a16z
Partner 20, Staff Engineer, Incident Response
San Francisco, California, United States · Staff+
Sponsorship not specified$243k-$284kDetected 50 days ago
PythonGitDatabricksAWSGCPCybersecuritySIEMKQLSOARIncident ResponseFigmaLeadership
About the role
- We're hiring a Staff Incident Response Engineer to anchor a16z's detection and response work.
- Your work protects the firm, our LPs, and our portfolio companies.
- You'll work day to day with the Head of Cybersecurity, Security Engineering, IT, and Legal.
Responsibilities
- We've established a team that is defined by respect for the entrepreneur and the company-building process; we know what it's like to be in the founder's shoes.
- You'll own incident triage and response across AWS and GCP, write the detections that catch real threats in our SIEM, and run point when something serious happens.
- We see capital call wire fraud attempts, vishing campaigns, social engineering against IT and partners, and occasionally more sophisticated actors (nation-state groups, organized criminal operations) who specifically target venture capital firms.
- Drive post-mortems that lead to operational change, not process for its own sake
Requirements
- 5+ years of incident response experience or equivalent demonstrated impact, with cloud IR depth across both AWS and GCP
- Experience leading live incidents end to end - triage, containment, eradication, forensic investigation, and post-mortem - across cloud, SaaS, identity, and endpoint surfaces
- Experience running proactive, hypothesis-driven threat hunts using current TTPs and intel
- We weight transferable capability over experience with any specific product
- Experience defending against nation-state threat actors or organized criminal groups
- Working knowledge of AI/agent systems and their security implications, particularly in SOC workflows
- Experience translating the technical reality of an incident (blast radius, containment status, disclosure decisions) into language non-technical stakeholders can act on.
Nice to have
- GCIH or equivalent IR certification preferred
Skills
- Run incidents end to end, from first alert to post-mortem, across cloud and SaaS environments
Compensation
- The anticipated salary range for this role is between $243,000 - $284,000, actual starting pay may vary based on a range of factors which can include experience, skills, and scope.
Company info
- Write the detections that catch real threats, with a strong bias toward signal over noise and broad MITRE ATT&CK coverage
- Help shape the next generation of our SOC, including AI agent integration into triage and response workflows
- Founded in Silicon Valley in 2009 by Marc Andreessen and Ben Horowitz, Andreessen Horowitz (aka a16z) is a venture capital firm that backs bold entrepreneurs building the future through technology.
- We are stage agnostic.
This listing is sourced directly from a16z's careers page and normalized into a canonical job model.