Detection & Response Engineer

Runway ML
United States
Workplace: RemoteFull timeUSD 240,000 - 290,000 annuallyFunction: Solutions Engineering & Sales EngineeringSkills: ["Incident response","Automation","Writing","Judgment","Cross-functional partnership"]

Own Runway’s detection and response program end to end, including what gets logged, alerted on, triaged, and how incidents are recovered. Build detections as code across cloud environments and Kubernetes, measuring coverage and precision. Lead incident response and post-incident reviews, automate triage with enrichment/correlation/containment, and translate detection metrics into evidence for SOC 2 and ISO 27001. Partner with platform and research teams and participate in on-call rotations.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Runway ML
Runway ML
12 hours ago

Detection & Response Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Own Runway’s detection and response program end to end, including what gets logged, alerted on, triaged, and how incidents are recovered. Build detections as code across cloud environments and Kubernetes, measuring coverage and precision. Lead incident response and post-incident reviews, automate triage with enrichment/correlation/containment, and translate detection metrics into evidence for SOC 2 and ISO 27001. Partner with platform and research teams and participate in on-call rotations.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Own detection and response end to end: logging, alerting, triage, and recovery.
  • •Write and tune detections as code across cloud environments and Kubernetes, measuring coverage and precision.
  • •Lead incident response from the first alert through containment and forensics, then write post-incident reviews.
  • •Build automation for triage and evidence collection, using LLM-based tooling where it holds up under audit.
  • •Work with platform and research engineers to ensure new systems ship with logging and response playbooks in place; participate in threat hunts and tabletop exercises and an on-call rotation.

Pay and Benefits

Salary: USD 240,000 - 290,000 annually

Key Requirements

  • •Hands-on incident response experience, including triaging live alerts, leading investigations, and writing post-incident writeups.
  • •Experience building and tuning detections in a modern SIEM, ideally managed as code.
  • •Knowledge of how attackers move through cloud and Kubernetes environments, including IAM abuse, container escape, credential theft, and supply chain compromise.
  • •Comfort writing Python, TypeScript, Rust, or another language to automate response work and connect security tools.
  • •Familiarity with a major cloud platform and Kubernetes at the level of audit logs, RBAC, and workload identity.
Skills:Incident responseAutomationWritingJudgmentCross-functional partnership
Tech Stack:PythonTypeScriptRustSIEMKubernetesCloudIdentity systemsEndpointsSaaSIAMRBACLLMSOC 2ISO 27001LLM-based toolingLLM toolingMCP servers

Company Brief

Runway ML
Provides generative AI tools and a creative platform for creators and studios to generate, edit, and collaborate on images, video, and other media using state-of-the-art machine learning models.
Industry: AI & Machine Learning
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series C
Headquarters: New York, United States
Founded: 2018
WebsiteLinkedIn