# Security Operations Lead

**Company:** [Fireworks AI](https://hotfix.jobs/companies/fireworks-ai)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $180k – $210k/yr
**Experience:** 7+ years
**Skills:** Crowdstrike, SIEM, Edr, Detection Engineering, Incident Response, Python, Soar, AWS, GCP, Azure, Mitre Att&Ck, Threat Intelligence, Incident.Io, Pagerduty, Splunk
**Posted:** 2026-08-20

> Build and lead Fireworks AI’s security operations function, owning detection engineering, incident response, threat intelligence, and SecOps workflows. The role requires 7+ years of security experience, hands-on EDR and cloud security expertise, strong Python automation skills, and the ability to grow an IC function into a team.

## Job Description

## Responsibilities
- Lead the rollout, tuning, and ongoing operation of CrowdStrike across endpoint and cloud environments, including SIEM use cases.
- Define and operate detection and response programs, including detection content, triage and escalation workflows, and MITRE ATT&CK coverage measurement.
- Own incident response from triage through executive communication, post-incident reviews, and lessons learned.
- Establish security operations workflows, including SOAR automation, alerting, on-call, incident orchestration, IT ticket triage, SLAs, and metrics.
- Build a threat intelligence capability focused on AI infrastructure and customers, translating intelligence into detections, hardening, and tabletop scenarios.
- Partner with Infrastructure, Corporate Security, IT, Security Engineering, and other cross-functional teams.
- Hire and develop the SecOps team as the function matures, potentially expanding into 24x7 coverage, cloud detection engineering, insider threat, and red/purple team operations.

## Requirements
- 7+ years of experience in security operations, detection and response, incident response, or a related field.
- Hands-on EDR experience, preferably CrowdStrike, including detection engineering and tuning.
- Strong experience writing, testing, and maintaining detection content at scale.
- Demonstrated leadership of real incident responses from triage through executive communication and post-incident review.
- Strong scripting and automation skills, including Python and SOAR platforms.
- Working knowledge of cloud security operations across AWS, GCP, or Azure.
- Experience building or significantly maturing a SecOps function, including tooling selection, process design, and metrics.
- Ability to operate hands-on in a build-phase environment.

## Nice to Have
- SIEM detection engineering at scale with CrowdStrike Falcon LogScale/NG-SIEM, Splunk, Sumo Logic, Panther, or similar tools.
- Experience with Incident.io, PagerDuty, or comparable incident management tools.
- Threat intelligence experience, including operationalizing intelligence into detection and hardening outcomes.
- Experience at an AI, cloud infrastructure, or high-growth SaaS company.
- Certifications such as GCIA, GCIH, GCFA, or OSCP.

## Compensation & Benefits
- Salary range: $180,000–$210,000.
- Work on AI infrastructure and scalable model serving with a collaborative team of engineers and AI researchers.

## Similar jobs

- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Security Engineer, Threat & Offensive Security](https://hotfix.jobs/jobs/9e88bf55-b93e-4acd-ae0b-a8850f2c805e) - Valon - Remote - $180k – $230k/yr
- [Senior Product Security Engineer](https://hotfix.jobs/jobs/ee4b6e89-8ca0-45e7-9cbf-da0994206d99) - Anyscale - $180k – $210k/yr
- [Compliance Manager](https://hotfix.jobs/jobs/90cc18a6-7467-4675-96aa-770c09c5a6ee) - Anyscale - San Francisco, CA - $180k – $230k/yr
- [Senior Application Security Engineer](https://hotfix.jobs/jobs/4bd73e3b-28a6-4dae-956a-f38222e41da3) - Siftstack - Marina Del Rey, CA - $180k – $230k/yr

**Apply:** https://hotfix.jobs/jobs/6494f34e-ec68-46c4-a932-f070ac908ddf
**Canonical:** https://hotfix.jobs/jobs/6494f34e-ec68-46c4-a932-f070ac908ddf