SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Operations Lead

Fireworks - Remote - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Fireworks is hiring its first Security Operations Lead to build and run the SecOps function at a Series D AI infrastructure platform ($17.5B valuation, backed by NVIDIA, Sequoia, AMD, and others). You'll own security operations end-to-end: standing up detection and response capabilities, operationalizing incident response playbooks, running threat intelligence into action, and building the operational muscle to keep Fireworks resilient as it scales globally. Key responsibilities include leading the rollout and tuning of CrowdStrike EDR/SIEM across endpoints and cloud environments; defining and operating the detection and response program with detection content, triage workflows, and continuous improvement against MITRE ATT&CK; owning incident response end-to-end from playbook operationalization through post-incident reviews; standing up security operations workflows with Incident.io for alerting, on-call, and incident orchestration; and building a threat intelligence capability focused on AI infrastructure threats. This is an IC-to-manager role: you'll start hands-on building and running the function, growing into a people leader as the team scales. You'll partner closely with Infrastructure, Corporate Security, and cross-functional teams on incidents and shared initiatives. Required: 7+ years in security operations, detection and response, or incident response; hands-on EDR experience (CrowdStrike preferred); strong detection engineering background with experience writing and maintaining detection content at scale; demonstrated incident response leadership running real incidents; strong scripting/automation skills (Python, SOAR); working knowledge of cloud security operations (AWS, GCP, Azure); experience building or maturing a SecOps function including tooling, process, and metrics; comfort operating in build phase. Nice-to-have: SIEM detection engineering at scale; Incident.io/PagerDuty experience; threat intelligence operationalization; prior AI/cloud infrastructure/high-growth SaaS experience; relevant certifications (GCIA, GCIH, GCFA, OSCP).

Similar roles