Anyscale's need to detect and respond to security events across its production and corporate environments is growing as the company scales. We're looking for a Senior Detection and Response Engineer to own detection engineering and to lead incident response when it counts, coordinating the response and driving it to resolution
This is a high-ownership role with real room to shape how detection and response works at Anyscale. You will own the detection pipeline, the response runbooks, and incident response, reporting to the Head of Security and partnering with engineering. This role is based in India
In your first year, success looks like strong detection coverage across our cloud, endpoint, and runtime telemetry, a working correlation and alerting pipeline, and incident response runbooks that have been exercised in practice
Own and build detection coverage across cloud, endpoint, and runtime telemetry
Own a centralized correlation and alerting capability that turns telemetry into actionable detections
Own incident response: runbooks, escalation paths, and coordination during an incident, across corporate and production environments
Drive detection of anomalous activity across the environments we run, including our Kubernetes footprint
Tune detections to keep signal high and noise low, and measure detection and response performance such as mean time to detect and respond
Run incident retrospectives and feed lessons back into detections and controls
Partner with infrastructure security and IT to close gaps surfaced during response