incident response in complex technical organizations and reporting progress to executives.
- Strong hands‑on technical experience investigating, responding to, and coordinating high‑stakes incidents, including the ability to work effectively with engineers and technical operators.
- Experience analyzing incident data such as system events, operational signals, service dependencies, logs, timelines, and recovery actions to support response leadership and decision‑making.
Preferred Qualification(s):
- Working knowledge of modern infrastructure, distributed systems, cloud environments, identity systems, networking, and security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).