Назад
5 дней назад

Detection & Response Engineer (AI Security)

240 000 - 290 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Английский
b2
Страна
France/UK/US +1 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Detection & Response Engineer (AI Security): Building and owning an end-to-end detection and response program for frontier AI infrastructure, research environments, and video model products with an accent on detections as code, automated response, and security telemetry. Focus on leading incident investigations, securing cloud and Kubernetes environments, monitoring AI agents and developer tooling, and producing evidence for SOC 2 and ISO 27001.

Location: Remote; offices available in New York, San Francisco, Seattle, London, Paris, and Tel Aviv

Salary: $240K–$290K annually for candidates in the U.S.; ranges may vary outside the U.S.

Company

Runway builds AI world models and frontier video models by combining art, science, and simulation.

What you will do

  • Own the detection and response program end to end, including logging, alerting, triage, recovery, and incident metrics.
  • Write and tune detections as code across cloud environments, Kubernetes, identity systems, endpoints, and SaaS platforms.
  • Lead incident response from initial alert through containment, forensics, and post-incident review.
  • Build automation for enrichment, correlation, containment actions, and evidence collection, including audited LLM-based tooling where appropriate.
  • Monitor AI agents and developer tooling, and develop telemetry, controls, threat hunts, and tabletop exercises.
  • Partner with platform, research, and GRC teams to implement security logging, response playbooks, and evidence for SOC 2, ISO 27001, and enterprise reviews.

Requirements

  • Hands-on experience triaging live alerts, leading investigations, and documenting incidents.
  • Experience building and tuning detections in a modern SIEM, preferably managed as code.
  • Knowledge of attacker activity in cloud and Kubernetes environments, including IAM abuse, container escape, credential theft, and supply chain compromise.
  • Ability to write Python, TypeScript, Rust, or another language for response automation and security tool integrations.
  • Familiarity with a major cloud platform and Kubernetes audit logs, RBAC, and workload identity.
  • Strong written communication and sound judgment about alerting, automation, and escalation.

Nice to have

  • Experience monitoring GPU or HPC infrastructure, research environments, or large datasets.
  • Experience building detections or guardrails for AI agents, LLM tooling, or MCP servers.
  • Cloud forensics experience, including disk and memory acquisition, audit trail reconstruction, and chain of custody.
  • Published open-source detection content.

Culture & Benefits

  • Remote work is available, with offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv.
  • Participation in a security incident on-call rotation is expected.
  • Work with creative, open-minded, caring, and ambitious colleagues building AI simulation systems.
  • Commitment to equal opportunity, inclusion, and pay equity.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →