Назад
Company hidden
58 минут назад

Lead Engineer, Incident Response (AI)

295 000 - 347 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Engineer, Incident Response (AI): Building and leading detection and response capabilities across cloud, SaaS, identity, and endpoint environments with an accent on incident investigation, detection engineering, automation, and brand protection. Focus on leading high-stakes response, designing SIEM and security logging architecture, threat hunting, and evaluating AI-assisted response workflows.

Location: San Francisco, California, United States; in-office presence required two days per week

Salary: $295,000–$347,000 per year, plus potential carry, discretionary bonuses, and benefits.

Company

hirify.global is a venture capital firm investing in technology companies across areas including AI, healthcare, crypto, fintech, enterprise software, consumer products, and games.

What you will do

  • Set the detection and response roadmap, prioritize threats, and measure coverage, alert quality, and response effectiveness.
  • Lead, coach, and develop security engineers while remaining hands-on with investigations and engineering projects.
  • Lead major incidents from triage through containment, eradication, recovery, and postmortems, including vendor incidents.
  • Design SIEM architecture, security log pipelines, detection-as-code, and visibility across cloud, identity, and endpoint environments.
  • Run threat hunts and build brand protection capabilities against impersonation, fraudulent websites, and lookalike domains.
  • Build AI-assisted response automation and coordinate incident communications with Security Engineering, IT, Legal, Compliance, Finance, and investing teams.

Requirements

  • 9+ years of incident response or detection and response experience, including cloud incident response across AWS and GCP.
  • Experience managing security engineers through coaching and performance management while remaining technically hands-on.
  • Experience leading detection and response programs and high-stakes incidents across cloud, SaaS, identity, and endpoint environments.
  • Strong detection engineering skills with SIEM query languages or rule formats such as KQL or Sigma, including testing and tuning.
  • Experience with SIEM and security log pipelines, EDR, SOAR, forensic investigation, threat hunting, and security automation.
  • Strong Python skills, knowledge of AI and agent-system limitations and risks, and the ability to communicate technical trade-offs to senior stakeholders.

Nice to have

  • GCIH or an equivalent incident response certification.

Culture & Benefits

  • Health, dental, vision, disability, and life insurance.
  • 401(k) plan, vacation, and sick leave.
  • Eligibility for the a16z carry program and discretionary bonus programs.
  • Participation in the Security team's on-call rotation.
  • Collaborative culture focused on long-term relationships, empathy, teamwork, and high-quality execution.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →