Security engineer, detection and response
Job Description
WRITER is hiring a staff-level Security engineer to build AI-focused detection and automated response for threats targeting the AI platform, training data, and model deployments.
Responsibilities
- Design and implement detection strategies for AI-specific threats, including prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training datasets or model weights across distributed infrastructure
- Build automated response playbooks and orchestration workflows to contain threats without human intervention, supporting self-healing security systems that reduce mean time to response from hours to minutes
- Remediate compromised inference endpoints through automated actions
- Coordinate security incident response across teams (Cloud, AppSec, Enterprise, AI Security) when AI infrastructure or models are compromised
- Conduct forensic investigations for training pipeline attacks and model manipulation attempts
- Draft clear incident communications for engineering and executive leadership
- Perform proactive threat hunting across GPU clusters and training infrastructure by analyzing model outputs, reproducing AI-specific vulnerabilities from research, and identifying visibility gaps in distributed training environments
- Create detection-as-code frameworks with version control and automated deployment
- Onboard telemetry from AI training infrastructure and inference endpoints
- Build dashboards tracking model security metrics, GPU utilization patterns, and access to sensitive research data
- Act as an operational security partner across teams by translating AI Security threat research into production detections and enabling responsible AI development through security guardrails
- Monitor Cloud Infrastructure GPU clusters for threats and support Software Security Engineering by detecting customer-impacting incidents
- Maintain a 24/7 on-call rotation for critical AI security incidents and continuously improve detection coverage and automation as AI systems evolve
Requirements
- 3-5+ years experience in security operations, detection engineering, or incident response with a track record of identifying and stopping sophisticated production attacks
- Experience securing AI/ML infrastructure, high-performance computing environments, or other distributed systems at scale
- Strong programming ability in Python and/or KQL and/or SPL to build custom detection logic, automate response workflows, and operationalize security across cloud-native and distributed computing environments
- Experience with SIEM platforms, detection technologies, and forensic investigation techniques
- Proven ability to build detections for novel attack techniques without established patterns and to conduct forensics in complex distributed environments
- Self-directed execution mindset focused on securing high-value intellectual property, automating incident response in complex environments, and proactively finding critical security gaps
- Strong alignment with WRITER values, including connecting across security, infrastructure, and AI research teams; challenging assumptions about AI security engineering; and owning protection of the AI platform with accountability
Technologies
- Python
- KQL
- SPL
- SIEM
Benefits
- Generous PTO plus company holidays
- Medical, dental, and vision coverage for you and your family
- Paid parental leave for all parents (16 weeks)
- Fertility and family planning support
- Early-detection cancer testing through Galleri
- Flexible spending account and dependent FSA options
- Health savings account for eligible plans with company contribution
- Annual work-life stipends for wellness and learning and development
- Company-wide off-sites and team off-sites
- Competitive compensation, company stock options, and 401k
Location: New York, NY (onsite)
Compensation: USD 132,000 - 240,000 per year