Security Engineer, Detection and Response
Build detection, threat-hunting, and automated incident-response capabilities for AI infrastructure, including GPU clusters, training pipelines, and model deployments. The role requires substantial security operations experience, strong programming skills, and expertise in distributed systems or AI/ML environments.
About the job
Responsibilities
- Design and implement detections for AI-specific threats, including prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training datasets or model weights.
- Build automated response playbooks and orchestration workflows to contain and remediate threats.
- Coordinate security incident response across Cloud, AppSec, Enterprise, and AI Security teams, including forensic investigations of training-pipeline attacks and model manipulation.
- Proactively hunt for threats across GPU clusters and training infrastructure, analyze model outputs for compromise, reproduce AI-specific vulnerabilities, and identify visibility gaps.
- Build detection-as-code frameworks with version control and automated deployment.
- Onboard telemetry from AI training infrastructure and inference endpoints and create dashboards for model security metrics, GPU utilization, and sensitive research-data access.
- Translate threat research into production detections, monitor GPU clusters, detect customer-impacting incidents, and enable security guardrails.
- Participate in a 24/7 on-call rotation for critical AI security incidents.
Requirements
- 3–5+ years of experience in security operations, detection engineering, or incident response, specifically securing AI/ML infrastructure, high-performance computing environments, or distributed systems at scale.
- Strong programming skills in Python, KQL, SPL, or similar languages.
- Experience with SIEM platforms, detection technologies, and forensic investigation techniques.
- Ability to build detections for novel attack techniques and conduct forensics in complex distributed environments.
- Experience securing high-value intellectual property, automating incident response, and conducting proactive threat hunting.
Benefits
- Paid time off and company holidays.
- Medical, dental, and vision coverage.
- Paid parental leave, fertility and family-planning support.
- Flexible spending and health savings account options.
- Wellness and learning stipends.
- Company and team off-sites.
- Stock options and 401(k).
Skills
Python, Kql, Spl, SIEM, Detection Engineering, Incident Response, Threat Hunting, Digital Forensics, Ai Security, Machine Learning, Gpu Clusters, Cloud Infrastructure, Detection-As-Code, Prompt Injection, Model Extraction
Similar jobs
Security Engineering jobsOwn and scale Sardine’s security compliance and GRC function across major security, privacy, and resilience frameworks, including FedRAMP. The role leads audits, risk management, customer assurance, executive reporting, and a growing compliance team while partnering closely with technical and business stakeholders.
Senior Security Compliance Engineer supporting public-sector compliance programs, regulated customers, audits, certifications, and FedRAMP continuous monitoring. Requires 5+ years in GRC or cybersecurity, compliance automation experience, cloud familiarity, and U.S. citizenship and residency.
Owns technology compliance and security assurance controls across corporate and business systems, aligning evidence for SOX, SOC 2, ISO, regulatory, and contractual obligations. The role requires 5+ years in compliance, audit, security, or IT, strong control-testing experience, and a bachelor's degree or equivalent.
Senior Security Engineer on the Red Team performing offensive security, adversarial testing, and red team operations against GenAI/LLM systems, deepfake defenses, cloud infrastructure, and SaaS products. Requires 3+ years of hands-on pen testing/red team experience plus demonstrable GenAI attack experience.
Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.