> Markdown version of [/jobs/ext/73550-principal-incident-responder](https://www.wearedevelopers.com/jobs/ext/73550-principal-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Incident Responder - **Company:** Fluidstack Inc - **Location:** San Francisco, CA, United States - **Salary:** $270,000.0 - $370,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Data Centers, Large Language Models - **Published:** May 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=347d6539db75161e ## About the Role Do you have experience in Root cause analysis?, * Experience running incidents that bridge cyber, physical, and OT or ICS surfaces. * Experience at critical-infrastructure operators, data centers, or industrial environments. * Experience designing or operating agent-augmented incident response, including triage, investigation, or response automation. * Experience tuning LLM-based IR systems against measured precision and recall. ## Description Fluidstack operates the compute infrastructure powering frontier AI. The work running on it is among the most consequential being done today, and the adversaries interested in it are among the most sophisticated, persistent, and well-resourced anywhere. We are building Detection & Response Engineering from the ground up: engineering-led, agent-first, and built to scale across IT, OT, and physical surfaces. As the Principal Incident Responder, you are the most senior incident commander in the program. You define what material-incident response looks like at Fluidstack, set the runbook standard the rest of the IR function operates inside, and lead the room when those systems come under attack., * Run material incidents as incident commander, coordinating across detection, response, physical security, data center operations, legal, communications, and customers. * Build the IR program: runbook standards, severity definitions, materiality methodology, evidence contracts, and post-incident review cadence. * Define the agent-human contract for response: escalation criteria, evidence packages required from agents, and human verdict feedback into agent quality. * Design and operate the senior-IR on-call rotation (ack SLAs, escalation chain, fan-out logic) and remain an active senior IC inside it. * Analyze incident trends and patterns to surface systemic risks and recurring root causes, and turn the learnings into runbook, detection, or program improvements. * Drive cross-functional follow-through after every significant incident, tracking remediation and systemic fixes to completion across detection, response, infrastructure, and other teams. * Define and track the IR program's KPIs and report on them to security and engineering leadership. * Set the tabletop and exercise cadence for IR readiness, executive crisis-comms, and audit-readiness drills. * Carry the external face of IR for regulatory and customer disclosure obligations, and audit responses. About You * You have run material incidents at companies with sophisticated threat models, as the most senior commander on the call. * You have made disclosure-grade calls under regulatory and customer reporting clocks. * You have written runbooks that other engineers followed under pressure, and rewritten them after they did not work. * You have built operational processes from the ground up in environments where structure did not previously exist. * You read the agent-first thesis as one of the most interesting design choices in incident response today. * You have well-founded opinions on what makes a runbook actually used or an incident response process actually effective. * You move fluently between technical containment and executive, legal, or customer-facing conversations during a declared incident. * You see what is needed, scope it yourself, and run with it. ## Related Videos - [Designing UX for SRE Agents in High-Stakes Incidents](https://www.wearedevelopers.com/videos/100003-designing-ux-for-sre-agents-in-high-stakes-incidents) - [Edit Your Future: Queerverse Radical AI](https://www.wearedevelopers.com/videos/909-edit-your-future-queerverse-radical-ai) - [Creating Industry ready solutions with LLM Models](https://www.wearedevelopers.com/videos/899-creating-industry-ready-solutions-with-llm-models) - [The Sustainability Race: AI's Promises, Pitfalls and Potential](https://www.wearedevelopers.com/videos/100155-the-sustainability-race-ai-s-promises-pitfalls-and-potential) - [AI is dead, long live AK](https://www.wearedevelopers.com/videos/1093-ai-is-dead-long-live-ak) - [Lies, Damned Lies and Large Language Models](https://www.wearedevelopers.com/videos/1231-lies-damned-lies-and-large-language-models) ## Related Articles - [What Are Large Language Models?](https://www.wearedevelopers.com/magazine/304-what-are-large-language-models) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)