Senior Security Engineer I, Advanced Response

CoreWeave

Bellevue (WA)

Hybrid

USD 139,000 - 204,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

100% medical, dental, and vision insurance
Flexible Spending Account
401(k) with employer match
Catered lunch daily
Flexible PTO
Tuition Reimbursement

Job summary

CoreWeave is seeking a Cybersecurity Incident Response Lead in Bellevue, WA. This role involves leading complex cybersecurity incidents, conducting in-depth investigations, and developing AI-driven tools to enhance threat response. The ideal candidate has significant experience in incident response and threat hunting, is skilled in technical investigations, and can effectively communicate with senior leadership. CoreWeave offers a comprehensive benefits package, including health insurance, flexible PTO, and an equitable work environment.

Qualifications

  • Extensive experience in incident response and threat hunting.
  • Strong technical investigation skills with logs and telemetry.
  • Deep familiarity with cloud, endpoint, identity, and network environments.

Responsibilities

  • Lead complex cybersecurity incidents end‑to‑end.
  • Conduct technical investigations across data sources.
  • Run a structured threat hunting program informed by intelligence.

Skills

Incident response experience
Technical investigation skills
Familiarity with attacker TTPs
Experience briefing senior leadership
Scripting or automation proficiency

Tools

SQL
Python
Kubernetes

Job description

What You’ll Do

CoreWeave powers the world’s most demanding AI infrastructure, and threat actors know it. The Advanced Response Team exists to fight back. You’ll lead our most critical incidents, hunt adversaries before they surface, and build the capabilities that define how CoreWeave defends itself at scale.

  • Counter threat actors at a scale most practitioners never encounter — and build the capabilities to stay left of boom
  • Work alongside security partners who hold a high bar and expect you to raise it
  • Shape how CoreWeave finds and responds to the threats that matter most, with the autonomy to build and execute at the highest level
About the Role
  • Leading the most complex, highest severity cybersecurity incidents at CoreWeave end‑to‑end – with full ownership of outcomes, not just coordination
  • Reading smoke — authoritatively forming hypotheses about what’s burning and a strategy to attack it before you can see the fire directly
  • Serving as a clear, credible voice to senior leadership during active incidents — translating fast‑moving technical situations into risk and decision frameworks that drive action
  • Conducting deep technical investigations and hunts across endpoint, cloud, identity, and network data sources to establish scope, timeline, and root cause
  • Producing rigorous, risk‑driven post‑incident reviews that go beyond surface‑level timelines and result in concrete, durable improvements
  • Running a structured threat hunting program informed by operationalized intelligence — turning actor profiles, campaign reporting, and TTP gaps into hunts, and turning hunt findings into durable actions to harden CoreWeave and improve our response posture
  • Architecting and building AI‑powered tooling that drives how CoreWeave counters threats — accelerating work left and right of boom
  • Developing and running incident simulations and tabletop exercises that stress‑test real‑world response capabilities before a real incident does
Who You Are
  • Extensive experience in incident response, security operations roles, and/or threat hunting at scale, with demonstrated ownership of complex, high‑impact incidents from start to finish
  • Strong technical investigation and hunting skills — comfortable working hands‑on with logs, telemetry, and raw system data to form and validate hypotheses, not just direct others to do it
  • Deep familiarity with attacker TTPs and how they manifest across cloud, endpoint, identity, and network environments
  • Experience briefing senior leadership and non‑technical stakeholders during active incidents with clarity and composure
  • Comfort leading and operating across organizational boundaries — pulling the right people in at the right time without losing ownership of the outcome
  • Proficiency in at least one query language (e.g., SQL, Splunk Query Language, HiveQL)
  • Ability to script or automate in Python, Go, or similar to close operational gaps and accelerate response and hunting workflows
Preferred
  • Experience building or materially maturing an IR program at a cloud‑native organization
  • Familiarity with Kubernetes or containerized environments, with appetite to go deeper
  • Experience building and leveraging AI‑assisted tooling in investigation or triage workflows
  • Familiarity with SOAR platforms and case management tooling in an operational IR context

On‑call hours (including weekends and holidays) and leadership during active incidents is expected. If building a world‑class response and threat hunt program, and actually answering the call when you’re needed, is what gets you going, we’d love to connect.

Benefits

The base salary range for this role is $139,000 to $204,000. The starting salary will be determined based on job‑related knowledge, skills, experience, and market location. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program.

  • Medical, dental, and vision insurance—100% paid for by CoreWeave
  • Company‑paid life insurance
  • Voluntary supplemental life insurance
  • Short‑ and long‑term disability insurance
  • Flexible Spending Account
  • Health Savings Account
  • Tuition Reimbursement
  • Participation in Employee Stock Purchase Program (ESPP)
  • Mental wellness benefits through Spring Health
  • Family‑forming support provided by Carrot
  • Paid parental leave
  • Flexible, full‑service childcare support with Kinside
  • 401(k) with a generous employer match
  • Flexible PTO
  • Catered lunch each day in our office and data‑center locations
  • A casual work environment
  • A work culture focused on innovative disruption
Export Control Compliance
  • Applicant must be a U.S. person (e.g., U.S. citizen, lawful permanent resident, refugee, asylee)
  • or eligible to access the export‑controlled information without a required export authorization, or reasonably likely to obtain the required export authorization from the applicable U.S. government agency
Equal Employment Opportunity

CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: careers@coreweave.com.

California Consumer Privacy Act

California applicants only.

Our Workplace

While we prioritize a hybrid work environment, remote work may be considered for candidates located more than 30 miles from an office, based on role requirements for specialized skill sets. New hires will be invited to attend onboarding at one of our hubs within their first month. Teams also gather quarterly to support collaboration.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer I, Advanced Response
Senior Security Engineer I, Advanced Response

Coreweave • Livingston (NJ)

On-site
USD 139,000 - 204,000
Medical, dental, and vision insurance – 100% paid
Flexible PTO
401(k) with employer match
+1
Staff Security Engineer, Vulnerability Management
Staff Security Engineer, Vulnerability Management

Coreweave • Livingston (NJ)

On-site
USD 188,000 - 275,000
Medical, dental, and vision insurance
Company-paid Life Insurance
401(k) with employer match
+2
Staff Security Engineer, Vulnerability Management CoreWeave Livingston, NJ / New York, NY / Sun[...]
Staff Security Engineer, Vulnerability Management CoreWeave Livingston, NJ / New York, NY / Sun[...]

Neura Market • Livingston (NJ), Northern (KY)

Hybrid
USD 188,000 - 275,000
Medical, dental, and vision insurance
401(k) with employer match
Paid parental leave
+1
Staff Security Engineer, Vulnerability Management
Staff Security Engineer, Vulnerability Management

CoreWeave • New York (NY)

Hybrid
USD 188,000 - 275,000
Medical, dental, and vision insurance – 100% paid
Tuition Reimbursement
401(k) with employer match
+2
Senior Manager, Corporate Security
Senior Manager, Corporate Security

Coreweave • Livingston (NJ)

On-site
USD 149,000 - 198,000
Senior Threat Intelligence Specialist I, Protective and Geopolitical Intel
Senior Threat Intelligence Specialist I, Protective and Geopolitical Intel

Coreweave • Bellevue (WA)

On-site
USD 134,000 - 179,000
Medical, dental, & vision insurance
Company-paid Life Insurance
Discretionary bonus
+6
Senior Manager, Corporate Security
Senior Manager, Corporate Security

Socket.dev • New York (NY), Sunnyvale (CA), Livingston (NJ)

On-site
USD 149,000 - 198,000
Medical, dental, vision
401(k) match
Flexible PTO
Principal Security Engineer
Principal Security Engineer

jobr.pro • Livingston (NJ)

On-site
USD 180,000 - 260,000
Medical, dental, and vision insurance
401(k) with employer match
Paid parental leave
+4
Offensive Security Engineer
Offensive Security Engineer

Coreweave • Livingston (NJ)

On-site
USD 165,000 - 242,000
Medical, dental, and vision insurance – 100% paid for by CoreWeave
401(k) with a generous employer match
Flexible PTO
+2
Senior Security Engineer II, Cloud Security
Senior Security Engineer II, Cloud Security

CoreWeave • Bellevue (WA)

On-site
USD 165,000 - 242,000
Medical, dental, and vision insurance
Employee Stock Purchase Program
Flexible PTO
+2