pirchroles › Incident Manager
is this you?

Incident Manager

When a bank's payment system dies at 2am, there's a person on the bridge call who isn't fixing the code — they're running the response: right people paged, decisions forced, executives calmed, chaos converted into a timeline. That's the incident manager. It's a career built for people who get calmer as things get worse, and most people have never heard it exists. Here's the honest picture.

Median pay (US)
~$95k / yr
Typical range
$70k–$135k+
Degree required?
No — composure + process fluency win

What the job actually is

Incident managers own the RESPONSE to technology failures, not the repair itself: triaging severity, assembling the right responders, running the bridge (keeping engineers focused on fixing while shielding them from executive panic), forcing decisions when investigation stalls ('we roll back at :30 unless someone objects with data'), communicating status upward and outward in plain language, and afterward running the post-incident review that turns pain into prevention. The role comes in flavors: ITIL-style major incident managers at enterprises and MSPs (process-heavy, often 24/7 rotations), SRE-adjacent incident commanders at tech companies (closer to engineering, often a rotating hat that became a job), and problem managers who chase the recurring causes between fires. The shared core: command presence without command authority.

Is it actually you?

You'll probably love it if

  • You're the person who gets CALMER when everyone else spins up — genuinely, not aspirationally
  • Coordinating experts without being the deepest expert suits your ego fine
  • Clear communication under pressure is your superpower: brief, honest, no filler
  • Process (severity levels, comms cadences, runbooks) feels like scaffolding, not bureaucracy
  • The blameless-postmortem mindset — systems fail, people don't — matches how you think

Maybe not, if

  • You'd hate not being the fixer — IMs run the response, engineers get the catharsis
  • Shift rotations and 2am bridge calls are incompatible with your life
  • Adrenaline debt accumulates in you — this job's stress is real and spiky
  • Chasing status from stressed engineers who see you as overhead would wear you down
  • Quiet weeks would bore you into misery (much of the job is preparation, not fires)

The real day-to-day (no hype)

How people break in — or switch in

The classic sources: NOC and help-desk people who showed unusual calm during outages (this is genuinely how many IMs get spotted — a major incident happens and someone notices you didn't flail), service desk leads at MSPs, support engineers, and military/emergency-services veterans whose command-and-control instincts transfer almost directly. Practical moves: get incident reps wherever you are (volunteer for the on-call rotation, take notes and drive comms during the next big outage — someone has to, and doing it well is an audition), learn the vocabulary (ITIL 4 Foundation is a cheap, recognized ticket into enterprise roles; study real postmortems from major tech companies — many are public), and practice the writing: crisp status updates are the visible tenth of the job. Enterprises, banks, MSPs, healthcare systems, and any 24/7 platform company hire for this continuously.

Veterans and former first responders: this is one of tech's most direct transfers of what you already do — triage, command structure, comms discipline under pressure. ITIL Foundation plus your incident stories from the field is a complete application; don't let the tech-vocabulary gap talk you out of applying.

Your application, already half-written

Here's a question every Incident Manager application asks, answered the way pirch would — in a real voice, grounded in real experience:

“Walk us through how you handled a major incident.”
Payment processing went down during a holiday sales peak — roughly $80k an hour of failed transactions and an executive team lighting up every channel. I declared SEV-1, opened the bridge, and did the three things I always do first: assigned a scribe (so the timeline builds itself), split the room (one thread investigating the new deploy, one prepping rollback in parallel — not sequentially), and set the comms cadence out loud: business update every 15 minutes, from me only, so engineers could work instead of reporting. Twenty minutes in, investigation was inconclusive and the rollback was staged, so I forced the call: 'Rollback in five unless someone objects with evidence.' Nobody did; we rolled back; payments recovered at minute 41. The root cause turned out to be a config interaction the deploy tests couldn't catch. The postmortem mattered more than the save: blameless, three action items with owners — including a canary stage for that deploy class — and I tracked all three to completion. That failure mode hasn't recurred in the two years since. What I actually manage isn't incidents — it's the gap between a 40-minute outage and a 4-hour one, and that gap is decision discipline, not technical genius.
pirch's co-pilot writes answers like this for your background and the exact job — try it free →
pirch mascot

pirch finds the incident roles that fit your nerve

Incident manager, major incident manager, incident commander, problem manager — enterprises, MSPs, and tech companies all label it differently and demand different rotations. Tell pirch who you are and it hunts down real, still-open roles that fit your life, with a tailored cover letter already written. No spray-and-pray. No dead links.

start your free hunt
first hunt free · we never auto-apply · you stay in control

Common questions

What does an incident manager actually do?

They run the response when technology fails: triage severity, assemble responders, run the bridge call, force timely decisions, communicate status in plain language, and drive the post-incident review that prevents recurrence. They coordinate the fix; engineers perform it.

How much do incident managers make?

Roughly $70k–$135k+ with a median around $95k. Major-incident roles at banks and large enterprises pay toward the top, SRE-adjacent incident command at tech companies can exceed the range, and 24/7 rotation coverage often adds shift differentials.

What qualifications do you need for incident management?

Demonstrated composure under pressure beats credentials — but ITIL 4 Foundation is a cheap, widely recognized enterprise ticket, and familiarity with incident tooling and public postmortems helps. NOC, help desk, support, and military/emergency backgrounds all convert directly.

Is incident management stressful?

Spikily, yes — real incidents are intense and rotations mean some 2am calls. The offsets: between incidents the work is preparation-paced, the skill compounds into leadership roles unusually well, and people wired for crisis-calm often find it energizing rather than draining. Know your wiring honestly before choosing it.

Related roles