Lead Cybersecurity Incident Response Engineer

CoreWeave

New York (NY)

On-site

USD 139,000 - 204,000

Full time

32 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, dental & vision insurance
401(k) with company match
Flexible PTO
Tuition Reimbursement
ESPP
Mental Wellness Benefits
Parental Leave
Flexible childcare support
Catered lunch
Casual work environment

Job summary

CoreWeave is seeking an experienced lead for our Advanced Response Team to own and drive the most critical security incidents from start to finish, coordinating across teams and reporting to senior leadership.

You will investigate, hunt threats across cloud and endpoint data, develop post-incident reviews, and design automation to harden environments, including AI-assisted tooling and structured simulations.

Qualifications

  • Extensive experience in incident response, security operations, and/or threat hunting.
  • Strong investigation and hunting skills, with hands-on data analysis.
  • Deep familiarity with attacker TTPs across cloud, endpoint, identity, and network.
  • Experience briefing senior leadership during active incidents with clarity.
  • Ability to lead across organizational boundaries while owning outcomes.
  • Proficiency in at least one query language (e.g., SQL, Splunk, HiveQL).
  • Ability to script or automate in Python, Go, or similar to close gaps.

Responsibilities

  • Lead the most complex, highest-severity cybersecurity incidents end-to-end with full ownership of outcomes.
  • Form hypotheses quickly from smoke and attack signals and shape strategy.
  • Brief senior leadership during active incidents with concise risk language.
  • Conduct deep investigations across endpoint, cloud, identity, and network data sources.
  • Deliver rigorous post-incident reviews and durable improvements.
  • Run a structured threat hunting program and translate findings into actions.
  • Architect and build AI-powered tooling to accelerate response and hunting workflows.

Skills

Incident response
Security operations
Threat hunting
Leadership briefing
Cross-functional collaboration
Query languages
Scripting (Python/Go)

Tools

Kubernetes

Job description

CoreWeave is seeking an experienced lead for our Advanced Response Team to own and drive the most critical security incidents from start to finish, coordinating across teams and reporting to senior leadership.

You will investigate, hunt threats across cloud and endpoint data, develop post-incident reviews, and design automation to harden environments, including AI-assisted tooling and structured simulations.

Get your free, confidential resume review.
or drag and drop your file here.