Partner 34, Lead Engineer, Incident Response

Andreessen Horowitz

San Francisco (CA)

On-site

USD 180,000 - 250,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Andreessen Horowitz seeks a Lead Engineer, Incident Response to lead and shape a16z's detection and response program. This hands-on role emphasizes investigations, detections, automation, and coaching engineers toward technical excellence.

You will span cloud, SaaS, identity, and endpoint environments, shaping roadmaps, tooling, threat hunting, and response practices while coordinating with IT, Legal, and Compliance. In-office presence is required two days a week in San Francisco.

Qualifications

  • 9+ years in incident response or detection with cloud focus.
  • Track record leading detection and response programs across cloud/SaaS/identity.
  • Experience managing security engineers with coaching and performance feedback.
  • Strong detection engineering skills and incident response automation.

Responsibilities

  • Set the detection and response roadmap, prioritizing threats and measuring coverage.
  • Lead and develop engineers through coaching, feedback, and technical reviews.
  • Develop the team's ability to respond from triage through containment and recovery.
  • Maintain and test response playbooks and escalation criteria.
  • Design and improve SIEM architecture and security logging across cloud/identity/endpoint.
  • Run threat hunts informed by threat intelligence and investigations.
  • Build and improve brand protection capabilities (impersonation/fraud).
  • Build AI-assisted response automation and define human approvals.
  • Keep stakeholders aligned during incidents and communicate impact and options.
  • Lead postmortems and drive corrective actions to completion.

Skills

Incident response leadership
Cloud incident response
Mentoring/coaching
Detection engineering
Threat hunting tooling

Tools

SIEM
EDR
MITRE ATT&CK
Playbooks

Job description

The Role

We're hiring a Lead Engineer, Incident Response to lead and shape a16z's detection and response team. This is a hands-on role: you'll spend a significant portion of your time investigating incidents, writing and reviewing detections, building automation, and making the harder technical response decisions. You'll also manage and develop the engineers on the team.


You'll build and improve detection and response capabilities across the firm's cloud, SaaS, identity, and endpoint environments, shaping the roadmap, tooling, threat hunting, and response practices. You'll also develop capabilities to protect the firm against impersonation and fraud. You'll work closely with Security Engineering, IT, Legal, Compliance, and other cross-functional teams to put these capabilities into practice and turn lessons from incidents into better detections, tooling, and controls.


Venture capital firms face threats that extend beyond their infrastructure: capital call wire fraud, impersonation, and social engineering against employees and partners, alongside attacks by organized criminal and nation-state groups. Your work protects sensitive firm and limited partner (LP) information, financial transactions, and the relationships the firm depends on.


This role requires an in-office presence 2 days a week in our San Francisco, CA office.


To join our team, you should be excited to:


  • Set the detection and response roadmap, prioritizing the threats that matter most to the firm and measuring detection coverage, alert quality, and response effectiveness

  • Lead and develop engineers through coaching, feedback, performance management, and technical reviews, working alongside them on investigations and engineering projects

  • Develop the team's ability to respond from triage through containment, eradication, and recovery, including vendor incidents. Lead major incidents, coordinate a16z's technical response with system owners and affected providers, and elevate decisions requiring leadership or Legal approval

  • Maintain and test response playbooks and escalation criteria through cross-functional tabletop exercises and incident simulations

  • Design and improve SIEM architecture and security logging with Security Engineering and IT, expanding detection coverage across cloud, identity, and endpoint environments, including EDR. Write, review, test, and tune detections as code, using relevant MITRE ATT&CK techniques to assess coverage and working with system owners to close visibility gaps

  • Run hypothesis-driven threat hunts informed by threat intelligence and prior investigations, turning findings into new detections

  • Build and improve brand protection capabilities including monitoring, investigation, and takedowns of lookalike domains, fraudulent websites, and social media accounts

  • Build AI-assisted response automation. Evaluate accuracy and reliability before deployment and define where human judgment and approvals are required

  • Keep technical and non-technical stakeholders aligned during incidents, including IT, Legal, Compliance, Finance, and investing teams. Clearly communicate impact, uncertainty, response options, and next steps

  • Develop the team's postmortem practices, lead reviews of root causes and contributing factors, and drive corrective actions to completion with the teams responsible for remediation

  • Participate in the Security team's on-call rotation


Minimum Qualifications


  • 9+ years of incident response or detection and response experience, or equivalent demonstrated impact, with depth in cloud incident response across AWS and GCP

  • Prior experience managing security engineers, including coaching and performance management, while remaining technically hands-on

  • A track record of building and leading detection and response programs, making architecture and prioritization decisions, and delivering measurable improvements

  • Experience leading high- stakes incidents across cloud, SaaS, identity, and endpoint environments, including forensic investigation, containment, recovery, and postmortems

  • Strong detection engineering skills, including SIEM query langua

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Partner 34, Lead Engineer, Incident Response
Partner 34, Lead Engineer, Incident Response

Theblockchainassociation • San Francisco (CA)

Hybrid
USD 295,000 - 347,000
Health insurance
Dental insurance
Vision insurance
+2
Partner 34, Lead Engineer, Incident Response
Partner 34, Lead Engineer, Incident Response

A16z • San Francisco (CA)

Hybrid
USD 295,000 - 347,000
Health insurance
Dental insurance
Vision insurance
+5
Lead Incident Response Engineer — Build Detection & Response
Lead Incident Response Engineer — Build Detection & Response

Andreessen Horowitz • San Francisco (CA)

On-site
USD 180,000 - 250,000
Lead Incident Response Engineer, Cloud & Threat Detection
Lead Incident Response Engineer, Cloud & Threat Detection

Theblockchainassociation • San Francisco (CA)

Hybrid
USD 295,000 - 347,000
Health insurance
Dental insurance
Vision insurance
+2
Lead Incident Response Engineer: Cloud & Identity
Lead Incident Response Engineer: Cloud & Identity

A16z • San Francisco (CA)

Hybrid
USD 295,000 - 347,000
Health insurance
Dental insurance
Vision insurance
+5
Partner 20, Staff Security Engineer, AI & Security Platform
Partner 20, Staff Security Engineer, AI & Security Platform

Andreessen Horowitz • San Francisco (CA)

On-site
USD 243,000 - 284,000
Health insurance
Dental insurance
Vision insurance
+5
Partner 20, Staff Security Engineer, AI & Security Platform
Partner 20, Staff Security Engineer, AI & Security Platform

Andreessen Horowitz (a16z) • San Francisco (CA), Northern (KY)

On-site
USD 243,000 - 284,000
Carry program
Health insurance
Dental insurance
+4
Partner 20, Staff Engineer, Enterprise Security
Partner 20, Staff Engineer, Enterprise Security

Theblockchainassociation • San Francisco (CA)

Hybrid
USD 243,000 - 284,000
Health insurance
Dental insurance
Vision insurance
+6
Partner 20, Staff Engineer, Enterprise Security
Partner 20, Staff Engineer, Enterprise Security

A16z • San Francisco (CA)

On-site
USD 243,000 - 284,000
Health insurance
Dental insurance
Vision insurance
+7
Detection and Response Engineer
Detection and Response Engineer

Modal Labs • New York (NY)

On-site
USD 140,000 - 190,000