Senior Security Engineer I, Advanced Response
Job description
About the role
CoreWeave is seeking a technical expert to join our security team and manage incident response for our specialized AI cloud infrastructure. You will identify, analyze, and mitigate threats across our high-performance computing environments to ensure the integrity of our platform. This role requires a deep technical understanding of how modern AI workloads interact with underlying infrastructure. The successful candidate will act as a primary defender against sophisticated threats targeting critical computational assets. You will own the full lifecycle of security incidents from initial detection through complete remediation and recovery. Your work will directly influence the security posture of a platform powering some of the most demanding artificial intelligence applications. This position demands a proactive mindset and the ability to operate effectively in a fast-paced, high-impact environment.
Key facts
What you'll do
- Lead forensic investigations into security incidents and perform detailed root cause analysis on platform threats.
- Develop and iteratively refine automated response playbooks to address security events in real-time with minimal manual intervention.
- Collaborate closely with engineering teams to harden the infrastructure and improve the fidelity of security detection capabilities.
- Continuously monitor cloud environments for suspicious activity, unauthorized access attempts, and indicators of compromise.
- Create comprehensive technical documentation and structured post-incident reports to improve future security posture and knowledge sharing.
- Analyze complex security data to identify patterns of malicious behavior and emerging tactics used against the platform.
- Serve as a technical authority during active security incidents, guiding remediation efforts and communicating status to stakeholders.
- Design and implement detection logic to identify advanced persistent threats targeting the AI compute environment.
- Partner with infrastructure teams to ensure security controls are integrated into the deployment lifecycle from the earliest stages.
- Evaluate new security tools and technologies to enhance the organization's ability to detect and respond to sophisticated adversaries.
- Maintain a deep understanding of the threat landscape specifically affecting high-performance computing and AI infrastructure.
- Translate complex technical findings into clear narratives for both technical and non-technical audiences during incident reporting.
- Drive improvements in security processes to reduce response times and increase the efficiency of investigative workflows.
- Act as a subject matter expert for internal teams regarding cloud security best practices and incident response procedures.
Requirements
- Proven experience in incident response, threat hunting, or security operations within a cloud environment, specifically managing incidents in production settings.
- Deep understanding of Linux internals, networking protocols, and cloud-native security architectures that underpin scalable compute platforms.
- Ability to write scripts for automation and data analysis to support security workflows and accelerate investigative processes.
- Strong knowledge of modern attack vectors and defensive strategies relevant to large-scale infrastructure running critical workloads.
- Demonstrated capability to work effectively in a fast-paced environment where priorities shift rapidly based on emerging threats.
- Experience with structured investigation methodologies and the ability to document findings in a clear, legally defensible manner.
- Understanding of the unique security challenges associated with AI infrastructure, including data poisoning, model theft, and adversarial attacks.
- Must be able to obtain necessary security clearances or meet specific compliance requirements as dictated by the role and client engagements.
Nice to have
- Experience working with Kubernetes security and containerized environments, including securing the control plane and worker nodes.
- Background in securing GPU-accelerated workloads or high-performance computing clusters where performance and security intersect.
- Familiarity with infrastructure-as-code tools and CI/CD security integration to automate security checks within deployment pipelines.
- Knowledge of log aggregation platforms and security information and event management (SIEM) systems for advanced threat detection.
- Experience with digital forensics tools and techniques for analyzing compromised systems and preserving evidence.
- Understanding of compliance frameworks and regulatory requirements relevant to cloud-based security operations.
Practical notes
CoreWeave operates as an AI-native cloud provider focused on large-scale GPU compute. Applicants should be prepared to work in a fast-paced environment supporting complex AI workloads. Please submit your application through the official CoreWeave careers portal.