Security Operations Lead

Fireworks AI

United States

On-site

USD 140,000 - 190,000

Full time

12 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Fireworks AI is hiring its first Security Operations Lead to build and run a modern SecOps function. You will own incident response end-to-end, stand up detection content, and drive playbooks while growing into a people leadership role as the team scales.

You’ll roll out CrowdStrike across endpoints and cloud, expand SOAR automation with Incident.io, and partner with IT and Security Engineering to improve detection, response, and resilience across our AI infrastructure as we scale globally.

Qualifications

  • Strong detection engineering background with scalable content.
  • Proven scripting/automation, especially Python and SOAR.
  • Experience building or maturing a SecOps function, tooling, processes, metrics.
  • 7+ years in security operations, detection, or incident response.
  • Hands-on with EDR platforms (CrowdStrike preferred).
  • Cloud security operations in AWS, GCP, or Azure; telemetry and response knowledge.
  • Professional certifications such as GCIA, GCIH, GCFA, OSCP, or similar.

Responsibilities

  • Lead the rollout and operation of CrowdStrike across endpoints and cloud environments.
  • Define, implement, and measure the detection and response program against MITRE ATT&CK.
  • Own end-to-end incident response: run incidents, post-incident reviews, and lessons learned.
  • Develop and run security operations workflows, including SOAR with Incident.io, on-call and SLAs.
  • Build threat intelligence into detections, hardening, and tabletop exercises.
  • Partner with Infrastructure and Security Engineering to cover incidents and improve coverage.

Skills

Detection engineering
Python
SOAR automation
Incident response
Cloud security
EDR tooling
Security operations
Leadership

Tools

CrowdStrike
Incident.io
SIEM

Job description

Responsibilities
  • We’re hiring our first Security Operations Lead to build and run the SecOps function at Fireworks AI
  • As we scale our AI infrastructure platform globally, we’re investing in a modern detection and response capability anchored on CrowdStrike (EDR and SIEM, 365-day retention), Console AI for ticketing, and Incident Io for on-call and incident management
  • We have a Security Incident Response Plan (SIRP) in place that you’ll build on, and you’ll own the function end-to-end: standing up detection content, operationalizing our incident response playbooks, running threat intel into action, and building the operational muscle that keeps Fireworks resilient as we grow
  • This role sits within the Security team and will primarily support Corporate Security and own incident response broadly, while partnering closely with Security Engineering on infrastructure-related incidents - bridging both areas
  • This is an IC-to-manager role: you’ll start hands-on building and running the function, growing into a people leader as the team scales
  • Lead the rollout, tuning, and ongoing operation of CrowdStrike across our endpoint and cloud environment and SIEM use cases, partnering with IT and Security Engineering on deployment and coverage
  • Define and operate our detection and response program: build detection content, establish triage and escalation workflows, and continuously measure and improve coverage against frameworks like MITRE ATT&CK
  • Own incident response end-to-end: operationalize our existing SIRP into detailed playbooks, run incidents, lead post-incident reviews, and drive lessons learned into program improvements
  • Stand up our security operations workflow, including SOAR automation with Incident.io for alerting, on-call, and incident orchestration, while also defining how incidents self-submitted through our IT ticketing system are triaged and handled as one-off cases - along with the SLAs and metrics the function runs on
  • Build and operationalize a threat intelligence capability: track threats relevant to AI infrastructure and our customer base, and translate intel into detections, hardening, and tabletop scenarios
  • Partner closely with Infrastructure, Corporate Security, and other cross-functional teams across the organization, engaging as needed to support incidents and shared initiatives
  • As the function matures, you’ll have the opportunity to:
  • Hire and build the SecOps team, growing from IC to people leader
  • Expand 24x7 coverage and adjacent capabilities like cloud detection engineering, insider threat, or red team / purple team operations
  • Shape the broader security strategy as a senior leader in the function
Qualifications
  • Strong detection engineering background: you’ve written, tested, and maintained detection content at scale and understand the tradeoffs between coverage, fidelity, and analyst load
  • Strong scripting and automation skills (Python, SOAR platforms) applied to detection, response, and reporting workflows
  • Experience building or significantly maturing a SecOps function, including tooling selection, process design, and metrics
  • 7+ years in security operations, detection and response, incident response, or a closely related field
  • Hands-on experience with EDR platforms (CrowdStrike strongly preferred; SentinelOne, Defender, or similar also relevant) including detection engineering and tuning
  • Comfort operating in a build phase: you can write the playbook and run the playbook, and you know when to invest in process versus when to just get things done
  • Demonstrated incident response leadership: you’ve run real incidents from triage through executive communication and post-incident review
  • Working knowledge of cloud security operations (AWS, GCP, or Azure) and the unique telemetry, attack patterns, and response considerations of cloud-native environments
  • Certifications such as GCIA, GCIH, GCFA, OSCP, or similar
  • Prior experience at an AI, cloud infrastructure, or high- growth SaaS company
  • Threat intelligence experience, including operationalizing intel into detection and hardening outcomes
  • Experience with Incident.io, PagerDuty, or comparable incident management tooling
  • Experience with SIEM detection engineering at scale (CrowdStrike Falcon LogScale/NG-SIEM, Splunk, Sumo Logic, Panther, or similar)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Lead
Security Operations Lead

Fireworks AI • San Mateo (CA)

On-site
USD 180,000 - 230,000
Security Operations Lead
Security Operations Lead

Fireworks AI • New York (NY)

On-site
USD 150,000 - 230,000
Security Operations Lead — Build & Scale AI SecOps
Security Operations Lead — Build & Scale AI SecOps

Fireworks AI • United States

On-site
USD 140,000 - 190,000
SecOps Leader: AI Infra Incident Response
SecOps Leader: AI Infra Incident Response

Fireworks AI • San Mateo (CA)

On-site
USD 180,000 - 230,000
IT Security Operations Analyst
IT Security Operations Analyst

Blackstone Talent Group • San Francisco (CA)

On-site
USD 120,000 - 150,000
Security Specialist - Incident.io
Security Specialist - Incident.io

Executive Operations, LLC • South Lyon (MI)

On-site
USD 80,000 - 120,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Associate Security Engineer (Remote)
Associate Security Engineer (Remote)

CrowdStrike • Town of Texas (WI)

On-site
USD 70,000 - 95,000
Market-leading compensation
Comprehensive wellness programs
Paid time off and holidays
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000