SlipstreamJobsFresh Startup & VC-Backed Jobs

Security engineer, detection and response

Writer - San Francisco, CA, United States - In-office - posted 2026-09-22

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Writer is an enterprise generative AI platform valued at $1.9B, backed by leading investors, serving hundreds of companies including Mars, Marriott, Uber, and Vanguard. The company is building and deploying AI agents grounded in enterprise data, powered by Writer's enterprise-grade LLMs. You will join Writer's security team as a Staff Detection and Response Engineer, responsible for protecting the AI infrastructure that powers the platform. This role combines hands-on security engineering with strategic threat intelligence to defend cutting-edge AI systems against evolving adversaries. Key responsibilities include: - Design and implement detection strategies for AI-specific threats including prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training datasets or model weights across distributed infrastructure. - Build automated response playbooks and orchestration workflows that contain threats without human intervention, reducing mean time to response from hours to minutes while automatically remediating compromised inference endpoints. - Lead security incident response coordination across all teams (Cloud, AppSec, Enterprise, AI Security) when AI infrastructure or models are compromised, conducting forensic investigations on training pipeline attacks and model manipulation attempts. - Hunt proactively for sophisticated threats across GPU clusters and training infrastructure by analyzing model outputs for signs of compromise, reproducing AI-specific vulnerabilities, and identifying visibility gaps before adversaries exploit them. - Build detection-as-code frameworks with version control and automated deployment, onboard telemetry from AI training infrastructure and inference endpoints, and create dashboards tracking model security metrics and access to sensitive research data. - Collaborate cross-functionally as the operational security partner, translating AI Security's threat research into production detections and enabling responsible AI development through security guardrails. - Maintain 24/7 on-call rotation for critical AI security incidents, responding to real-time threats while continuously improving detection coverage and automation. The role is based in San Francisco or Seattle, reporting to the Head of Security Operations. Writer is open to hiring at multiple levels with compensation scaled to experience and expertise. Requirements: - 3-5+ years in security operations, detection engineering, or incident response with proven track record of identifying and stopping sophisticated attacks in production environments, specifically securing AI/ML infrastructure, high-performance computing environments, or distributed systems at scale. - Strong programming skills in Python, KQL, SPL, or similar languages to build custom detection logic, automate response workflows, and operationalize security across cloud-native and distributed computing environments. - Experience with SIEM platforms, detection technologies, and forensic investigation techniques with demonstrated ability to build detection for novel attack techniques and conduct forensics in complex distributed environments. - Self-directed execution mindset with track record of securing high-value intellectual property, automating incident response in complex environments, and identifying critical security gaps through proactive threat hunting. - Deep alignment with Writer's values: ability to connect across security, infrastructure, and AI research teams; challenge assumptions about AI security engineering; and own the protection of the AI platform with accountability.

About Writer

AI / Data / Infrastructure; SaaS / Enterprise Software — enterprise generative AI platform for business teams.

Similar roles