Principal Incident Responder
Lead end-to-end incident response for frontier AI infrastructure, building detection logic, playbooks, and forensic tooling from the ground up while investigating threats across cloud, endpoint, network, and physical systems at gigawatt scale. Requires hands-on experience leading major incidents, proactive threat hunting, and standing up IR programs.
About the job
Role Scope
- Lead incident response end to end across corporate, cloud, and data center environments, from detection and containment through eradication and post-incident review.
- Build the detection logic, response playbooks, and forensic tooling for an environment where the assets under threat are the most targeted model weights in technology.
- Run investigations across a threat surface measured in gigawatts, correlating signals from cloud, endpoint, network, and physical systems into a single picture of an attack.
- Stand up the incident response function from the ground up, defining severity models, on-call rotations, and the escalation path to leadership.
- Turn each incident into a permanent improvement by partnering with the security and IT teams to close the gaps your investigations surface.
What We're Looking For
- You've personally led major security incidents from first alert to resolution, making containment calls under pressure with the business watching.
- You've built detection logic and response playbooks that caught real intrusions, not just theoretical ones.
- You've run digital forensics across cloud, endpoint, and network evidence and reconstructed what an attacker actually did.
- You've stood up or substantially rebuilt an incident response program rather than only operating inside someone else's.
- You've hunted for threats proactively and found activity that existing tooling missed.
- You write incident reports and postmortems clear enough that both engineers and executives act on them.
- Bonus: Experience defending high-value targets such as AI labs, financial infrastructure, or critical infrastructure against nation-state threat models. Cloud-native forensics (AWS, GCP). Detection engineering and SIEM or SOAR tooling. Malware analysis or reverse engineering.
Skills
Incident Response, Digital Forensics, Threat Hunting, Detection Engineering, SIEM, Soar, Malware Analysis, Reverse Engineering, AWS, GCP, Cloud Forensics
Similar jobs
Security Engineering jobsLeads offensive security research across GitLab’s codebase and AI-powered agentic surfaces, identifying systemic vulnerabilities, developing exploit proofs of concept, and driving remediation. Requires 10+ years of security research or penetration-testing experience and proficiency in multiple programming languages.
Own GitLab’s global security awareness and human-risk program, leading phishing simulations, behavior-change initiatives, training platforms, vendor strategy, and audit support. Requires 10+ years scaling enterprise awareness programs and strong stakeholder influence in a distributed organization.
Leads security, privacy, audit, vendor-risk, and AI governance programs while setting long-term GRC strategy and executing cross-functional controls. Requires 10+ years of GRC, information security, and privacy compliance experience, with deep SOC 2, privacy, and emerging AI governance expertise.
Leads Anthropic’s coordinated vulnerability disclosure and CNA programs, including jailbreak disclosures, external researcher partnerships, public communication, and AI-assisted triage. The role requires disclosure coordination, vulnerability-response operations, and security-community engagement experience.
Build the GRC platform at Anthropic by designing data pipelines, integrations, and agentic LLM workflows that automate compliance evidence collection, policy-as-code, and real-time risk reporting across cloud, identity, HR, and CI/CD systems.