Skip to content

Open nowPosted 48 days ago

Incident Response Manager, Security Operations Group | Worldwide Operations Security

Amazon / AWS22,294 open roles

Where
London, England, GBR
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIncident Response Manager, Security Operations Group | Worldwide Operations SecurityAmazon / AWS · London, England, GBR
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Amazon / AWS's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Amazon / AWS postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.2%30 days
This job: posted 48 days ago

Amazon / AWS median: 7 days open

The posting

This position can be based from any EMEA Corporate Location or current site (pending site lead, PXT and Hiring manager approval).

As an Incident Response Manager within Worldwide Operations Security (WWOS) Security Operations Group (SOG), you will serve as the primary crisis response coordinator for high and moderate severity incidents (SEV1, SEV2 and SEV3) impacting Amazon's people, operations, assets, and brand across globally. You will independently own the end-to-end lifecycle of critical incidents from initial notification and triage though immediate mitigation, stakeholder coordination, and post-incident review. Reporting to the Sr. Manager – Operations Incident Management, you will operate within established GSOC and SOG protocols, lead Incident Management Teams (IMTs) through complex crisis events, and drive continuous improvement of response frameworks across one of Amazon's most dynamic operating environments.

Key job responsibilities - Lead end-to-end coordination of high severity incidents (SEV1/SEV2), managing the full lifecycle from initial notification through mitigation, stabilization, and closure - Own 24/7/365 on-call rotation, responding to threats and incidents within the CTI Matrix per SOG escalation procedures, including Slack channel activation and senior leadership notification - Coordinate Immediate Mitigation calls with site-level Incident Commanders and IMTs, assigning action items to ensure life safety, operational continuity, and brand protection - Execute tactical response protocols including video lockdown, ESU/Off-Duty deployments, and OSINT/SOCMINT analysis within established timelines - Prepare site risk overviews and deliver incident summaries to WWOS senior leadership within 4 hours of incident onset - Manage Incident Room operations including real-time updates, dynamic action tracking, EMT notifications, and stakeholder conference calls - Lead After Action Reviews within 3 days of incident conclusion, driving corrective actions and mechanism implementation to prevent recurrence - Maintain and validate high severity protocols, the CTI Matrix, escalation workflows, and response timelines through continuous improvement - Partner with GSOC, Regional S&LP, Operations, WHS, and PXT to influence decision-making and ensure site-level IMT readiness per WWOS Critical Incident Response standards

A day in the life As an Incident Response Manager, your day begins by reviewing active Incident Rooms, monitoring the GSOC threat landscape, and independently assessing emerging threats against the Category, Type, and Item (CTI) matrix to determine escalation requirements. You drive strategic and tactical work simultaneously, supporting Immediate Mitigation (IM) calls with site-level Incident Commanders and IMTs, and leading real-time response actions. Throughout the week, you engage senior stakeholders across WWOS, Ops, PXT, ER, WHS, and Ops Disruption leadership, supporting GSOC Conference Calls and guiding decision-making during critical incidents. You own On-Call rotation responsibilities, responding to emerging threats with direct mitigation support including coordinating ESU/Off-Duty deployments, conducting OSINT/SOCMINT analysis, and delivering initial incident summaries to WWOS senior leadership within established SLAs. When high severity events arise, you exercise independent judgment to create site-specific Slack channels, manage video lockdown tickets, prepare site risk overviews and hardening posture assessments, and lead After Action Reviews (AARs) within 3 days of incident conclusion.

About the team The Operational Incident Response (OIR) team sits within the Security Operations Group (SOG) under Worldwide Operations Security (WWOS). The team provides 24/7/365 critical incident coordination across WWAS operations, serving as the central point for real-time response to life safety events, operational disruptions, natural disasters, workplace violence, and facility security threats. Working through the GSOC, the team brings together key stakeholders, manages Incident Rooms, and drives resolution from first notification through post-incident review.

OIR members are senior individual contributors who independently own the full incident lifecycle. They coordinate Immediate Mitigation calls with site-level Incident Commanders and IMTs, facilitate GSOC Conference Calls for SEV1 events, and deliver incident summaries to WWOS senior leadership. Key partnerships include GSOC, Regional S&LP, Operations leadership, Legal, and cross-functional business continuity stakeholders across highly diversified global environments.

The team operates as a service to the business, ensuring continuation of operations through risk oversight, contingency planning, and structured response. This role requires independent judgment under pressure, real-time coordination across multiple time zones, and the ability to influence senior leadership during unfolding events where life safety is at stake.

- Bachelor's degree or equivalent in Risk Management, Business Administration, Security Management, or a related field - Experience applying key financial performance indicators (KPIs) to analyses, or experience in building financial and operational reports/data sets that inform business decision-making - Experience building cross-functional partnerships and influencing stakeholders across the organization to act without having a direct reporting relationship - Knowledge of Microsoft Office products and applications at an advanced level - Experience prioritizing and handling multiple assignments at any given time while maintaining commitment to deadlines, or experience with end-to-end project management - Experience in written and verbal communication with the ability to present complex technical information in a clear and concise manner to executives and non-technical leaders - Experience in a high-volume environment, such as a security operations center, event security, call center, or crisis management/emergency response center

- Experience working in a fast-paced and ambiguous environment, or experience delivering results for large, cross-functional initiatives/projects - Master's degree in risk management, Security, Business Administration, or related field - A security/risk management industry certification (ASIS CPP, CRMP, CBCP, or equivalent) - Advanced experience with risk, business continuity, and data management platforms (BSI, Audit Board, etc.) - Direct user experience with geo-spatial tools and platforms (ArcGIS, ESRI, Palantir, etc.)

Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice (https://www.amazon.jobs/en/privacy_page) to know more about how we collect, use and transfer the personal data of our candidates.

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Amazon / AWS's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Amazon / AWS's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Amazon / AWS's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.