Detection & Response Engineer
Remote • Remote • FullTime
Posted 7h ago
Remote Work Policy
Fully remote
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Runway is seeking a Detection & Response Engineer to build and manage the company's security program for its infrastructure, research environment, and products. This role involves developing "detections as code" and "response as automation" to identify and mitigate threats in a unique environment that includes research compute, large training datasets, and AI-assisted tooling. The engineer will have end-to-end ownership of the detection program, from logging to incident closure, and will collaborate with platform and research engineers to ensure new systems are secure from the outset. This is an opportunity to shape a critical security function within a company at the forefront of AI development.
Responsibilities
- Own detection and response end-to-end, including logging, alerting, triage, and recovery.
- Write and tune detections as code across cloud environments, Kubernetes, identity systems, endpoints, and SaaS, focusing on coverage and precision.
- Lead incident response from initial alert through containment and forensics, including writing post-incident reviews.
- Build automation for triage, enrichment, correlation, containment, and evidence collection, utilizing LLM-based tooling where appropriate.
- Monitor AI agents and developer tooling within the environment, translating observations into telemetry and controls.
- Partner with platform and research engineers to integrate logging and response playbooks into new systems.
- Conduct threat hunts and tabletop exercises to identify and remediate vulnerabilities.
- Generate metrics for SOC 2, ISO 27001, and customer security reviews.
- Participate in an on-call rotation for security incidents.
Requirements
- Hands-on incident response experience, including triaging alerts, leading investigations, and documenting incidents.
- Experience building and tuning detections in a modern SIEM, preferably managed as code.
- Working knowledge of cloud and Kubernetes attack vectors (e.g., IAM abuse, container escape, credential theft, supply chain compromise) and their corresponding logs.
- Proficiency in Python, Typescript, Rust, or a similar language for automating security tasks and tool integration.
- Familiarity with at least one major cloud platform and Kubernetes at the level of audit logs, RBAC, and workload identity.
- Strong writing skills for incident timelines, detection documentation, and leadership updates.
- Sound judgment for determining alert priorities, automation opportunities, and escalation needs.