Anyscale

Senior Detection and Response Engineer

Anyscale • $150K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in security with a focus on detection engineering and incident response, preferably in a startup environment.
  • Hands-on experience with cloud (AWS, Azure), endpoint (EDR), and container telemetry.
  • Proven track record of leading incident response from start to finish.
  • Ability to build and scale detection and response capabilities.
  • Strong judgment and communication skills during high-pressure situations.
  • Experience collaborating with engineers and IT to address response gaps.

Responsibilities

  • Own and enhance detection coverage across cloud, endpoint, and runtime telemetry.
  • Develop a centralized correlation and alerting system for actionable detections.
  • Lead incident response efforts, including runbooks and coordination during incidents.
  • Detect anomalous activities across various environments, including Kubernetes.
  • Tune detection systems to optimize signal-to-noise ratio and measure performance metrics.
  • Conduct incident retrospectives and integrate lessons learned into detection strategies.
  • Collaborate with infrastructure security and IT to address identified gaps.

Benefits

  • Competitive salary and equity options.
  • Health, dental, and vision coverage with many plans up to 99% employer-covered.
  • Flexible time off policy.
  • Paid parental leave.
  • Mental health support services.
Full Job Description
About the Role

Anyscale's need to detect and respond to security events across its production and corporate environments is growing as the company scales. We're looking for a Senior Detection and Response Engineer to own detection engineering and to lead incident response when it counts, coordinating the response and driving it to resolution.

This is a high-ownership role with real room to shape how detection and response works at Anyscale. You will own the detection pipeline, the response runbooks, and incident response, reporting to the Head of Security and partnering with engineering. This role is based in India.

In your first year, success looks like strong detection coverage across our cloud, endpoint, and runtime telemetry, a working correlation and alerting pipeline, and incident response runbooks that have been exercised in practice.

What You'll Do
  • Own and build detection coverage across cloud, endpoint, and runtime telemetry.
  • Own a centralized correlation and alerting capability that turns telemetry into actionable detections.
  • Own incident response: runbooks, escalation paths, and coordination during an incident, across corporate and production environments.
  • Drive detection of anomalous activity across the environments we run, including our Kubernetes footprint.
  • Tune detections to keep signal high and noise low, and measure detection and response performance such as mean time to detect and respond.
  • Run incident retrospectives and feed lessons back into detections and controls.
  • Partner with infrastructure security and IT to close gaps surfaced during response.


What You'll Bring
  • 6+ years in security, with a strong focus on detection engineering and incident response, ideally at a high-growth startup.
  • Hands-on experience building detections and correlation across cloud (AWS, Azure), endpoint (EDR), and ideally container and runtime telemetry.
  • Experience owning incident response end to end, including leading during live incidents.
  • Comfort building and scaling a detection and response capability, not only operating an existing one.
  • Sound judgment under pressure and clear communication during incidents.
  • Fluency working with engineers and IT to close the gaps that response surfaces.


Nice to Have
  • Experience with SIEM or detection platforms and detection-as-code approaches.
  • Familiarity with runtime security tooling such as Upwind or similar.
  • Threat hunting or purple-team experience.
  • Background in AI or ML platforms or distributed systems.
Why Anyscale
  • We're on a mission to make scalable computing effortless. Ray is the AI Compute Engine at the center of some of the world's most powerful AI platforms
  • Our tech is in production at companies like OpenAI, Uber, Spotify, Instacart, and Cruise
  • We're backed by Andreessen Horowitz, NEA, and Addition, with $250M+ raised to date
  • Recent partnerships with Azure, CoreWeave, and Google Cloud are putting AI-native compute directly into enterprise environments
  • Competitive salary and equity, plus health/dental/vision coverage (many plans up to 99% employer-covered)
  • We offer flexible time off, paid parental leave, and mental health support

About Anyscale

SOHO 3Q is a prime community-focused, shared office space in China managed by SOHO China. It is headquartered at Chaowai SOHO in Beijing, China. As of June 2019, the coworking space had 30 spaces in China.
Learn more about Anyscale

Similar Jobs

More Jobs at Anyscale

More Information Technology Jobs

Find similar Senior Detection and Response Engineer jobs: