Security engineer, detection and response (UK)
London, UK • FullTime
Posted 13h ago
About the job
WRITER is seeking a Staff Detection and Response Engineer to join its security team and protect the company's AI infrastructure. This role involves building sophisticated detection systems for attacks targeting the AI platform, training data, and model deployments, as well as creating automated response capabilities. The position combines hands-on security engineering with strategic thinking to address novel threats in cutting-edge AI/AGI systems. The engineer will be the operational arm of the security function, translating threat intelligence into real-time detections, coordinating incident response, and hunting for sophisticated attacks across GPU clusters and distributed training environments. This is an opportunity to define AI security engineering at scale, working closely with AI Security research, Cloud Infrastructure, Software Security Engineering, and AI researchers.
Responsibilities
- Design and implement detection strategies for AI-specific threats like prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training data or model weights.
- Build automated response playbooks and orchestration workflows for self-healing security systems, reducing mean time to response and automatically remediating compromised endpoints.
- Lead security incident response coordination across multiple teams during AI infrastructure or model compromises, conducting forensic investigations and drafting incident communications.
- Proactively hunt for sophisticated threats across GPU clusters and training infrastructure by analyzing model outputs, reproducing AI-specific vulnerabilities, and identifying visibility gaps.
- Develop detection-as-code frameworks with version control and automated deployment, onboard telemetry from AI infrastructure, and create dashboards for model security metrics.
- Collaborate with various teams as an operational security partner, translating threat research into production detections and enabling responsible AI development.
- Maintain a 24/7 on-call rotation for critical AI security incidents, responding to real-time threats and improving detection coverage and automation.
Requirements
- 3-5+ years in security operations, detection engineering, or incident response with a proven track record of stopping sophisticated attacks.
- 3+ years specifically securing AI/ML infrastructure, high-performance computing environments, or other distributed systems at scale.
- Strong programming skills in Python, KQL, SPL, or similar languages for building detection logic and automating response workflows.
- Experience with SIEM platforms, detection technologies, and forensic investigation techniques, including building detections for novel attack techniques.
- Self-directed execution mindset with experience securing high-value intellectual property and automating incident response in complex environments.
- Ability to identify critical security gaps through proactive threat hunting.
- Ability to connect across security, infrastructure, and AI research teams to build comprehensive defenses.
- Ability to challenge assumptions about security in AI systems.