Detection & Response Engineer
R
RunwayArtificial Intelligence
Open to hiring remote — we also have offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv.Full-TimeMiddle
Salary$240K - $290K; $240K – $290K
Apply NowOpens the employer's application page
Job Details
- Required Skills
- PythonKubernetesTypeScriptRust
Requirements
- Hands-on incident response experience including triaging live alerts and leading investigations
- Experience building and tuning detections in a modern SIEM, ideally managed as code
- Knowledge of attacker methodology in cloud and Kubernetes (IAM abuse, container escape, credential theft, supply chain compromise)
- Comfort writing code in Python, Typescript, or Rust to automate response and integrate security tools
- Familiarity with at least one major cloud platform
- Proficiency with Kubernetes audit logs, RBAC, and workload identity
- Excellent technical writing skills for incident timelines, documentation, and reporting
- Strong judgment regarding alerting thresholds, automation, and incident escalation
Responsibilities
- Own detection and response end to end: what we log, what we alert on, how we triage and how we recover
- Write and tune detections as code across multiple cloud environments, Kubernetes, identity systems, endpoints and SaaS
- Lead incident response from the first alert through containment and forensics, then write the post-incident review
- Build automation for triage, enrichment, correlation, and containment, including using LLM-based tooling
- Monitor AI agents and developer tooling to turn activity into telemetry and controls
- Partner with platform and research engineers to ensure new systems ship with logging and response playbooks
- Run threat hunts and tabletop exercises to proactively identify and fix vulnerabilities
- Turn incident and detection metrics into evidence for SOC 2, ISO 27001, and security reviews
- Participate in an on-call rotation for security incidents
View Full Description & ApplyYou'll be redirected to the employer's site