Staff Detection Engineer

Fluidstack

Seattle (WA)

On-site

USD 269,000 - 330,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fluidstack seeks an experienced security operations professional to lead detection engineering and incident response for its frontier AI compute infrastructure. You will own detection content across cloud and endpoint telemetry, write detections, and drive automation in Python.

You will coordinate with leadership to shape strategy and work across IT and infrastructure teams to improve telemetry and security postures.

Qualifications

  • 8+ years in security operations, detection engineering, or incident response at scale.
  • Proven ability to build or scale a detection engineering function with program and coverage.
  • Deep hands-on experience writing detections against cloud telemetry and endpoint telemetry.
  • Strong scripting and automation skills in Python or similar for detection-as-code pipelines.
  • Experience leading incident response at high scale and driving postmortems into action.
  • Technical leadership without heavy management overhead; able to set direction and execute.
  • Bonus: GPU clusters security, HPC, or open-source detection content contributions.

Responsibilities

  • Build the detection engineering function from the ground up with telemetry pipelines and runbooks.
  • Own detection-as-code end-to-end with tests, version control, and CI.
  • Lead incident response for high-severity events with containment and root cause analysis.
  • Drive automation of triage and enrichment in Python to scale alert volume.
  • Collaborate with leadership to translate threat landscape into a prioritized security roadmap.
  • Work with corp IT and infrastructure teams to secure telemetry, logging, and access.

Skills

Security operations
Detection engineering
Incident response
Python scripting
Automation

Tools

AWS
GCP
Azure
EDR
Sigma
CI/CD

Job description

About FluidstackWe exist to make humanity more free. For most of human history, you farmed or you starved. Technology gave people more time for the things they wanted to do, instead of things they had to do. Powerful AI will be the biggest lever for human choice we've ever built - but only if models are aligned with what humanity actually wants. There are groups building AI who don't share these goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands human freedom or shrinks it.

About FluidstackWe exist to make humanity more free. For most of human history, you farmed or you starved. Technology gave people more time for the things they wanted to do, instead of things they had to do. Powerful AI will be the biggest lever for human choice we've ever built - but only if models are aligned with what humanity actually wants. There are groups building AI who don't share these goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands human freedom or shrinks it.

We're singularly focused on delivering 10 to 100s of GWs of compute faster than anyone else, rethinking every layer of the stack. We acquire power, design and build data centers, and operate them - with teams spanning hardware and software. Speed and scale are our key differentiators. Come be a part of building civilization-scale infrastructure for AI.

We hire people who care deeply about this problem space. If that is you, please apply!

How We Operate
  • Extreme ownership. Full autonomy. Own things end to end often taking on scope outside your core role without being asked to get things done.
  • Velocity. We drive everything forward as fast as possible.
  • First principles. Challenge every assumption. Zero analogy thinking, no egos, the best idea wins.
  • Love of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward.
The Security & Corp IT Team

The Security & Corp IT team protects the people, systems, and infrastructure behind the largest AI compute buildout in history.

Examples Of Key Problems The Team Is Working On

  • Build detection and response coverage across cloud (AWS/GCP/Azure), endpoint, and identity telemetry for a company whose attack surface spans corporate IT and gigawatt-scale data center infrastructure.
  • Run incident response end to end, from first alert through containment, remediation, and postmortem, without a large SOC to fall back on.
  • Stand up detection-as-code pipelines so every detection is versioned, tested, and deployed like software rather than hand-edited in a console.
  • Harden corp IT foundations (identity, device management, access) so security scales with headcount instead of lagging it.
Role Scope
  • Build the detection engineering function from the ground up: telemetry pipelines, detection content, alert routing, and response runbooks, with coverage you can defend against a threat model, not just a tool checklist.
  • Own detection-as-code end to end, writing detections across cloud and endpoint sources with tests, version control, and CI so a bad rule never ships silently.
  • Lead incident response for high-severity events, driving containment and root cause, and closing out each incident with detections that catch the same class of attack next time.
  • Drive automation of triage and enrichment in Python (or similar) so alert volume scales without proportional headcount.
  • Partner directly with leadership on security strategy, translating threat landscape and detection gaps into a prioritized roadmap with clear tradeoffs.
  • Work across corp IT and infrastructure teams to get the telemetry, logging, and access you need, and to fix the root causes your detections keep surfacing.
What We're Looking For

The below is a starting point. We always make space for exceptional people, so if you don't fit this role exactly, tell us where you would.

  • 8+ years in security operations, detection engineering, or incident response, with time spent at a high-growth tech company, cloud-native infrastructure provider, or top-tier MDR/threat intel firm.
  • You've built or scaled a detection engineering function, not just operated inside one: you can point to the program, the pipeline, and the coverage that exist because of you.
  • Deep hands-on experience writing detections against cloud telemetry (AWS, GCP, or Azure control plane and audit logs) and endpoint telemetry (EDR event streams, OS-level signals).
  • Strong scripting and automation skills in Python or similar, enough to build and maintain detection-as-code pipelines yourself rather than spec them for someone else.
  • Incident response experience at a company operating at significant scale, where you led response under pressure and your postmortems changed how the company operates.
  • You operate as a technical lead without heavy management overhead: you set direction, make the calls, and do the work.
  • You work well across corp IT and infrastructure teams in a fast-moving environment, and you get telemetry and fixes shipped by making the case, not by escalating.
  • Bonus: experience securing GPU clusters, HPC environments, or physical data center infrastructure, or contributions to open-source detection content (Sigma, community rule sets).

We are committed to pay equity and transparency.

Fluidstack is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Fluidstack will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

Compensation Range: $269K - $330K

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection Engineer
Senior Detection Engineer

Fluidstack • Austin (TX)

On-site
USD 147,000 - 182,000
Senior Detection Engineer
Senior Detection Engineer

Fluidstack • Seattle (WA)

On-site
USD 147,000 - 182,000
Senior Detection Engineer
Senior Detection Engineer

Fluidstack • New York (NY)

On-site
USD 120,000 - 180,000
Staff Detection Engineer
Staff Detection Engineer

Socket.dev • San Francisco (CA)

On-site
USD 150,000 - 210,000
Health, dental, and vision insurance
Generous PTO policy
Retirement plan
Principal Incident Responder
Principal Incident Responder

Fluidstack • Seattle (WA)

On-site
USD 330,000 - 380,000
Principal Incident Responder
Principal Incident Responder

Fluidstack • New York (NY)

On-site
USD 330,000 - 380,000
Principal Incident Responder
Principal Incident Responder

Fluidstack • Austin (TX)

On-site
USD 330,000 - 380,000
Security Engineer, Threat Intelligence
Security Engineer, Threat Intelligence

Socket.dev • New York (NY)

On-site
USD 220,000 - 300,000
Competitive total compensation package
Equity
Retirement or pension plan
+2
Security Engineer, Infrastructure
Security Engineer, Infrastructure

Fluidstack • Seattle (WA)

On-site
USD 182,000 - 210,000
Total compensation including equity
Pension/retirement plan
Health, dental, vision insurance
+1
Incident Response Manager
Incident Response Manager

Fluidstack • Seattle (WA)

On-site
USD 182,000 - 224,000
Equity
Health insurance
Generous PTO