Senior Detection and Response Engineer

Posted 8 Days Ago
Be an Early Applicant
San Francisco, CA, USA
In-Office
200K-240K Annually
Senior level
Artificial Intelligence • Software
The Role
Own detection engineering and incident response across corporate and production environments. Build cloud, endpoint, container, runtime, correlation, and alerting capabilities; lead live incidents; develop and exercise response runbooks; tune detections; measure detection and response performance; conduct retrospectives; and partner with infrastructure security and IT to address identified gaps.
Summary Generated by Built In

At Anyscale, we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We’re commercializing Ray, a popular open-source project that's creating an ecosystem of libraries for scalable machine learning. Companies like OpenAI, Uber, Spotify, Instacart, Cruise, and many more, have Ray in their tech stacks to accelerate the progress of AI applications out into the real world.

With Anyscale, we’re building the best place to run Ray, so that any developer or data scientist can scale an ML application from their laptop to the cluster without needing to be a distributed systems expert.

Proud to be backed by Andreessen Horowitz, NEA, and Addition with $250+ million raised to date.

About the Role

Anyscale's need to detect and respond to security events across its production and corporate environments is growing as the company scales. We're looking for a Senior Detection and Response Engineer to own detection engineering and to lead incident response when it counts, coordinating the response and driving it to resolution.

This is a high-ownership role with real room to shape how detection and response works at Anyscale. You will own the detection pipeline, the response runbooks, and incident response, reporting to the Head of Security and partnering with engineering. This role is based in India.

In your first year, success looks like strong detection coverage across our cloud, endpoint, and runtime telemetry, a working correlation and alerting pipeline, and incident response runbooks that have been exercised in practice.

What You'll Do
  • Own and build detection coverage across cloud, endpoint, and runtime telemetry.

  • Own a centralized correlation and alerting capability that turns telemetry into actionable detections.

  • Own incident response: runbooks, escalation paths, and coordination during an incident, across corporate and production environments.

  • Drive detection of anomalous activity across the environments we run, including our Kubernetes footprint.

  • Tune detections to keep signal high and noise low, and measure detection and response performance such as mean time to detect and respond.

  • Run incident retrospectives and feed lessons back into detections and controls.

  • Partner with infrastructure security and IT to close gaps surfaced during response.

What You'll Bring
  • 6+ years in security, with a strong focus on detection engineering and incident response, ideally at a high-growth startup.

  • Hands-on experience building detections and correlation across cloud (AWS, Azure), endpoint (EDR), and ideally container and runtime telemetry.

  • Experience owning incident response end to end, including leading during live incidents.

  • Comfort building and scaling a detection and response capability, not only operating an existing one.

  • Sound judgment under pressure and clear communication during incidents.

  • Fluency working with engineers and IT to close the gaps that response surfaces.

Nice to Have
  • Experience with SIEM or detection platforms and detection-as-code approaches.

  • Familiarity with runtime security tooling such as Upwind or similar.

  • Threat hunting or purple-team experience.

  • Background in AI or ML platforms or distributed systems.

Skills Required

  • 6+ years of experience in security, with a strong focus on detection engineering and incident response
  • Hands-on experience building detections and correlation across AWS or Azure cloud environments
  • Hands-on experience with endpoint detection and response telemetry
  • Experience with container and runtime telemetry
  • Experience owning incident response end to end, including leading live incidents
  • Experience building and scaling a detection and response capability
  • Sound judgment under pressure and clear communication during incidents
  • Ability to work effectively with engineering and IT teams to close security gaps
  • Experience with SIEM or detection platforms and detection-as-code approaches
  • Familiarity with runtime security tooling such as Upwind or similar
  • Threat hunting or purple-team experience
  • Background in AI or ML platforms or distributed systems

Anyscale Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Anyscale and has not been reviewed or approved by Anyscale.

  • Fair & Transparent Compensation Pay is considered market-based with target ranges shown in postings and a stated market-based philosophy. Feedback suggests this clarity and consistency aid confidence in pay fairness.
  • Equity Value & Accessibility Equity is commonly included in offers and is positioned as a meaningful part of total compensation for many roles. Feedback suggests this equity participation enhances perceived overall pay competitiveness.
  • Healthcare Strength Health, dental, and vision coverage are described as robust with many plan options, alongside mental-health support and fertility benefits. Feedback suggests this strong core healthcare offering increases perceived benefits quality.

Anyscale Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
115 Employees
Year Founded: 2019

What We Do

Distributed computing made simple Anyscale enables developers of all skill levels to easily build applications that run at any scale, from a laptop to a data center.

Similar Jobs

Klaviyo Logo Klaviyo

Senior Security Engineer

Consumer Web • eCommerce • Marketing Tech • Retail • Software • Analytics • Generative AI
Easy Apply
Hybrid
San Francisco, CA, USA
2400 Employees
142K-212K Annually

CrowdStrike Logo CrowdStrike

Full-stack Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Hybrid
Sunnyvale, CA, USA
11000 Employees
160K-250K Annually

CrowdStrike Logo CrowdStrike

Senior Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Hybrid
Sunnyvale, CA, USA
11000 Employees
140K-215K Annually

CrowdStrike Logo CrowdStrike

Senior Full-stack Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Hybrid
Sunnyvale, CA, USA
11000 Employees
140K-215K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account