Partner 20, Staff Engineer, Incident Response
Core
Staff Incident Response Engineer owning end-to-end incident triage, response, and post-mortems for a16z's cloud and SaaS environments, protecting the firm, LPs, and portfolio companies from real-world threats like wire fraud, vishing, and nation-state actors.
Role type
Staff Engineer, Incident Response (Security Operations)
Builds
Detection rules (Sigma, KQL), automation scripts (Python), and SOC workflows integrating AI agents
Domain
Cybersecurity, Cloud Security, Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response leadership, cloud security (AWS/GCP), detection authoring, threat hunting, Python scripting, SIEM architecture, stakeholder communication
Preferred skills
GCIH certification, AI/agent system security knowledge, experience defending against nation-state actors
Technologies
AWS, GCP, Sigma, KQL, SIEM, SOAR, EDR, Python
Responsibilities
Run incidents end-to-end (triage, containment, eradication, forensics, post-mortem), write detections for SIEM, conduct proactive threat hunts, partner with Legal/Finance/Investing teams during incidents, drive operational changes from post-mortems
Seniority
Staff, hands-on IC with strategic partnership