Security Engineer, Detection and Response
Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.
About the job
Responsibilities
- Design and implement detections for AI-specific threats, including prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training data or model weights.
- Build automated response playbooks and orchestration workflows to contain and remediate threats.
- Coordinate security incident response across Cloud, AppSec, Enterprise, and AI Security teams.
- Conduct forensic investigations into training-pipeline attacks and model manipulation attempts.
- Proactively hunt for threats across GPU clusters and distributed training infrastructure.
- Build detection-as-code frameworks with version control and automated deployment.
- Onboard telemetry from AI training infrastructure and inference endpoints.
- Create dashboards for model security metrics, GPU utilization patterns, and access to sensitive research data.
- Translate threat research into production detections and establish security guardrails.
- Participate in a 24/7 on-call rotation for critical AI security incidents.
Requirements
- 3–5+ years of experience in security operations, detection engineering, or incident response, with a record of stopping sophisticated production attacks.
- 3+ years securing AI/ML infrastructure, high-performance computing environments, or distributed systems at scale.
- Strong programming skills in Python, KQL, SPL, or similar languages.
- Experience with SIEM platforms, detection technologies, and forensic investigation techniques.
- Ability to develop detections for novel attack techniques and conduct forensics in complex distributed environments.
- Experience automating incident response and conducting proactive threat hunting.
Compensation and benefits
- Competitive compensation and company stock options.
- Generous paid time off and company holidays.
- Medical and dental insurance.
- 16 weeks of paid parental leave for all parents.
- Fertility and family-planning support.
- Early-detection cancer testing.
- Competitive pension scheme and company contribution.
- Wellness, learning and development stipends.
- Company-wide and team off-sites.
Skills
Python, Kql, Spl, SIEM, Detection Engineering, Incident Response, Threat Hunting, Digital Forensics, Ai Security, Machine Learning Infrastructure, Gpu Clusters, Detection As Code, Cloud Security, Security Orchestration
Similar jobs
Security Engineering jobsSenior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Senior security engineer who red teams formally verified systems, assesses proof and threat-model boundaries, and builds AI-driven vulnerability discovery and exploit-generation tooling. Requires hands-on offensive security, formal methods, systems expertise, software development, and rigorous technical reporting.
Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.
This role creates and tests red-team labs, ranges, and learning content that simulate real-world attacks and teach offensive-security concepts. It requires several years of penetration-testing or offensive-security experience, strong MITRE ATT&CK knowledge, and broad technical cybersecurity skills.