> Markdown version of [/jobs/ext/2714988-staff-incident-response-engineer](https://www.wearedevelopers.com/jobs/ext/2714988-staff-incident-response-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Incident Response Engineer - **Company:** Andreessen Horowitz - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $243,000.0 - $284,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Build Automation, Software as a Service, Cyber Security, Kusto Query Language, Security Information and Event Management, Scripting, Mitre Att&ck, Virtual Agents, Security Orchestration, Automation & Response - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/partner-20-staff-engineer-incident-response-a16z-2-8044745 ## About the Role * 5+ years of incident response experience or equivalent demonstrated impact, with cloud IR depth across both AWS and GCP * Experience leading live incidents end to end - triage, containment, eradication, forensic investigation, and post-mortem - across cloud, SaaS, identity, and endpoint surfaces * Experience running proactive, hypothesis-driven threat hunts using current TTPs and intel * Hands-on detection authoring in modern SIEM platforms (Sigma, KQL, or equivalent) and experience working with detection-as-code * Experience building detection frameworks and contributing to SIEM architecture decisions * Strong Python scripting. This is a role where you build automation, not one where you only operate someone else's * Demonstrated capability across modern security tooling categories (cloud telemetry, EDR, SOAR, SIEM). We weight transferable capability over experience with any specific product * GCIH or equivalent IR certification preferred * Comfortable in a fast-moving environment where security is expected to enable the business * Experience defending against nation-state threat actors or organized criminal groups * Working knowledge of AI/agent systems and their security implications, particularly in SOC workflows * Experience translating the technical reality of an incident (blast radius, containment status, disclosure decisions) into language non-technical stakeholders can act on. * Low ego, high empathy, and the capacity to collaborate effectively with diverse teams ## Description We're hiring a Staff Incident Response Engineer to anchor a16z's detection and response work. You'll own incident triage and response across AWS and GCP, write the detections that catch real threats in our SIEM, and run point when something serious happens. The threats here are not theoretical. We see capital call wire fraud attempts, vishing campaigns, social engineering against IT and partners, and occasionally more sophisticated actors (nation-state groups, organized criminal operations) who specifically target venture capital firms. Your work protects the firm, our LPs, and our portfolio companies. You'll work day to day with the Head of Cybersecurity, Security Engineering, IT, and Legal. This role requires an in-office presence 2 days a week in our San Francisco, CA office. To join our team, you should be excited to: * Run incidents end to end, from first alert to post-mortem, across cloud and SaaS environments * Write the detections that catch real threats, with a strong bias toward signal over noise and broad MITRE ATT&CK coverage * Help shape the next generation of our SOC, including AI agent integration into triage and response workflows * Partner across the firm during incidents: investing teams, Legal, Compliance, Finance, IT, and firm leadership all get pulled in, and this role keeps every audience aligned under pressure * Drive post-mortems that lead to operational change, not process for its own sake * Work against real adversaries, including nation-state groups, organized criminal operations, and threat actors who specifically target venture capital firms ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Designing UX for SRE Agents in High-Stakes Incidents](https://www.wearedevelopers.com/videos/100003-designing-ux-for-sre-agents-in-high-stakes-incidents) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)