Senior Detection and Response Engineer
Anyscale · San Francisco
About this role
## Senior Detection and Response Engineer ### About Anyscale At Anyscale, we’re on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We’re commercializing **Ray**, an open-source project that helps build an ecosystem for scalable machine learning—so developers and data scientists can scale from laptop to cluster without needing to be distributed-systems experts. ### About the Role As Anyscale scales, the need to **detect and respond to security events** across production and corporate environments is growing. You’ll own **detection engineering** and **lead incident response** when it matters—coordinating the response and driving it to resolution. This is a **high-ownership role** with real room to shape how detection and response works at Anyscale. You’ll own the **detection pipeline**, **response runbooks**, and **incident response**, reporting to the **Head of Security** and partnering with engineering. **Location:** India **In your first year, success looks like:** - Strong detection coverage across **cloud, endpoint, and runtime telemetry** - A working **correlation and alerting pipeline** - Incident response **runbooks exercised in practice** ### What You’ll Do - Own and build **detection coverage** across **cloud, endpoint, and runtime telemetry** - Own a centralized **correlation and alerting** capability that turns telemetry into actionable detections - Own **incident response**: runbooks, escalation paths, and coordination during incidents across corporate and production environments - Drive detection of **anomalous activity**, including across the **Kubernetes** footprint - Tune detections to keep **signal high** and **noise low**, and measure performance (e.g., **MTTD/MTTR**) - Run **incident retrospectives** and feed lessons back into detections and controls - Partner with **infrastructure security** and **IT** to close gaps surfaced during response ### What You’ll Bring - **6+ years** in security, with strong focus on **detection engineering** and **incident response** (ideally at a high-growth startup) - Hands-on experience building detections/correlation across: - **Cloud** (AWS, Azure) - **Endpoint** (EDR) - Ideally **container and runtime telemetry** - Experience owning **incident response end to end**, including leading during live incidents - Comfort building and scaling a detection/response capability (not just operating an existing one) - Sound judgment under pressure and clear communication during incidents - Fluency working with engineers and IT to close gaps uncovered during response ### Nice to Have - Experience with **SIEM** or detection platforms and **detection-as-code** approaches - Familiarity with runtime security tooling such as **Upwind** (or similar) - Threat hunting or **purple-team** experience - Background in **AI/ML platforms** or **distributed systems**
Listing freshness
CronJobs last confirmed this listing 23h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.