Staff Security Engineer, Incident Response at CoreWeave
CoreWeave is seeking a Staff Security Engineer, Incident Response to lead and enhance the company’s security incident response program across its cloud-based GPU infrastructure. You will detect, triage, investigate, and remediate security incidents, and you will design scalable IR processes, runbooks, and forensics workflows. You will collaborate with SRE, security engineering, and product teams to improve detection, containment, and remediation across cloud and on-prem components, and you will drive automation and telemetry improvements.
Responsibilities
- Lead and coordinate incident response activities for security incidents across CoreWeave's infrastructure.
- Develop, maintain, and improve incident response playbooks, runbooks, and post-incident review processes.
- Monitor alerts from SIEM/EDR, perform triage, containment, eradication, and recovery actions.
- Conduct digital forensics on involved systems, preserving chain of custody and ensuring evidence integrity.
- Collaborate with SRE, security engineering, and product teams to enhance detection, telemetry, and security controls across cloud and GPU workloads.
- Drive automation and tooling improvements to reduce mean time to detect/resolve incidents.
- Lead blue-team exercises, threat hunting efforts, and vulnerability management initiatives.
- Provide mentorship and guidance to junior security engineers and coordinate communications with stakeholders and executives.
Requirements
- 5+ years of hands-on incident response or security engineering experience.
- Strong knowledge of security operations, incident response lifecycle, forensics, and malware analysis.
- Experience with SIEM/EDR tools (e.g., Splunk, Elastic, CrowdStrike, Palo Alto products) and blue-team workflows.
- Proficiency in at least one scripting language (Python preferred).
- Experience with cloud platforms (AWS, Azure, GCP) and containerized workloads (Kubernetes, Docker).
- Excellent communication and cross-functional collaboration skills; ability to translate technical findings for non-technical stakeholders.
- Bachelor’s degree in Computer Science, Cybersecurity, or related field; security certifications (GCIH, CISSP, CEH, or equivalent) preferred.
Nice to have
- Experience with GPU/HPC environments and AI workloads.
- Knowledge of threat intelligence, vulnerability management, and patching processes.
Benefits
Competitive compensation and opportunities for growth within a fast-paced security organization.