About this Incident Response & Forensics Lead role at Anaplan
At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market.
What unites Anaplanners across teams and geographies is our collective commitment to our customers’ success and to our Winning Culture.
Our customers rank among the who’s who in the Fortune 50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform.
Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins – big and small.
Supported by operating principles of being strategy-led, values-based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together!
Role Summary:
As Anaplan's Incident Response & Forensics Lead, you will lead and improve how we investigate, respond to, and learn from security incidents. This is a senior, hands-on role that combines deep digital forensics and incident response expertise with strong threat intelligence knowledge. You will lead complex investigations, perform forensic analysis, conduct threat hunting, and leverage intelligence to understand who we are up against and how they operate.
You'll help build a mature, intelligence-driven IR capability grounded in a clear understanding of who targets organisations like ours and how they operate, including state-sponsored actors, well-resourced criminal groups, and attackers making growing use of AI.
Your Impact:
- Act as technical lead on our highest-severity incidents, owning the investigation end-to-end, from triage and scoping through containment, eradication, recovery, and post-incident review
- Perform digital forensic analysis across endpoints, servers, cloud, SaaS, and identity environments, preserving evidence and reconstructing attacker activity and timelines
- Apply an intelligence-driven approach to investigations, using what you find to understand adversary tradecraft, likely objectives, and related activity, and using that understanding to guide scoping and response decisions
- Work alongside legal, privacy, and communications teams during major incidents, and with external incident response partners where needed
- Lead proactive, hypothesis-led threat hunts informed by investigation findings, intelligence, and emerging tradecraft, and turn the results into tested, high-fidelity detections
- Produce internal threat reporting that translates what we're seeing in our environment, and across the threat landscape relevant to us, into clear assessments and actions for security teams and leadership
- Shape our threat intelligence capability, including intelligence requirements and the sources and tooling that support them, keeping it directly connected to investigation, hunting, and detection work
- Expand incident response playbooks, forensic procedures, and evidence handling standards, raise the standard of how we run complex investigations, and coach SOC analysts through live investigations
- Use AI as a core part of how you work, building and applying AI-assisted workflows and automation for evidence collection, enrichment, triage, and analysis, and integrating them with our security tooling
Your Skills:
- Extensive hands-on experience in digital forensics and incident response, including leading complex, high-severity investigations across hybrid, cloud, and SaaS environments
- Practical forensic skills across endpoint, memory, network, log, and cloud evidence, with a sound approach to evidence handling and chain of custody
- An intelligence mindset developed through investigative work: you naturally ask who is behind activity, what they want, and what else they're likely to have done, and you can turn investigation findings into intelligence that drives hunting, detection, and reporting
- Working knowledge of intelligence analysis fundamentals, such as intelligence requirements, structured analysis, confidence assessments, and models like the Diamond Model and F3EAD, and how they apply to incident response
- Familiarity with the cybercrime underground, including how criminal forums and marketplaces, initial access brokers, and ransomware ecosystems operate. Experience safely operating and managing research personas is a strong plus
- Experience leading hypothesis-driven threat hunting and converting findings into detections
- Demonstrable, hands-on experience using AI in security work, such as building AI-assisted investigation or triage workflows, using LLMs to accelerate analysis, or developing automation and integrations, with a grounded view of where it helps and where it doesn't. Solid scripting ability (e.g. Python) to support this
- Good knowledge of SIEM, SOAR, and EDR/XDR platforms and how they support investigation, hunting, and response
- Strong understanding of attacker behaviour and the MITRE ATT&CK framework, particularly across enterprise, cloud, and SaaS environments
- Ability to explain complex technical findings clearly and concisely, in writing and in person, to executive audiences, including CISO-level stakeholders
- Calm, structured judgement during high-pressure incidents, with a drive to share knowledge and raise the capability of the wider team
Our Commitment to Diversity, Equity, Inclusion and Belonging (DEIB)
We believe attracting and retaining the best talent and fostering an inclusive culture strengthens our business. DEIB improves our workforce, enhances trust with our partners and customers, and drives business success. Build your career in a place where diversity, equity, inclusion and belonging aren’t just words on paper – this is what drives our innovation, it’s how we connect, and it contributes to what makes us a market leader. We believe in a hiring and working environment where all people are respected and valued, regardless of gender identity or expression, sexual orientation, religion, ethnicity, age, neurodiversity, disability status, citizenship, or any other aspect which makes people unique. We hire you for who you are, and we want you to bring your authentic self to work every day!
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive equitable benefits and all privileges of employment. Please contact us to request accommodation.
Fraud Recruitment Disclaimer
It has come to our attention that fraudulent and fictitious job opportunities are being circulated on the Internet. Prospective candidates are being contacted by certain individuals, mainly through telephone calls, emails and correspondence, claiming they are representatives of Anaplan. The main purpose of these correspondences and announcements is to obtain privileged information from individuals.
Anaplan does not:
- Extend offers to candidates without an extensive interview process with a member of our recruitment team and a hiring manager via video or in person.
- Send job offers via email. All offers are first extended verbally by a member of our internal recruitment team whenever possible and then followed up via written communication.
All emails from Anaplan would come from an @anaplan.com email address. Should you have any doubts about the authenticity of an email, letter or telephone communication purportedly from, for, or on behalf of Anaplan, please send an email to [email protected] before taking any further action in relation to the correspondence.
Privacy & AI Notice
Candidate data processed during our recruitment activities is handled in accordance with our Candidate Privacy Notice. This may include the use of artificial intelligence or automated tools to assist our team in evaluating qualifications.
