Security engineer, detection and response
Job Description
WRITER is hiring a staff-level detection and response engineer to help secure the AI platform. This role focuses on building AI-specific detection systems and automated response workflows for threats targeting the AI platform, training data, and model deployments, while coordinating incident response across engineering teams.
Location
- New York, NY (onsite)
Compensation
- USD 132,000 - 240,000 per year
Key Responsibilities
- Design and implement detection strategies for AI-specific threats, including prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training datasets or model weights across distributed infrastructure.
- Build automated response playbooks and orchestration workflows that contain threats without human intervention, creating self-healing security systems that reduce mean time to response from hours to minutes and automatically remediate compromised inference endpoints.
- Coordinate security incident response across Cloud, AppSec, Enterprise, and AI Security when AI infrastructure or models are compromised, including forensic investigations of training pipeline attacks and model manipulation attempts, and drafting incident communications for engineering and executive leadership.
- Proactively hunt for sophisticated threats across GPU clusters and training infrastructure by analyzing model outputs, reproducing AI-specific vulnerabilities from security research, and identifying visibility gaps in distributed training environments before adversaries exploit them.
- Develop detection-as-code frameworks with version control and automated deployment, onboard telemetry from AI training infrastructure and inference endpoints, and maintain dashboards tracking model security metrics, GPU utilization patterns, and access to sensitive research data.
- Serve as an operational security partner across teams by translating AI Security threat research into production detections, monitoring GPU clusters for threats, detecting customer-impacting incidents for Software Security Engineering, and enabling responsible AI development through security guardrails.
- Maintain a 24/7 on-call rotation for critical AI security incidents, responding to real-time threats and improving detection coverage and automation capabilities as AI systems evolve.
Required Experience
- 3-5+ years in security operations, detection engineering, or incident response with a demonstrated track record of identifying and stopping sophisticated attacks in production environments, specifically securing AI/ML infrastructure, high-performance computing environments, or other distributed systems at scale.
Required Skills
- Strong programming skills in Python, KQL, SPL, or similar languages to build custom detection logic, automate response workflows, and operationalize security at scale in cloud-native and distributed computing environments.
- Experience with SIEM platforms, detection technologies, and forensic investigation techniques, including building detection for novel attack techniques without established patterns and conducting forensics in complex distributed environments.
- Self-directed execution with a track record of securing high-value intellectual property, automating incident response in complex environments, and proactively identifying critical security gaps through threat hunting.
- Strong alignment with WRITER values, including cross-team collaboration across security, infrastructure, and AI research, challenging assumptions in AI security engineering, and maintaining accountability for protecting the AI platform while keeping pace with evolving threats.
Technologies
- Python
- KQL
- SPL
- SIEM
Benefits
- Generous PTO plus company holidays
- Medical, dental, and vision coverage for you and your family
- Paid parental leave for all parents (16 weeks)
- Fertility and family planning support
- Early-detection cancer testing through Galleri
- Flexible spending account and dependent FSA options
- Health savings account for eligible plans with company contribution
- Annual work-life stipends for wellness (gym, massage/chiropractor, personal training, etc.) and learning and development
- Company-wide off-sites and team off-sites
- Competitive compensation, company stock options, and 401k
About the Role
- Join WRITER’s security team as a staff detection and response engineer to protect the AI infrastructure transforming how the world works.
- Build sophisticated detection systems for attacks targeting the AI platform, training data, and model deployments, along with automated response capabilities that scale.
- Combine hands-on security engineering with strategic thinking to address emerging threats that are not well-established.
- Translate threat intelligence into real-time detections, coordinate incident response across multiple teams, and conduct threat hunting across GPU clusters and distributed training environments.
- Work with AI Security research, Cloud Infrastructure, Software Security Engineering, and AI researchers to support defense-in-depth for a high-value AI platform.
- Reporting line: head of security operations. This role is open with a location based in the San Francisco or Seattle office.
- WRITER is open to hiring at multiple levels, with compensation ranges scaled to experience, expertise, and scope.