SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 220,000 - 0 / annual
Turing is an AI company headquartered in San Francisco that works with frontier AI labs to generate high-quality datasets, reinforcement learning environments, and research benchmarks. The company also partners with Fortune 500 enterprises to build and deploy agentic AI systems in mission-critical workflows.
You will serve as a senior technical voice in security operations, handling the organization's most complex and high-severity security cases while improving the detection, investigation, and response systems the entire team relies on.
Key responsibilities:
- Lead triage and investigation of complex, high-severity security alerts and incidents across cloud, endpoint, identity, and application telemetry
- Own and improve detection quality by tuning, writing, and validating detections in partnership with detection engineering
- Serve as a senior responder during security incidents, driving investigations and producing clear post-incident analysis
- Perform proactive threat hunting and convert findings into new detections and prevention measures
- Develop and maintain investigation and response playbooks while raising the analytical rigor of the team
- Operationalize threat intelligence to prioritize threats most relevant to the organization
- Build automation and tooling to streamline triage and investigation, reducing manual work
- Mentor analysts and establish standards for investigation quality and documentation
At the Staff level, your impact extends beyond cases you personally close. You will raise the analytical bar for the entire team, improve detections and playbooks everyone depends on, mentor other analysts, and make the organization measurably faster and sharper at catching and responding to threats.
Requirements:
- Significant experience (typically 8+ years) in security operations, incident response, threat detection, or similar analytical security role
- Deep hands-on experience investigating threats across cloud, endpoint, identity, and network telemetry
- Strong command of SIEM/detection platforms, log analysis, and query languages
- Experience writing and tuning detections and leading incident investigations end to end
- Scripting/automation ability (Python or similar) to reduce toil and extend tooling
- Excellent analytical judgment and clear written communication for incident documentation
Nice to have:
- Detection engineering experience and familiarity with detection-as-code practices
- Threat hunting and threat intelligence experience
- Familiarity with cloud provider security tooling and forensics
- Relevant certifications (GCIA, GCIH, or similar)