Detection & Response Engineer

Runway
$240,000 - $290,000Remote

About The Position

Runway is seeking a Detection & Response Engineer to join their Security team. This role is responsible for identifying and mitigating attacks against the company's infrastructure, research environment, and products. The position requires a unique approach to security due to the company's focus on AI and video models, involving research compute, large datasets, and AI-assisted tooling. The engineer will build the detection and response program using a code-based approach for detections and automation for responses, with a focus on queryable evidence. This is a role with significant ownership, from logging to incident closure, reporting to the head of security and collaborating with platform and research engineers.

Requirements

  • Hands-on incident response experience: you've triaged live alerts, led investigations and written up what happened afterward
  • Experience building and tuning detections in a modern SIEM, ideally managed as code
  • Working knowledge of how attackers move through cloud and Kubernetes environments (IAM abuse, container escape, credential theft, supply chain compromise) and what that leaves behind in logs
  • Comfort writing Python, Typescript, Rust or another language to automate response work and connect security tools
  • Familiarity with at least one major cloud platform and with Kubernetes at the level of audit logs, RBAC and workload identity
  • Clear writing. Incident timelines, detection documentation and updates to leadership are all part of the job
  • Judgment about what to alert on, what to automate and when to wake someone up

Nice To Haves

  • Experience monitoring GPU or HPC-style infrastructure, or research environments with large datasets
  • Experience building detections or guardrails for AI agents, LLM tooling or MCP servers
  • Cloud forensics experience: disk and memory acquisition, cloud audit trail reconstruction, chain of custody
  • Published open source detection content

Responsibilities

  • Own detection and response end to end: what we log, what we alert on, how we triage and how we recover
  • Write and tune detections as code across multiple cloud environments, Kubernetes, identity systems, endpoints and SaaS, and measure them on coverage and precision rather than alert volume
  • Lead incident response from the first alert through containment and forensics, then write the post-incident review people actually read
  • Build automation that takes toil out of triage, including enrichment, correlation, containment actions and evidence collection, and use LLM-based tooling where it holds up under audit
  • Monitor AI agents and developer tooling operating inside our environment, and turn that into concrete telemetry and controls
  • Partner with platform and research engineers so new systems ship with logging and response playbooks in place on day one
  • Run threat hunts and tabletop exercises against the parts of the environment that worry you most, and fix what you find
  • Turn incident and detection metrics into evidence for SOC 2, ISO 27001 and enterprise customer security reviews, working with our GRC team
  • Participate in an on-call rotation for security incidents

Benefits

  • Competitive market rates for our size, stage and industry
  • Overall compensation package
  • Equal opportunity to succeed
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service