Security engineer, detection and response
San Francisco, CA • FullTime
Posted 13h ago
Job Location
San Francisco, CA
Tech Stack
Remote Work Policy
On-site
Employment Type
FullTime
Categories
AI Infrastructure Engineer
About the job
WRITER is seeking a Staff Detection and Response Engineer to join its security team. This role is crucial for protecting the AI infrastructure that is transforming how the world works. You will be responsible for building sophisticated detection systems to identify attacks targeting our AI platform, training data, and model deployments, while also creating automated response capabilities that scale with the company's rapid growth. This position offers a unique opportunity to combine hands-on security engineering with strategic thinking to stay ahead of novel threats in cutting-edge AI/AGI systems. You will act as the operational arm of the security function, translating threat intelligence into real-time detections, coordinating incident response, and hunting for sophisticated attacks across GPU clusters and distributed training environments. This role is ideal for someone excited by the challenge of securing systems fundamentally different from traditional ones and defining the future of AI security engineering at scale.
Responsibilities
- Design and implement detection strategies for AI-specific threats like prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training data or model weights.
- Build automated response playbooks and orchestration workflows for self-healing security systems, reducing response times and automatically remediating compromised endpoints.
- Lead security incident response coordination across teams (Cloud, AppSec, Enterprise, AI Security) for AI infrastructure or model compromises.
- Conduct forensic investigations on training pipeline attacks and model manipulation attempts.
- Draft clear incident communications for engineering and executive leadership.
- Proactively hunt for sophisticated threats across GPU clusters and training infrastructure by analyzing model outputs and identifying visibility gaps.
- Reproduce AI-specific vulnerabilities from security research.
- Build detection-as-code frameworks with version control and automated deployment.
- Onboard telemetry from AI training infrastructure and inference endpoints.
- Create dashboards to track model security metrics, GPU utilization, and access to sensitive research data.
- Collaborate cross-functionally as an operational security partner, translating threat research into production detections.
- Monitor Cloud Infrastructure's GPU clusters for threats.
- Detect customer-impacting incidents for Software Security Engineering.
- Enable responsible AI development through security guardrails.
- Maintain a 24/7 on-call rotation for critical AI security incidents.
- Respond to real-time threats targeting the platform.
- Continuously improve detection coverage and automation capabilities as AI systems evolve.
Requirements
- 3-5+ years in security operations, detection engineering, or incident response.
- Proven track record of identifying and stopping sophisticated attacks in production environments.
- Experience securing AI/ML infrastructure, high-performance computing environments, or other distributed systems at scale.
- Strong programming skills in Python, KQL, SPL, or similar languages.
- Ability to build custom detection logic and automate response workflows.
- Experience creating tools to operationalize security at scale across cloud-native and distributed computing environments.
- Experience with SIEM platforms and detection technologies.
- Experience with forensic investigation techniques.
- Demonstrated ability to build detection for novel attack techniques.
- Ability to conduct forensics in complex distributed environments.
- Self-directed execution mindset.
- Track record of securing high-value intellectual property.
- Experience automating incident response in complex environments.
- Ability to identify critical security gaps through proactive threat hunting.