Senior Engineering Manager – Incident Response
Listed on 2026-08-22
-
IT/Tech
Security Management & Operations, Cybersecurity
Senior Engineering Manager – Incident Response
Security | Remote, Americas | San Francisco, United States | Austin, United States | New York, United States | Washington DC, United States | Seattle, United States |
Atlassians can choose where they work – whether in an office, from home, or a combination of the two. That way, Atlassians have more control over supporting their family, personal goals, and other priorities. We can hire people in any country where we have a legal entity.
In this role, you’ll lead high-impact incident response work in a complex cloud environment and help shape how Atlassian responds to security events ’ll lead or coordinate complex security incidents, bringing structure, urgency, and sound judgment under pressure. You’ll partner with Detection, Security Engineering, Product Security, Legal, Crisis Communications, Support, and senior leadership to drive investigation, containment, recovery, and follow-through. You’ll directly manage a team of 5-8 in the US region.
You’ll coach incident responders and senior practitioners, raising the quality of investigations, handoffs, decision‑making, and executive communication. You’ll improve the incident response system through playbooks, metrics, exercises, post‑incident reviews, and better tooling. A key part of the role will be driving the adoption of investigative AI tools and automation that help analysts triage faster, surface relevant signals, reduce toil, and improve consistency without compromising judgment or security rigor.
You’ll also support regulated and high‑trust environments, including work that requires a strong understanding of formal incident handling, reporting expectations, and documented operating procedures.
What you’ll bringOn day one, we’ll expect you to bring a strong mix of incident leadership, operational maturity, and people leadership. You’ll have experience directly leading complex, multi‑stakeholder security incidents in a SaaS, cloud, or enterprise environment, along with demonstrated success managing and developing senior security engineers, incident responders, and/or technical leads.
You’ll have strong executive communication skills, including the ability to translate incomplete technical information into clear decisions, risks, and next steps. You’ll have experience improving incident response programs through metrics, retrospectives, process design, readiness exercises, and cross‑team influence, as well as hands‑on familiarity with investigation workflows, detection and response tooling, log analysis, and operational coordination across globally distributed teams.
You should have experience deploying investigative AI tools and automation in security operations or incident response environments, including using automation to reduce analyst toil, improve triage quality, accelerate investigations, enrich cases, retrieve relevant knowledge, summarize findings, or orchestrate response workflows. You’ll also bring strong systems thinking: the ability to connect incidents to broader improvements in telemetry, detection logic, escalation paths, tooling, and operating models, together with calm, structured decision‑making in ambiguous, high‑pressure situations.
Whatwill set you apart
Experience serving as an incident commander or major incident manager for high‑severity cyber incidents will help you stand out, as will experience supporting regulated environments or formal incident reporting obligations, including government or FedRAMP‑adjacent contexts. We’ll value experience building or scaling follow‑the‑sun incident response models across regions and introducing AI‑assisted investigation workflows, case enrichment, knowledge retrieval, summarization, or orchestration capabilities in security operations.
Strong understanding of how to use operational metrics, quality signals, and error patterns to guide program investments is valuable, as is experience speaking externally, representing security programs, or contributing to broader security community practices.
Our team cultureThe Incident Response team values calm execution, clear communication, and continuous learning. We are collaborative, direct, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).