Global Detection and Response Lead
Core
Own and scale cybersecurity detection and response operations, including monitoring, triage, investigation, containment, and remediation of security events across global infrastructure.
Role type
Senior IC security operations leader (detection and response)
Builds
Advanced detection systems, real-time response capabilities, and telemetry/logging infrastructure for OpenAI's global environment.
Domain
Cybersecurity, AI infrastructure security, threat intelligence
Deliverable
production ML models | infrastructure
Required skills
detection engineering, incident response, security operations, team leadership, observability stack expertise, adversary tradecraft (TTPs), incident playbook management, cloud telemetry analysis, threat intelligence, stakeholder management, strategic planning
Preferred skills
experience with airgapped and sovereign environments, experience building detection/response teams at scale, experience with frontier AI lab security challenges
Technologies
SIEM, data lakes, EDR, cloud telemetry, logging
Responsibilities
Oversee global detection and response operations including continuous monitoring and incident remediation; Lead and mentor teams of senior engineers in observability, detection, and threat intelligence; Ensure operational rigor through incident playbooks, on-call management, and tabletop exercises; Partner with engineering to improve detection quality and telemetry coverage; Evaluate and respond to emergent security concerns in a frontier AI lab environment; Build a security program capable of withstanding tier-1 adversaries
Seniority
Senior, hands-on IC with team leadership