About The Position

Reflection is looking for a Member of Technical Staff - Incident Detection & Response to build our detection and response capabilities from the ground up. You will have a high level of autonomy to architect solutions and drive them through both technical and organizational adversity. This role is ideal for an engineer who thrives in high-ownership, low-structure environments and has a strong "0 to 1" mindset.

Requirements

  • Experience bootstrapping an IDR or DFIR function from scratch
  • Familiarity with modern SIEM/SOAR systems
  • Experience working with various EDR/XDR platforms
  • Strong proficiency in macOS and Linux environments
  • Extensive experience working with diverse log sources including but not limited to GCP, AWS, Azure, Google Workspace, major SaaS platforms, and neocloud providers such as Together.ai, Anyscale, VoltagePark, Nvidia, GMI Cloud, etc.
  • Expertise in managing and building on Kubernetes clusters, including deploying and managing IDR tooling in multi-cloud Kubernetes environments
  • Well-founded opinions on how to detect and mitigate risk around agentic AI assistants
  • Familiarity with browser and memory forensics techniques
  • Experience with major telemetry aggregation, filtering, and routing systems such as Cribl or BindPlane
  • Comfort with Python and Golang

Responsibilities

  • Establish and lead the IDR/DFIR function, bringing an opinionated perspective on how to build a world-class program from scratch
  • Design and build the IDR infrastructure required to collect, aggregate, and route logs across geographically disparate Kubernetes clusters hosted across multiple cloud providers
  • Develop high-fidelity alerting systems that balance large log volumes with the need to minimize alert fatigue
  • Identify risks and implement mitigations for agentic AI assistants (e.g., OpenClaw, Claude Code) and protect critical assets like model weights and training data.
  • Develop containment mechanisms and entity-tracking pipelines that span laptops, SaaS platforms, and cloud/Kube infrastructure
  • Develop, maintain, and test incident response playbooks

Benefits

  • Top-tier compensation: Salary and equity structured to recognize and retain the best talent globally.
  • Health & wellness: Comprehensive medical, dental, vision, life, and disability insurance.
  • Life & family: Fully paid parental leave for all new parents, including adoptive and surrogate journeys. Financial support for family planning.
  • Benefits & balance: paid time off when you need it, relocation support, and more perks that optimize your time.
  • Opportunities to connect with teammates: lunch and dinner are provided daily. We have regular off-sites and team celebrations.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

1-10 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service