Principal Incident Responder

Fluidstack

Austin (TX)

On-site

USD 330,000 - 380,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Fluidstack is seeking a seasoned Incident Response Lead to secure our frontier compute infrastructure across corporate, cloud, and data center environments. You will own end-to-end IR from detection to eradication, drive cross‑team investigations, and define severity models and on‑call rotations as we scale.

You will build detection logic, response playbooks, and forensic tooling for high‑value targets like AI workloads.

Qualifications

  • Led major security incidents from first alert to resolution under pressure.
  • Built detection logic and response playbooks that caught real intrusions.
  • Conducted digital forensics across cloud, endpoint, and network evidence.
  • Turned incidents into permanent improvements by partnering with security and IT teams.

Responsibilities

  • Lead incident response end-to-end across corporate, cloud, and data center environments from detection to eradication and post-incident review.
  • Build detection logic, response playbooks, and forensic tooling for the frontier compute environment.
  • Run investigations across cloud, endpoint, network and physical systems to form a unified threat view.
  • Stand up the incident response function from ground up with defined severity models and on-call rotations.
  • Turn each incident into a permanent improvement by closing gaps surfaced by investigations.

Skills

Led major incidents
Detection logic
Digital forensics
Incident response program
Threat hunting
Incident reports

Tools

SIEM
SOAR
AWS
GCP

Job description

About Fluidstack

We exist to make humanity more free. For most of human history, you farmed or you starved. Technology gave people more time for the things they wanted to do, instead of things they had to do. Powerful AI will be the biggest lever for human choice we've ever built - but only if models are aligned with what humanity actually wants. There are groups building AI who don't share these goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands human freedom or shrinks it.

We’re singularly focused on delivering 10 to 100s of GWs of compute faster than anyone else, rethinking every layer of the stack. We acquire power, design and build data centers, and operate them - with teams spanning hardware and software. Speed and scale are our key differentiators. Come be a part of building civilization‑scale infrastructure for AI.

We hire people who care deeply about this problem space. If that is you, please apply!

How We Operate
  • Extreme ownership. Full autonomy. Own things end to end often taking on scope outside your core role without being asked to get things done.
  • Velocity. We drive everything forward as fast as possible.
  • First principles. Challenge every assumption. Zero analogy thinking, no egos, the best idea wins.
  • Love of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward.
The Security Team
  • Examples of key problems the team is working on.
  • You're securing the frontier of AI. The model weights training on our infrastructure are the most valuable and most targeted artifacts in technology, and we're standing up the compute to hold them faster than anyone ever has. A breach isn't a leak, it's the frontier walking out the door.
  • Build the entire security program from scratch. Most leaders inherit someone else's system and spend a career patching it. Here you own it end to end, bare metal to boardroom, as we scale across continents.
  • Your threat surface is measured in gigawatts. The customers running on our infrastructure are building the most consequential technology in human history, and being responsible for the physical and logical security of that work makes everything else feel small.
Role Scope
  • Lead incident response end to end across corporate, cloud, and data center environments, from detection and containment through eradication and post‑incident review.
  • Build the detection logic, response playbooks, and forensic tooling for an environment where the assets under threat are the most targeted model weights in technology.
  • Run investigations across a threat surface measured in gigawatts, correlating signals from cloud, endpoint, network, and physical systems into a single picture of an attack.
  • Stand up the incident response function from the ground up, defining severity models, on‑call rotations, and the escalation path to leadership.
  • Turn each incident into a permanent improvement by partnering with the security and IT teams to close the gaps your investigations surface.
What We’re Looking For
  • The below is a starting point. We always make space for exceptional people, so if you don't fit this role exactly, tell us where you would.
  • You've personally led major security incidents from first alert to resolution, making containment calls under pressure with the business watching.
  • You've built detection logic and response playbooks that caught real intrusions, not just theoretical ones.
  • You've run digital forensics across cloud, endpoint, and network evidence and reconstructed what an attacker actually did.
  • You've stood up or substantially rebuilt an incident response program rather than only operating inside someone else's.
  • You've hunted for threats proactively and found activity that existing tooling missed.
  • You write incident reports and postmortems clear enough that both engineers and executives act on them.
  • Bonus: Experience defending high‑value targets such as AI labs, financial infrastructure, or critical infrastructure against nation‑state threat models. Cloud‑native forensics (AWS, GCP). Detection engineering and SIEM or SOAR tooling. Malware analysis or reverse engineering.

We are committed to pay equity and transparency.

Fluidstack is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, and protected veterans’ status, or any other characteristic protected by law. Fluidstack will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

Compensation Range: $330K – $380K

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Incident Responder
Principal Incident Responder

Fluidstack • New York (NY)

On-site
USD 330,000 - 380,000
Principal Incident Responder
Principal Incident Responder

Fluidstack • Seattle (WA)

On-site
USD 330,000 - 380,000
Incident Response Manager
Incident Response Manager

Fluidstack • Seattle (WA)

On-site
USD 182,000 - 224,000
Equity
Health insurance
Generous PTO
Incident Response Manager
Incident Response Manager

Fluidstack • Austin (TX)

On-site
USD 218,000 - 269,000
Equity
Retirement plan
Health, dental, vision
+1
Incident Response Manager
Incident Response Manager

Fluidstack • San Francisco (CA)

On-site
USD 180,000 - 240,000
Health, dental, and vision insurance
Retirement plan
Generous PTO
Senior Detection Engineer
Senior Detection Engineer

Fluidstack • Austin (TX)

On-site
USD 147,000 - 182,000
Staff Detection Engineer
Staff Detection Engineer

Fluidstack • Seattle (WA)

On-site
USD 269,000 - 330,000
Security Deployment Lead, Deployment
Security Deployment Lead, Deployment

Fluidstack • Indiana (PA)

On-site
USD 185,000 - 221,000
Equity compensation
Staff Detection Engineer
Staff Detection Engineer

Socket.dev • San Francisco (CA)

On-site
USD 150,000 - 210,000
Health, dental, and vision insurance
Generous PTO policy
Retirement plan
Security Engineer, Infrastructure
Security Engineer, Infrastructure

Fluidstack • Austin (TX)

On-site
USD 170,000 - 220,000
Health, dental, and vision insurance
Generous PTO policy
Retirement plan