Partner 20, Staff Engineer, Incident Response

P2P

San Francisco (CA)

On-site

USD 243,000 - 284,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
401K plan
Vacation
Sick leave

Job summary

P2P is hiring a Senior Incident Response Engineer in San Francisco to lead incident triage and response across AWS and GCP. In this role, you will protect the firm from threats like capital call wire fraud and organized criminal operations. Candidates should have over 5 years of incident response experience and be skilled in detection authoring and Python scripting.

The anticipated salary range is $243,000 - $284,000 with additional benefits including participation in various bonus programs and health insurance.

Qualifications

  • 5+ years of incident response experience or equivalent demonstrated impact.
  • Experience leading live incidents end to end across various surfaces.
  • Hands-on detection authoring and experience with detection-as-code.

Responsibilities

  • Run incidents end to end across cloud and SaaS environments.
  • Write detections with a strong bias toward signal over noise.
  • Drive post-mortems that lead to operational change.

Skills

Incident response experience
Cloud IR depth across AWS and GCP
Detection authoring in modern SIEM platforms
Strong Python scripting
Proactive threat hunting
Experience defending against nation-state actors

Education

GCIH or equivalent IR certification

Tools

Sigma
KQL

Job description

The Role

We're hiring a Senior Incident Response Engineer to anchor a16z's detection and response work. You'll own incident triage and response across AWS and GCP, write the detections that catch real threats in our SIEM, and run point when something serious happens.

The threats here are not theoretical. We see capital call wire fraud attempts, vishing campaigns, social engineering against IT and partners, and occasionally more sophisticated actors (nation-state groups, organized criminal operations) who specifically target venture capital firms. Your work protects the firm, our LPs, and our portfolio companies. You'll work day to day with the Head of Cybersecurity, Security Engineering, IT, and Legal.

This role requires an in-office presence 2 days a week in our San Francisco, CA office.

To join our team, you should be excited to:
  • Run incidents end to end, from first alert to post-mortem, across cloud and SaaS environments
  • Write the detections that catch real threats, with a strong bias toward signal over noise and broad MITRE ATT&CK coverage
  • Help shape the next generation of our SOC, including AI agent integration into triage and response workflows
  • Partner across the firm during incidents: investing teams, Legal, Compliance, Finance, IT, and firm leadership all get pulled in, and this role keeps every audience aligned under pressure
  • Drive post-mortems that lead to operational change, not process for its own sake
  • Work against real adversaries, including nation-state groups, organized criminal operations, and threat actors who specifically target venture capital firms
Minimum Qualifications
  • 5+ years of incident response experience or equivalent demonstrated impact, with cloud IR depth across both AWS and GCP
  • Experience leading live incidents end to end — triage, containment, eradication, forensic investigation, and post-mortem — across cloud, SaaS, identity, and endpoint surfaces
  • Experience running proactive, hypothesis-driven threat hunts using current TTPs and intel
  • Hands‑on detection authoring in modern SIEM platforms (Sigma, KQL, or equivalent) and experience working with detection‑as‑code
  • Experience building detection frameworks and contributing to SIEM architecture decisions
  • Strong Python scripting. This is a role where you build automation, not one where you only operate someone else's
  • Demonstrated capability across modern security tooling categories (cloud telemetry, EDR, SOAR, SIEM). We weight transferable capability over experience with any specific product
  • GCIH or equivalent IR certification preferred
  • Comfortable in a fast-moving environment where security is expected to enable the business
  • Experience defending against nation-state threat actors or organized criminal groups
  • Working knowledge of AI/agent systems and their security implications, particularly in SOC workflows
  • Experience translating the technical reality of an incident (blast radius, containment status, disclosure decisions) into language non-technical stakeholders can act on.
  • Low ego, high empathy, and the capacity to collaborate effectively with diverse teams

The anticipated salary range for this role is between $243,000 - $284,000, actual starting pay may vary based on a range of factors which can include experience, skills, and scope.

This role is eligible to participate in the a16z carry program and various discretionary bonus programs as well as benefit and perquisite plans including health, dental, vision, disability, life insurance, 401K plan, vacation, and sick leave.

Our organization participates in E-Verify.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Partner 20, Staff Engineer, Security Automation
Partner 20, Staff Engineer, Security Automation

P2P • San Francisco (CA)

Hybrid
USD 243,000 - 284,000
Health insurance
401K plan
Paid vacation
+1
Incident Response Lead
Incident Response Lead

United States Digital Space LLC • Boston (MA)

On-site
USD 130,000 - 170,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • Washington

On-site
USD 237,000 - 297,000
Comprehensive health, dental, vision coverage
Retirement benefits
Learning and development stipend
+2
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • New York (NY)

On-site
USD 237,000 - 297,000
Comprehensive health coverage
Equity options
Paid time off
+2
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • San Francisco (CA)

On-site
USD 237,000 - 297,000
Health benefits
Retirement benefits
Learning and development stipend
+2
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • Seattle (WA)

On-site
USD 237,000 - 297,000
Comprehensive health benefits
Retirement benefits
Learning and development stipend
+2
Security Incident Response Engineer
Security Incident Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 125,000 - 165,000
Senior Security Engineer, Detection and Response
Senior Security Engineer, Detection and Response

hackerone • Boston (MA)

Remote
USD 182,000 - 202,000
Health (medical, vision, dental), life, and disability insurance
Equity stock options
Unlimited PTO
+2
Incident Response Lead
Incident Response Lead

ECS • Washington

Hybrid
USD 140,000 - 150,000
Security Engineer, Incident Response
Security Engineer, Incident Response

United States Digital Space LLC • New York (NY)

On-site
USD 120,000 - 180,000