The Director of Incident Management is responsible for leading the organization's incident response and service restoration function across IT, security, infrastructure, applications, and business-critical systems. This role ensures incidents are managed with urgency, discipline, and clear communications to minimize business disruption, protect assets, and restore services quickly and safely.
The ideal candidate is a strong operational leader with deep experience in incident coordination, escalation management, cross-functional communication, and post-incident improvement. This leader will establish and maintain incident processes, drive accountability during outages and security events, and partner with technical and business stakeholders to improve resilience and reduce repeat incidents.
Responsibilities:
- Lead enterprise incident management operations for IT service disruptions, security incidents, infrastructure outages, and high-priority business-impacting events.
- Own the incident lifecycle from triage and escalation through containment, restoration, communication, and post-incident review.
- Establish and maintain incident severity definitions, escalation paths, communication standards, and decision-making frameworks.
- Coordinate with IT, cybersecurity, infrastructure, application, service desk, vendors, and business leaders during major incidents.
- Serve as the primary point of command during major incidents and ensure clear ownership, timely actions, and executive-level updates.
- Partner with cybersecurity leadership during security incidents to coordinate operational response and service restoration in accordance with established security incident-response protocols.
- Manage incident communications to stakeholders, leadership, and end users with accuracy, professionalism, and urgency.
- Drive root cause analysis, corrective action tracking, and continuous improvement after major and recurring incidents.
- Monitor incident trends, recurring failure patterns, and service risks to recommend preventive actions.
- Develop and maintain incident management policies, runbooks, playbooks, and operational procedures.
- Plan and lead incident-response exercises, simulations, and readiness assessments to identify gaps and strengthen organizational preparedness.
- Ensure incident metrics and reporting are accurate, meaningful, and aligned with business objectives.
- Partner with change management, problem management, business continuity, disaster recovery, and service management functions to improve operational stability and resilience.
- Coach technical teams on effective incident handling, escalation discipline, and operational readiness.
- Provide leadership and direction to direct reports by establishing clear priorities, assigning responsibilities, supporting employee development, managing performance and driving accountability for operational outcomes.
- Support audits, regulatory expectations, and governance requirements related to operational resilience and incident response.
- Participate in an on-call rotation and remain available outside regular business hours to lead critical incident response, as business needs require.
- Other duties as assigned.
Requirements:
- Bachelor's degree in information technology, computer science, cybersecurity, business administration and 7+ years of experience in IT operations, service management, incident response, or security operations and 3+ years of leadership experience managing incident response, major incident coordination, or service restoration functions OR 10+ years of experience in IT operations, service management, incident response, or security operations and 3+ years of leadership experience managing incident response, major incident coordination, or service restoration functions
- Strong knowledge of ITIL, incident management processes, and service restoration practices.
- Demonstrated experience leading high-pressure situations and coordinating multiple technical teams.
- Excellent written and verbal communication skills, including executive communication.
- Strong analytical and problem-solving skills with a structured approach to triage and resolution.
- Experience working with ticketing, monitoring, collaboration, and reporting tools.
- Ability to influence without direct authority across technical and business teams.
- Ability to work outside regular business hours, including evenings, weekends, and holidays, to support critical incidents as necessary.
Preferred Qualificiations:
- Experience in regulated environments such as healthcare, life sciences, financial services, or other high-compliance sectors.
- Background in cybersecurity incident response or security operations.
- Experience with major incident command structures and executive communications.
- Familiarity with root cause analysis methodologies and operational resilience frameworks.
- ITIL certification, CISSP, CISM, PMP, or similar credentials.
- Experience building incident dashboards, metrics, and leadership reporting.
The L.A. Times is an equal opportunity employer and welcomes all qualified applicants regardless of race, ethnicity, religion, gender, gender identity, sexual orientation, disability status, protected veteran status, or any other characteristic protected by law. We actively work to create an inclusive environment where all of our employees can thrive. This Privacy Notice for Los Angeles Times sets forth how we will use the information we obtain when you apply for a position with us. Explore our company history, achievement, values, mission and more on our career site. The pay scale the Company reasonably expects to pay for this position at the time of the posting is $170,000 to $190,000 and takes into account a wide range of factors including but not limited to skill set, experience, training, licenses, certifications, and other business or organizational needs. Compensation will be determined based on the above factors along with the requirements of the position. At the L.A. Times, it is not typical for an individual to be hired at or near the top of the range for the role. Please visit our career site to view the benefits available to our employees. We recommend adding our applicant tracking system domain (@dayforce.com) as a safe sender or contact, sometimes these emails get filtered to candidates' spam folders.
|