Loading jobs…
Loading jobs…
Andreessen Horowitz — San Francisco California
Founded in Silicon Valley in 2009 by Marc Andreessen and Ben Horowitz, Andreessen Horowitz (aka a16z) is a venture capital firm that backs bold entrepreneurs building the future through technology. We are stage agnostic . We invest in seed to venture to growth-stage technology companies, across AI , bio + healthcare , consumer , crypto , enterprise , fintech , games , and companies building toward American dynamism .
a16z has $100B+ under management across multiple funds. We’ve established a team that is defined by respect for the entrepreneur and the company-building process; we know what it’s like to be in the founder’s shoes. We’ve invested in companies like Anduril, Airbnb, Coinbase, Cursor, Databricks, Deel, Figma, GitHub, Roblox, SpaceX, and Stripe.
Our team is at the forefront of new technology, helping founders and their companies impact and change the world. The Role We're hiring a Staff Incident Response Engineer to anchor a16z's detection and response work. You'll own incident triage and response across AWS and GCP, write the detections that catch real threats in our SIEM, and run point when something serious happens.
The threats here are not theoretical. We see capital call wire fraud attempts, vishing campaigns, social engineering against IT and partners, and occasionally more sophisticated actors (nation-state groups, organized criminal operations) who specifically target venture capital firms. Your work protects the firm, our LPs, and our portfolio companies.
You'll work day to day with the Head of Cybersecurity, Security Engineering, IT, and Legal. This role requires an in-office presence 2 days a week in our San Francisco, CA office.
Minimum Qualifications
5+ years of incident response experience or equivalent demonstrated impact, with cloud IR depth across both AWS and GCP Experience leading live incidents end to end — triage, containment, eradication, forensic investigation, and post-mortem — across cloud, SaaS, identity, and endpoint surfaces Experience running proactive, hypothesis-driven threat hunts using current TTPs and intel Hands-on detection authoring in modern SIEM platforms (Sigma, KQL, or equivalent) and experience working with detection-as-code Experience building detection frameworks and contributing to SIEM architecture decisions Strong Python scripting. This is a role where you build automation, not one where you only operate someone else's Demonstrated capability across modern security tooling categories (cloud telemetry, EDR, SOAR, SIEM). We weight transferable capability over experience with any specific product GCIH or equivalent IR certification preferred Comfortable in a fast-moving environment where security is expected to enable the business Experience defending against nation-state threat actors or organized criminal groups Working knowledge of AI/agent systems and their security implications, particularly in SOC workflows Experience translating the technical reality of an incident (blast radius, containment status, disclosure decisions) into language non-technical stakeholders can act on.