Runway Logo

Runway

Detection & Response Engineer

Posted 5 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
240K-290K Annually
Entry level
Remote
Hiring Remotely in USA
240K-290K Annually
Entry level
Owns the end-to-end detection and response program for cloud infrastructure, Kubernetes, research environments, AI tooling, and products. Responsibilities include developing detections as code, leading incident investigations, automating triage and containment, monitoring AI agents, conducting threat hunts and tabletop exercises, improving security telemetry, supporting SOC 2 and ISO 27001 evidence collection, and participating in security incident on-call rotations.
The summary above was generated by AI

We are building AI to simulate the world through merging art and science.
We believe that world models are at the frontier of progress in artificial intelligence. Language models alone won’t solve the world’s hardest problems – robotics, disease, scientific discovery. Real progress requires models that experience the world and learn from their mistakes, the same way that humans do. And this kind of trial and error can be massively accelerated when done in simulation, rather than in the real world.
World models offer the most clear path to general-purpose simulation, changing how stories are told, how scientific progress is made and how the next frontiers of humanity are reached.

Our team consists of creative, open minded, caring and ambitious people who are determined to change the world. We aspire to continuously build impossible things and our ability to do so relies on building an incredible team. If you are driven to do the same, we'd love to hear from you.

About the role

Open to hiring remote — we also have offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv.

Runway is hiring a Detection & Response Engineer to own how we find and stop attacks against our infrastructure, our research environment and our products.

Securing a company that trains and serves frontier video models is a different problem from securing a typical SaaS product. The environment includes research compute, large training datasets, a fast-moving build pipeline and engineers who work inside AI-assisted tooling every day. Each of those changes what an attack looks like and what you need to see to catch it.

You'll join the Security team and build our detection and response program the way an engineer would: detections as code, response as automation, evidence as something you can query. This is a role with real ownership: you'll own the detection program end to end, from what we log to how quickly we close an incident. You'll report to the head of security, partner with engineers across platform and research, and shape how this function grows from here.

What you'll do
  • Own detection and response end to end: what we log, what we alert on, how we triage and how we recover

  • Write and tune detections as code across multiple cloud environments, Kubernetes, identity systems, endpoints and SaaS, and measure them on coverage and precision rather than alert volume

  • Lead incident response from the first alert through containment and forensics, then write the post-incident review people actually read

  • Build automation that takes toil out of triage, including enrichment, correlation, containment actions and evidence collection, and use LLM-based tooling where it holds up under audit

  • Monitor AI agents and developer tooling operating inside our environment, and turn that into concrete telemetry and controls

  • Partner with platform and research engineers so new systems ship with logging and response playbooks in place on day one

  • Run threat hunts and tabletop exercises against the parts of the environment that worry you most, and fix what you find

  • Turn incident and detection metrics into evidence for SOC 2, ISO 27001 and enterprise customer security reviews, working with our GRC team

  • Participate in an on-call rotation for security incidents

What you'll need
  • Hands-on incident response experience: you've triaged live alerts, led investigations and written up what happened afterward

  • Experience building and tuning detections in a modern SIEM, ideally managed as code

  • Working knowledge of how attackers move through cloud and Kubernetes environments (IAM abuse, container escape, credential theft, supply chain compromise) and what that leaves behind in logs

  • Comfort writing Python, Typescript, Rust or another language to automate response work and connect security tools

  • Familiarity with at least one major cloud platform and with Kubernetes at the level of audit logs, RBAC and workload identity

  • Clear writing. Incident timelines, detection documentation and updates to leadership are all part of the job

  • Judgment about what to alert on, what to automate and when to wake someone up

Even better if you have
  • Experience monitoring GPU or HPC-style infrastructure, or research environments with large datasets

  • Experience building detections or guardrails for AI agents, LLM tooling or MCP servers

  • Cloud forensics experience: disk and memory acquisition, cloud audit trail reconstruction, chain of custody

  • Published open source detection content

Runway strives to recruit and retain exceptional talent from diverse backgrounds while ensuring pay equity for our team. Our salary ranges are based on competitive market rates for our size, stage and industry, and salary is just one part of the overall compensation package we provide.

There are many factors that go into salary determinations, including relevant experience, skill level and qualifications assessed during the interview process, and maintaining internal equity with peers on the team. The range shared below is a general expectation for the function as posted, but we are also open to considering candidates who may be more or less experienced than outlined in the job description. In this case, we will communicate any updates in the expected salary range.

Lastly, the provided range is the expected salary for candidates in the U.S. Outside of those regions, there may be a change in the range, which again, will be communicated to candidates.

Working at Runway

Great things come from great teams. We’d love to hear from you.

We’re committed to creating a space where our employees can bring their full selves to work and have equal opportunity to succeed. So regardless of race, gender identity or expression, sexual orientation, religion, origin, ability, age, veteran status, if joining this mission speaks to you, we encourage you to apply.

More about Runway

  • Universal World Simulator

  • GWM-1

  • Gen-4.5

  • General World Models

  • Robotics SDK

  • Conversational Real-time Agents

  • Runway Studios

We're excited to be recognized as a best place to work:

Crain's | InHerSight | BuiltIn NYC | INC

Similar Jobs

20 Days Ago
Remote or Hybrid
US
137K-191K Annually
Senior level
137K-191K Annually
Senior level
Information Technology
Engineer AI-powered threat detections, automated response playbooks, and continuous adversary emulation. Apply machine learning and LLMs to security operations, conduct threat hunting and AI red teaming, map coverage to MITRE ATT&CK, and develop detection-as-code through CI/CD. Build production-grade Python integrations, measurable containment capabilities, and safe autonomous defenses with guardrails. Mentor security professionals and collaborate across threat response, cyber defense engineering, and platform teams.
Top Skills: AIAtomic Red TeamCalderaCi/CdCloud SecurityCobalt StrikeCrowdstrikeEntra IdInfrastructure-As-CodeLlmsMachine LearningMicrosoft DefenderMicrosoft SentinelMitre Att&CkPolicy-As-CodePythonSIEMSoarSplunkTinesXdr
One Month Ago
Remote
United States
80K-134K Annually
Mid level
80K-134K Annually
Mid level
Cloud • Security • Cybersecurity
Operate SIEM monitoring and alerting, perform hypothesis-driven threat hunts, develop and tune detections across multiple SIEMs, translate intelligence into detection logic, escalate incidents with MITRE ATT&CK mapping, and produce runbooks, dashboards, and documentation to improve client security posture.
Top Skills: AnsibleAWSAzureDetection-As-CodeElkGCPGitGitlabLogrhythmMicrosoft SentinelMitre Att&CkNist 800-53SplunkSumo LogicTerraform
One Month Ago
In-Office or Remote
Boston, MA, USA
110K-170K Annually
Expert/Leader
110K-170K Annually
Expert/Leader
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
Lead detection and response across cloud, blockchain, and AI surfaces. Build detection coverage, run incident response, deploy SOC AI tooling, maintain SIEM/SOAR and orchestration, and collaborate cross-functionally to remediate threats and improve visibility. Participate in on-call rotation and support threat modeling, vulnerability scans, and custom tooling.
Top Skills: Agentic WorkflowsAi ToolingAWSBlockchainCase ManagementCspmDetections As CodeEksGCPGoGoogle SuiteIamIdentity FederationKmsKubernetesmacOSOciOn-Chain MonitoringPantherPythonSIEMSlackSmart ContractsSoarTinesWiz

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account