SlipstreamJobsFresh Startup & VC-Backed Jobs

Detection & Response Engineer

Runway - Remote - Remote - posted 2026-09-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Runway is hiring a Detection & Response Engineer to own the security detection and incident response program for a company building frontier generative AI models for video and creative production. The role is unique because securing Runway's infrastructure differs significantly from typical SaaS security. The environment includes research compute, large training datasets, fast-moving build pipelines, and engineers working inside AI-assisted tooling daily—each element changes what attacks look like and what telemetry is needed to catch them. You will join the Security team and build the detection and response program as an engineer would: detections as code, response as automation, evidence as queryable data. This is a high-ownership role reporting to the head of security, partnering with platform and research engineers across the company. Key responsibilities: - Own detection and response end to end: logging strategy, alerting rules, triage workflows, and incident recovery - Write and tune detections as code across multiple cloud environments, Kubernetes, identity systems, endpoints, and SaaS tools; measure on coverage and precision rather than alert volume - Lead incident response from first alert through containment and forensics; write post-incident reviews - Build automation to reduce triage toil, including enrichment, correlation, containment actions, and evidence collection; leverage LLM-based tooling where audit-appropriate - Monitor AI agents and developer tooling operating in the environment; translate observations into concrete telemetry and controls - Partner with platform and research engineers to ensure new systems ship with logging and response playbooks on day one - Run threat hunts and tabletop exercises; fix findings - Convert incident and detection metrics into evidence for SOC 2, ISO 27001, and enterprise customer security reviews - Participate in on-call rotation for security incidents Requirements: - Hands-on incident response experience: you have triaged live alerts, led investigations, and documented findings - Experience building and tuning detections in a modern SIEM, ideally managed as code - Working knowledge of how attackers move through cloud and Kubernetes environments (IAM abuse, container escape, credential theft, supply chain compromise) and what those activities leave in logs - Ability to write Python, Typescript, Rust, or similar languages to automate response work and integrate security tools - Familiarity with at least one major cloud platform and Kubernetes at the level of audit logs, RBAC, and workload identity - Clear writing skills for incident timelines, detection documentation, and leadership updates - Sound judgment about what to alert on, what to automate, and when to escalate Bonus qualifications: - Experience monitoring GPU or HPC-style infrastructure, or research environments with large datasets - Experience building detections or guardrails for AI agents, LLM tooling, or MCP servers - Cloud forensics experience: disk and memory acquisition, cloud audit trail reconstruction, chain of custody - Published open source detection content

About Runway

AI / Data / Infrastructure; Media / Creator Economy — generative AI tools for video and creative production.

Similar roles