Anyscale

Senior Detection and Response Engineer

Anyscale$150K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in security focusing on detection engineering and incident response, preferably in a startup.
  • Hands-on experience with building detections across cloud (AWS, Azure), endpoints, and ideally container telemetry.
  • Proven ownership of end-to-end incident response, leading during live incidents.
  • Ability to build and scale detection and response capabilities, rather than merely operate them.
  • Strong judgment under pressure and clear incident communication.
  • Ability to collaborate effectively with engineers and IT for incident response improvements.

Responsibilities

  • Own and enhance detection coverage across cloud, endpoints, and runtime telemetry.
  • Develop a centralized correlation and alerting system to create actionable detections from telemetry.
  • Manage incident response processes, including runbooks and coordination during incidents.
  • Detect anomalous activity across various environments, including Kubernetes.
  • Fine-tune detections to maintain high signal quality and measure performance metrics.
  • Conduct incident retrospectives and integrate learnings into detection strategies.
  • Collaborate with infrastructure security and IT to address gaps identified during responses.

Benefits

  • Opportunity to own and shape detection and response processes.
  • High-impact role with significant responsibility in a growing company.
  • Collaborative environment working alongside engineering teams.
  • Possibility to work with advanced technologies in security.
  • Exposure to a high-growth startup atmosphere.
Full Job Description
About the Role

Anyscale's need to detect and respond to security events across its production and corporate environments is growing as the company scales. We're looking for a Senior Detection and Response Engineer to own detection engineering and to lead incident response when it counts, coordinating the response and driving it to resolution.

This is a high-ownership role with real room to shape how detection and response works at Anyscale. You will own the detection pipeline, the response runbooks, and incident response, reporting to the Head of Security and partnering with engineering. This role is based in India.

In your first year, success looks like strong detection coverage across our cloud, endpoint, and runtime telemetry, a working correlation and alerting pipeline, and incident response runbooks that have been exercised in practice.

What You'll Do
  • Own and build detection coverage across cloud, endpoint, and runtime telemetry.
  • Own a centralized correlation and alerting capability that turns telemetry into actionable detections.
  • Own incident response: runbooks, escalation paths, and coordination during an incident, across corporate and production environments.
  • Drive detection of anomalous activity across the environments we run, including our Kubernetes footprint.
  • Tune detections to keep signal high and noise low, and measure detection and response performance such as mean time to detect and respond.
  • Run incident retrospectives and feed lessons back into detections and controls.
  • Partner with infrastructure security and IT to close gaps surfaced during response.


What You'll Bring
  • 6+ years in security, with a strong focus on detection engineering and incident response, ideally at a high-growth startup.
  • Hands-on experience building detections and correlation across cloud (AWS, Azure), endpoint (EDR), and ideally container and runtime telemetry.
  • Experience owning incident response end to end, including leading during live incidents.
  • Comfort building and scaling a detection and response capability, not only operating an existing one.
  • Sound judgment under pressure and clear communication during incidents.
  • Fluency working with engineers and IT to close the gaps that response surfaces.


Nice to Have
  • Experience with SIEM or detection platforms and detection-as-code approaches.
  • Familiarity with runtime security tooling such as Upwind or similar.
  • Threat hunting or purple-team experience.
  • Background in AI or ML platforms or distributed systems.

About Anyscale

SOHO 3Q is a prime community-focused, shared office space in China managed by SOHO China. It is headquartered at Chaowai SOHO in Beijing, China. As of June 2019, the coworking space had 30 spaces in China.
Learn more about Anyscale

Similar Jobs

More Jobs at Anyscale

More Information Technology Jobs

Find similar Senior Detection and Response Engineer jobs: