Principal Incident Responder
Core
Lead end-to-end incident response for a gigawatt-scale AI compute infrastructure, securing model weights and physical/logical systems across corporate, cloud, and data center environments.
Role type
Principal Incident Responder (Security)
Builds
Detection logic, response playbooks, forensic tooling, and the incident response program from the ground up.
Domain
AI Infrastructure Security / Cybersecurity
Deliverable
production ML models | infrastructure
Required skills
Incident response leadership, digital forensics (cloud/endpoint/network), threat hunting, playbook development, post-incident analysis, severity modeling, escalation management
Preferred skills
Defense of high-value targets (AI labs, critical infrastructure), cloud-native forensics (AWS, GCP), detection engineering, SIEM/SOAR, malware analysis, reverse engineering
Technologies
AWS, GCP, SIEM, SOAR
Responsibilities
Lead incident response from detection to post-incident review; build detection logic and response playbooks; run investigations correlating signals across cloud, endpoint, network, and physical systems; stand up the incident response function including on-call rotations; partner with teams to implement permanent improvements based on incident findings
Seniority
Principal, hands-on IC with program ownership