Senior Security Engineer I, Advanced Response

Weights & Biases Weights & Biases · Data AI · Bellevue, WA +3 · Technology

This role focuses on leading critical cybersecurity incidents, hunting adversaries, and building AI-powered tooling to enhance CoreWeave's defense capabilities at scale. The Senior Security Engineer will architect and build AI tools to accelerate threat detection and response, conduct deep technical investigations, and run a structured threat hunting program.

What you'd actually do

  1. Leading the most complex, highest severity cybersecurity incidents at CoreWeave end-to-end – with full ownership of outcomes, not just coordination
  2. Conducting deep technical investigations and hunts across endpoint, cloud, identity, and network data sources to establish scope, timeline, and root cause
  3. Architecting and building AI-powered tooling that drives how CoreWeave counters threats — accelerating work left and right of boom
  4. Running a structured threat hunting program informed by operationalized intelligence — turning actor profiles, campaign reporting, and TTP gaps into hunts, and turning hunt findings into durable actions to harden CoreWeave and improve our response posture
  5. Producing rigorous, risk-driven post-incident reviews that go beyond surface-level timelines and result in concrete, durable improvements

Skills

Required

  • Incident response
  • Security operations
  • Threat hunting
  • Technical investigation
  • Cloud security
  • Endpoint security
  • Identity security
  • Network security
  • Attacker TTPs
  • SQL
  • Splunk Query Language
  • HiveQL
  • Python
  • Go

Nice to have

  • Building or maturing an IR program at a cloud-native organization
  • Kubernetes
  • Containerized environments
  • AI-assisted tooling in investigation or triage workflows
  • SOAR platforms
  • Case management tooling

What the JD emphasized

  • AI-powered tooling
  • threat hunting
  • incident response
  • security operations roles
  • threat hunting at scale
  • complex, high-impact incidents
  • deep technical investigations
  • attacker TTPs
  • cloud, endpoint, identity, and network environments
  • script or automate in Python, Go, or similar

Other signals

  • AI-powered tooling
  • threat hunting
  • incident response
  • security engineering