# Principal Incident Responder

**Company:** [Fluidstack](https://hotfix.jobs/companies/fluidstack)
**Location:** Austin, TX, New York, NY, San Francisco, CA, Seattle, WA
**Role:** Security Engineering
**Salary:** $330k – $380k/yr
**Experience:** 7+ years
**Skills:** Incident Response, digital forensics, threat hunting, detection engineering, SIEM, soar, malware analysis, reverse engineering, AWS, GCP, cloud forensics
**Posted:** 2026-07-17

> Lead end-to-end incident response for frontier AI infrastructure, building detection logic, playbooks, and forensic tooling from the ground up while investigating threats across cloud, endpoint, network, and physical systems at gigawatt scale. Requires hands-on experience leading major incidents, proactive threat hunting, and standing up IR programs.

## Job Description

## Role Scope
- Lead incident response end to end across corporate, cloud, and data center environments, from detection and containment through eradication and post-incident review.
- Build the detection logic, response playbooks, and forensic tooling for an environment where the assets under threat are the most targeted model weights in technology.
- Run investigations across a threat surface measured in gigawatts, correlating signals from cloud, endpoint, network, and physical systems into a single picture of an attack.
- Stand up the incident response function from the ground up, defining severity models, on-call rotations, and the escalation path to leadership.
- Turn each incident into a permanent improvement by partnering with the security and IT teams to close the gaps your investigations surface.

## What We're Looking For
- You've personally led major security incidents from first alert to resolution, making containment calls under pressure with the business watching.
- You've built detection logic and response playbooks that caught real intrusions, not just theoretical ones.
- You've run digital forensics across cloud, endpoint, and network evidence and reconstructed what an attacker actually did.
- You've stood up or substantially rebuilt an incident response program rather than only operating inside someone else's.
- You've hunted for threats proactively and found activity that existing tooling missed.
- You write incident reports and postmortems clear enough that both engineers and executives act on them.
- Bonus: Experience defending high-value targets such as AI labs, financial infrastructure, or critical infrastructure against nation-state threat models. Cloud-native forensics (AWS, GCP). Detection engineering and SIEM or SOAR tooling. Malware analysis or reverse engineering.

## Similar roles

- [Principal Security Engineer](https://hotfix.jobs/jobs/40a2458a-4a6c-488f-9347-eec2d58c26c2) - Square - California - $319k – $479k/yr
- [Principal Infrastructure Security Engineer](https://hotfix.jobs/jobs/fdaecf48-c221-4556-b4cf-722bfc4d05ed) - Crusoe - San Francisco, CA - $280k – $330k/yr
- [Principal Software Engineer II - Product Security](https://hotfix.jobs/jobs/09bd6c52-42a3-4c57-82dd-dcb03292fb85) - Snowflake - Menlo Park, CA - $280k – $403k/yr
- [Principal Engineer, Authentication](https://hotfix.jobs/jobs/6951d447-8a37-4257-b626-ee033a79d9b8) - Databricks - Remote - $280k – $385k/yr
- [Principal Engineer - Privacy](https://hotfix.jobs/jobs/7832d3b3-421d-475e-acde-1b8d426b086f) - Databricks - Mountain View, CA - $278k – $339k/yr

**Apply:** https://hotfix.jobs/jobs/674513ff-8806-4e7b-a45b-106312c091e9
**Canonical:** https://hotfix.jobs/jobs/674513ff-8806-4e7b-a45b-106312c091e9