a16z

a16z

Partner 20, Staff Engineer, Incident Response

San Francisco, California, United States · Staff+

Sponsorship not specified$243k-$284kDetected 50 days ago
PythonGitDatabricksAWSGCPCybersecuritySIEMKQLSOARIncident ResponseFigmaLeadership

About the role

  • We're hiring a Staff Incident Response Engineer to anchor a16z's detection and response work.
  • Your work protects the firm, our LPs, and our portfolio companies.
  • You'll work day to day with the Head of Cybersecurity, Security Engineering, IT, and Legal.

Responsibilities

  • We've established a team that is defined by respect for the entrepreneur and the company-building process; we know what it's like to be in the founder's shoes.
  • You'll own incident triage and response across AWS and GCP, write the detections that catch real threats in our SIEM, and run point when something serious happens.
  • We see capital call wire fraud attempts, vishing campaigns, social engineering against IT and partners, and occasionally more sophisticated actors (nation-state groups, organized criminal operations) who specifically target venture capital firms.
  • Drive post-mortems that lead to operational change, not process for its own sake

Requirements

  • 5+ years of incident response experience or equivalent demonstrated impact, with cloud IR depth across both AWS and GCP
  • Experience leading live incidents end to end - triage, containment, eradication, forensic investigation, and post-mortem - across cloud, SaaS, identity, and endpoint surfaces
  • Experience running proactive, hypothesis-driven threat hunts using current TTPs and intel
  • We weight transferable capability over experience with any specific product
  • Experience defending against nation-state threat actors or organized criminal groups
  • Working knowledge of AI/agent systems and their security implications, particularly in SOC workflows
  • Experience translating the technical reality of an incident (blast radius, containment status, disclosure decisions) into language non-technical stakeholders can act on.

Nice to have

  • GCIH or equivalent IR certification preferred

Skills

  • Run incidents end to end, from first alert to post-mortem, across cloud and SaaS environments

Compensation

  • The anticipated salary range for this role is between $243,000 - $284,000, actual starting pay may vary based on a range of factors which can include experience, skills, and scope.

Company info

  • Write the detections that catch real threats, with a strong bias toward signal over noise and broad MITRE ATT&CK coverage
  • Help shape the next generation of our SOC, including AI agent integration into triage and response workflows
  • Founded in Silicon Valley in 2009 by Marc Andreessen and Ben Horowitz, Andreessen Horowitz (aka a16z) is a venture capital firm that backs bold entrepreneurs building the future through technology.
  • We are stage agnostic.

This listing is sourced directly from a16z's careers page and normalized into a canonical job model.