As a Senior Security Operations Engineer I, you will independently lead the investigation and response to complex security events and incidents. You will serve as an escalation point for other analysts, contribute to the development of detections and automation, and help improve the processes and tooling that support our growing security operations program.
In this role, you will:
- Participate in a 24/7/365 SOC, including rotating on-call coverage for overnights and weekends.
- Independently investigate and respond to complex security events across Linux, macOS, cloud, and Kubernetes environments.
- Determine the scope, impact, severity, and appropriate escalation path for potential security incidents.
- Coordinate containment and remediation activities with security, engineering, infrastructure, and operations teams.
- Utilize and query SIEM, EDR, and other security tools to identify suspicious activity and develop actionable findings.
- Create and improve detections-as-code, investigation procedures, automation, runbooks, and response workflows.
- Perform post-incident reviews and recommend improvements to security controls and response capabilities.
- Partner with threat intelligence and detection engineering teams to prepare for emerging threats and address gaps in coverage.
- Serve as an escalation point and mentor for junior engineers, providing guidance during investigations and reviewing their work.
- Lead scoped operational and technical improvement projects that increase the effectiveness and scalability of the SOC.
- 3–5+ years of experience in security operations, incident response, digital forensics, detection engineering, or a related field.
- Strong experience investigating and responding to security events with limited or incomplete information.
- Strong working knowledge of Linux and macOS systems, including system internals, logging, and common forensic artifacts.
- Experience investigating Kubernetes or container security events.
- Proficiency with modern security tools and platforms, including SIEM, EDR, IDS/IPS, and firewalls.
- Strong understanding of network protocols, VPNs, proxies, identity systems, and other security technologies.
- Experience developing or tuning security detections, preferably using detections-as-code.
- Ability to manage complex investigations, communicate risk clearly, and make sound decisions in high-pressure situations.
- Experience mentoring less-experienced engineers and collaborating effectively across teams and time zones.
- Degree in Computer Science, Computer Engineering, Cyber Security, Information Technology, or equivalent practical experience.
- Experience securing cloud infrastructure or large-scale production environments.
- Experience using Python or another scripting language to automate security workflows.
- Familiarity with incident response in Kubernetes-based infrastructure.
- Experience collaborating with detection engineering, threat intelligence, or software engineering teams.
- A demonstrated commitment to staying current with emerging threats, security technologies, and industry best practices.
The base salary range for this role is $134,000 to $179,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).
What We Offer
The range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.
In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings for full-time employees; for roles in other locations, benefits vary and are shared during the hiring process. These include:
- Medical, dental, and vision insurance - 100% paid for by CoreWeave
- Company-paid Life Insurance
- Voluntary supplemental life insurance
- Short and long-term disability insurance
- Flexible Spending Account
- Health Savings Account
- Tuition Reimbursement
- Ability to Participate in Employee Stock Purchase Program (ESPP)
- Mental Wellness Benefits through Spring Health
- Family-Forming support provided by Carrot
- Paid Parental Leave
- Flexible, full-service childcare support with Kinside
- 401(k) with a generous employer match
- Flexible PTO
- Catered lunch each day in our office and data center locations
- A casual work environment
- A work culture focused on innovative disruption
California Applicants
California Consumer Privacy Act
Equal Opportunity & Accommodations
CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.
As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: [email protected].
Export Control Compliance
This position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the export controlled information without a required export authorization, or (C) eligible and reasonably likely to obtain the required export authorization from the applicable U.S. government agency. CoreWeave may, for legitimate business reasons, decline to pursue any export licensing process.
Skills Required
- 3-5+ years of experience in security operations, incident response, digital forensics, detection engineering, or a related field
- Strong experience investigating and responding to security events with limited or incomplete information
- Strong working knowledge of Linux and macOS systems, system internals, logging, and common forensic artifacts
- Experience investigating Kubernetes or container security events
- Proficiency with SIEM, EDR, IDS/IPS, firewalls, and other security tools and platforms
- Strong understanding of network protocols, VPNs, proxies, identity systems, and security technologies
- Experience developing or tuning security detections, preferably using detections-as-code
- Ability to manage complex investigations, communicate risk clearly, and make sound decisions under pressure
- Experience mentoring less-experienced engineers and collaborating across teams and time zones
- Degree in Computer Science, Computer Engineering, Cyber Security, Information Technology, or equivalent practical experience
- Experience securing cloud infrastructure or large-scale production environments
- Experience using Python or another scripting language to automate security workflows
- Familiarity with incident response in Kubernetes-based infrastructure
- Experience collaborating with detection engineering, threat intelligence, or software engineering teams
- Commitment to staying current with emerging threats, security technologies, and industry best practices
- Must satisfy U.S. export-control access requirements or qualify for applicable export authorization
CoreWeave Compensation & Benefits Highlights
-
Healthcare Strength — Offerings include medical, dental, and vision coverage with employer-paid employee premiums cited for U.S. full-time staff, plus mental-health resources such as Spring Health and Calm. Feedback suggests this combination makes healthcare a standout element of the package.
-
Parental & Family Support — Paid parental leave, fertility/family-forming support through Carrot, and childcare assistance via Kinside are emphasized. These benefits indicate strong support for caregiving and family planning needs.
-
Equity Value & Accessibility — An Employee Stock Purchase Plan with a discounted purchase price is available to eligible U.S. employees, alongside equity/stock options in many roles. This structure offers accessible ownership potential in addition to salary and traditional benefits.
CoreWeave Insights
What We Do
CoreWeave, the AI Hyperscaler™, delivers a cloud platform of cutting-edge software powering the next wave of AI. The company's technology provides enterprises and leading AI labs with cloud solutions for accelerated computing. Since 2017, CoreWeave has operated a growing footprint of data centers across the US and Europe. CoreWeave was ranked as one of the TIME100 most influential companies and featured on Forbes Cloud 100 ranking in 2024. Learn more at www.coreweave.com.
Why Work With Us
At CoreWeave we work hard, have fun and move fast! Today we are a small, growing team of intelligent, genuine people, that value different perspectives and approaches to solving complex problems. We foster an environment that champions collaboration and prioritizes innovative solutions. Here, you are surrounded by the best.
Gallery
CoreWeave Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.