Lead Incident Response Engineer, Cloud & Threat Detection

Theblockchainassociation

San Francisco (CA)

Hybrid

USD 295,000 - 347,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
401K
Vacation policy

Job summary

Andreessen Horowitz (a16z) is hiring a Lead Engineer, Incident Response to lead and shape the detection and response team. This hands-on role involves investigating incidents, writing detections, building automation, and developing engineers.

You will shape capabilities across cloud, SaaS, identity, and endpoint environments and protect the firm from impersonation and fraud. This role requires in-office presence 2 days a week in our San Francisco, CA office, and offers a salary range tied to

Qualifications

  • 9+ years of incident response or detection experience with cloud (AWS/GCP).
  • Experience leading security engineers and mentoring teams.
  • Proven track record delivering measurable improvements in detection and response.

Responsibilities

  • Set the detection and response roadmap, prioritizing threats that matter and measuring coverage.
  • Lead and develop engineers through coaching, feedback, and reviews on investigations.
  • Develop the team's ability to respond from triage through containment, eradication, and recovery.
  • Maintain and test response playbooks and escalation criteria via tabletop exercises.
  • Design and improve SIEM architecture and security logging across cloud/identity/endpoint.
  • Run hypothesis-driven threat hunts and turn findings into detections.
  • Build brand protection capabilities including takedowns of lookalike domains and fraud.
  • Build AI-assisted response automation with human-oversight requirements.
  • Keep stakeholders aligned and clearly communicate impact and options.
  • Lead postmortems and drive corrective actions with remediation teams.
  • Participate in Security team's on-call rotation.

Skills

Incident response
Detection engineering
Python
Leadership
Communication
Cross-functional
Threat hunting
Automation
Cloud security
SOAR

Tools

SIEM
KQL
Sigma
EDR
SOAR
Cloud logs

Job description

Andreessen Horowitz (a16z) is hiring a Lead Engineer, Incident Response to lead and shape the detection and response team. This hands-on role involves investigating incidents, writing detections, building automation, and developing engineers.

You will shape capabilities across cloud, SaaS, identity, and endpoint environments and protect the firm from impersonation and fraud. This role requires in-office presence 2 days a week in our San Francisco, CA office, and offers a salary range tied to

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Incident Response Engineer — Build Detection & Response
Lead Incident Response Engineer — Build Detection & Response

Andreessen Horowitz • San Francisco (CA)

On-site
USD 180,000 - 250,000
Lead Incident Response Engineer: Cloud & Identity
Lead Incident Response Engineer: Cloud & Identity

A16z • San Francisco (CA)

Hybrid
USD 295,000 - 347,000
Health insurance
Dental insurance
Vision insurance
+5
Partner 34, Lead Engineer, Incident Response
Partner 34, Lead Engineer, Incident Response

Andreessen Horowitz • San Francisco (CA)

On-site
USD 180,000 - 250,000
Partner 34, Lead Engineer, Incident Response
Partner 34, Lead Engineer, Incident Response

a16z • San Francisco (CA)

On-site
USD 295,000 - 347,000
Health insurance
Dental insurance
Vision insurance
+2
Partner 34, Lead Engineer, Incident Response
Partner 34, Lead Engineer, Incident Response

A16z • San Francisco (CA)

Hybrid
USD 295,000 - 347,000
Health insurance
Dental insurance
Vision insurance
+5
Threat Detection & Response Engineer: Incident Leader
Threat Detection & Response Engineer: Incident Leader

Whatnot • San Francisco (CA)

Hybrid
USD 175,000 - 260,000
Health Insurance (Medical, Dental, Vis
Work From Home Support
Home office setup allowance
+5
Staff Security Engineer, AI-Driven Platform Automation
Staff Security Engineer, AI-Driven Platform Automation

Andreessen Horowitz • San Francisco (CA)

On-site
USD 243,000 - 284,000
Health insurance
Dental insurance
Vision insurance
+5
Senior Threat Detection & Incident Response Engineer
Senior Threat Detection & Incident Response Engineer

Altruist • San Francisco (CA), Northern (KY)

Hybrid
USD 200,000 - 240,000
Competitive total compensation
Premium healthcare, dental, and vision
401k with 4% match
+4
Security Engineer
Security Engineer

Atlas Search • New York (NY)

On-site
USD 140,000 - 190,000
Senior Incident Response Leader | Threat Hunting & Detection
Senior Incident Response Leader | Threat Hunting & Detection

Peraton Labs • United States

On-site
USD 104,000 - 166,000
Medical coverage
Dental coverage
Vision coverage
+7