Security engineer, detection and response (UK)Active

The opportunity

WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence.

What you'll do

  • Design and implement detection strategies that identify AI-specific threats: including prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training datasets or model weights across our distributed infrastructure

  • Build automated response playbooks and orchestration workflows that contain: threats without human intervention, creating self-healing security systems that reduce mean time to response from hours to minutes while automatically remediating compromised inference endpoints

  • Lead security incident response coordination across all teams (Cloud, AppSec,: Enterprise, AI Security) when AI infrastructure or models are compromised, conducting forensic investigations on training pipeline attacks and model manipulation attempts while drafting clear incident communications for engineering and executive leadership

  • Hunt proactively for sophisticated threats across GPU clusters and training: infrastructure by analyzing model outputs for signs of compromise, reproducing AI-specific vulnerabilities from security research, and identifying visibility gaps in distributed training environments before adversaries exploit them

  • Build detection-as-code frameworks with version control and automated: deployment, onboard telemetry from AI training infrastructure and inference endpoints, and create dashboards that track model security metrics, GPU utilization patterns, and access to sensitive research data

  • Collaborate cross-functionally as the operational security partner for all: teams – translating AI Security's threat research into production detections, monitoring Cloud Infrastructure's GPU clusters for threats, detecting customer-impacting incidents for Software Security Engineering, and enabling responsible AI development through security guardrails

What they're looking for

  • Maintain 24/7 on-call rotation for critical AI security incidents, responding: to real-time threats targeting our platform while continuously improving detection coverage and automation capabilities as our AI systems evolve
  • + years in security operations, detection engineering, or incident response: with a proven track record of identifying and stopping sophisticated attacks in production environments, plus 3+ years specifically securing AI/ML infrastructure, high-performance computing environments, or other distributed systems at scale
  • Strong programming skills in Python, KQL, SPL, or similar languages that: allow you to build custom detection logic, automate response workflows, and create tools that operationalize security at scale across cloud-native and distributed computing environments
  • Experience with SIEM platforms, detection technologies, and forensic: investigation techniques with demonstrated ability to build detection for novel attack techniques that don't have established patterns yet and to conduct forensics in complex distributed environments