Staff Detection Engineer
Fluidstack · San Francisco, CA · 1 mo ago
On-siteEngineering$269k–$330k/yrFull-time
About the role
The Security & Corp IT Team at Fluidstack is responsible for protecting the company's systems and infrastructure, which includes the largest AI compute buildout in history. This team works on a variety of critical problems such as building detection and response coverage across cloud, endpoint, and identity telemetry, incident response, and hardening corp IT foundations.
Responsibilities
- Build the detection engineering function from the ground up: telemetry pipelines, detection content, alert routing, and response runbooks, with coverage you can defend against a threat model, not just a tool checklist.
- Own detection-as-code end to end, writing detections across cloud and endpoint sources with tests, version control, and CI so a bad rule never ships silently.
- Lead incident response for high-severity events, driving containment and root cause, and closing out each incident with detections that catch the same class of attack next time.
- Drive automation of triage and enrichment in Python (or similar) so alert volume scales without proportional headcount.
- Partner directly with leadership on security strategy, translating threat landscape and detection gaps into a prioritized roadmap with clear tradeoffs.
- Work across corp IT and infrastructure teams to get the telemetry, logging, and access you need, and to fix the root causes your detections keep surfacing.
Requirements
- 8+ years in security operations, detection engineering, or incident response, with time spent at a high-growth tech company, cloud-native infrastructure provider, or top-tier MDR/threat intel firm.
- Deep hands-on experience writing detections against cloud telemetry (AWS, GCP, or Azure control plane and audit logs) and endpoint telemetry (EDR event streams, OS-level signals).
- Strong scripting and automation skills in Python or similar, enough to build and maintain detection-as-code pipelines yourself rather than spec them for someone else.
- Incident response experience at a company operating at significant scale, where you led response under pressure and your postmortems changed how the company operates.
- Operate as a technical lead without heavy management overhead: you set direction, make the calls, and do the work.
- Work well across corp IT and infrastructure teams in a fast-moving environment, and you get telemetry and fixes shipped by making the case, not by escalating.
Bonus
- Experience securing GPU clusters, HPC environments, or physical data center infrastructure.
- Contributions to open-source detection content (Sigma, community rule sets).
Pay
Compensation Range: $269K - $330K