Fireworks AI logo

Fireworks AI

Security Operations Lead

Hybrid

Part remote, part office, you need to live within commuting distance of a named location.

Hybrid · San Mateo

Employer listed it 5 weeks ago · Added yesterday

Been open since 5 weeks ago, still being checked, but it has been live a while.

Salary

$180,000 to $210,000

Location

Hybrid · San Mateo

Timezone

Not stated

Contract

Full-time

Experience

Lead

Category

Software

Published by the employer

Remote flexibility

Hybrid

This role is only partly remote, the employer expects time in the office around San Mateo, New York, United States, Remote, Hybrid, so you need to live within commuting distance.

What the employer says

  • Source listing states candidate location: "San Mateo, New York, United States, Remote, Hybrid"
  • Listing mentions "Hybrid"

What Nomaders makes of it

  • Not suitable if you plan to move between countries

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About Us:

Fireworks is the platform for specialized intelligence, enabling companies to build, train, and serve AI models tailored to their own data, workflows, and products. Founded by the team behind PyTorch and backed by AMD, Atreides, Benchmark Capital, Index Ventures, Lightspeed, NVIDIA, Sequoia Capital, and TCV, Fireworks powers production AI with hundreds of state-of-the-art open models across text, image, embedding, audio, and multimodal workloads. Today, Fireworks is a Series D company valued at $17.5 billion, bringing together an ambitious, collaborative team that's building the future of enterprise AI.

About the role

We're hiring our first Security Operations Lead to build and run the SecOps function at Fireworks AI. As we scale our AI infrastructure platform globally, we're investing in a modern detection and response capability anchored on CrowdStrike (EDR and SIEM, 365-day retention), Console AI for ticketing, and Incident.io for on-call and incident management. We have a Security Incident Response Plan (SIRP) in place that you'll build on, and you'll own the function end-to-end: standing up detection content, operationalizing our incident response playbooks, running threat intel into action, and building the operational muscle that keeps Fireworks resilient as we grow. This role sits within the Security team and will primarily support Corporate Security and own incident response broadly, while partnering closely with Security Engineering on infrastructure-related incidents — bridging both areas. This is an IC-to-manager role: you’ll start hands-on building and running the function, growing into a people leader as the team scales.

What you'll do

Lead the rollout, tuning, and ongoing operation of CrowdStrike across our endpoint and cloud environment and SIEM use cases, partnering with IT and Security Engineering on deployment and coverage

Define and operate our detection and response program: build detection content, establish triage and escalation workflows, and continuously measure and improve coverage against frameworks like MITRE ATT&CK

Own incident response end-to-end: operationalize our existing SIRP into detailed playbooks, run incidents, lead post-incident reviews, and drive lessons learned into program improvements

Stand up our security operations workflow, including SOAR automation with Incident.io for alerting, on-call, and incident orchestration, while also defining how incidents self-submitted through our IT ticketing system are triaged and handled as one-off cases — along with the SLAs and metrics the function runs on

Build and operationalize a threat intelligence capability: track threats relevant to AI infrastructure and our customer base, and translate intel into detections, hardening, and tabletop scenarios

Partner closely with Infrastructure, Corporate Security, and other cross-functional teams across the organization, engaging as needed to support incidents and shared initiatives

How the role will grow

As the function matures, you'll have the opportunity to:

Hire and build the SecOps team, growing from IC to people leader

Expand 24x7 coverage and adjacent capabilities like cloud detection engineering, insider threat, or red team / purple team operations

Shape the broader security strategy as a senior leader in the function

What we're looking for

7+ years in security operations, detection and response, incident response, or a closely related field

Hands-on experience with EDR platforms (CrowdStrike strongly preferred; SentinelOne, Defender, or similar also relevant) including detection engineering and tuning

Strong detection engineering background: you've written, tested, and maintained detection content at scale and understand the tradeoffs between coverage, fidelity, and analyst load

Demonstrated incident response leadership: you've run real incidents from triage through executive communication and post-incident review

Strong scripting and automation skills (Python, SOAR platforms) applied to detection, response, and reporting workflows

Working knowledge of cloud security operations (AWS, GCP, or Azure) and the unique telemetry, attack patterns, and response considerations of cloud-native environments

Experience building or significantly maturing a SecOps function, including tooling selection, process design, and metrics

Requirements

The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, hybrid, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Fireworks AI, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 1d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$180,000 to $210,000 · You'll be taken to the employer's careers page.