Senior Incident Response Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Incident Response Engineer (Cybersecurity): Owning incident triage and response across AWS and GCP with an accent on detection authoring in SIEM and defending against sophisticated threat actors. Focus on building automation via Python, integrating AI agents into SOC workflows, and conducting high-stakes post-mortems.
Location: Must be based in San Francisco, CA (hybrid, 2 days a week in office)
Salary: $243,000 - $284,000
Company
is a venture capital firm that backs bold entrepreneurs building the future across AI, crypto, fintech, and other technology sectors.
What you will do
- Manage end-to-end incident response from initial alert to post-mortem across cloud and SaaS environments.
- Develop high-signal detections in SIEM platforms to cover the MITRE ATT&CK framework.
- Integrate AI agents into triage and response workflows to modernize the SOC.
- Coordinate with Legal, Compliance, Finance, and leadership during critical security incidents.
- Design and implement automation and detection-as-code using Python.
- Execute proactive, hypothesis-driven threat hunts based on current TTPs.
Requirements
- 5+ years of incident response experience with deep expertise in both AWS and GCP.
- Proven track record of leading live incidents including forensic investigation and eradication.
- Proficiency in detection authoring (Sigma, KQL) and SIEM architecture.
- Strong Python scripting skills for building security automation.
- Experience defending against nation-state groups or organized criminal operations.
- Must be able to work from the San Francisco office 2 days per week.
Nice to have
- GCIH or equivalent IR certification.
- Knowledge of AI/agent systems and their security implications.
Culture & Benefits
- Comprehensive benefits package including health, dental, vision, disability, and life insurance.
- Retirement savings through a 401K plan.
- Paid vacation and sick leave.
- Participation in the a16z carry program and discretionary bonus programs.
- High-performance culture focusing on first-class business and long-term relationships.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →