← Back to results

Security Operations Lead

Lead the Security Operations function at Fireworks AI, building detection and response capabilities as the company scales its AI infrastructure.

Location
San Mateo
Compensation
Not disclosed
Level
lead
Type
full time

Posted by employer 1 month ago

First seen on Joblaze 1 month ago

Last verified on the company career page 7 hours ago

Requirements

Experience
7+ years

Not disclosed in this posting: compensation, work arrangement, visa sponsorship.

Joblaze summary

The Security Operations Lead at Fireworks AI is responsible for establishing and managing the security operations function, focusing on incident response and detection capabilities. This role requires expertise in EDR platforms, particularly CrowdStrike, along with strong skills in detection engineering and automation. Ideal candidates will have over seven years of experience in security operations and a proven track record in incident management. As the team grows, this position offers the opportunity to transition from an individual contributor to a leadership role.

Joblaze insights

  • Listed about a month ago — first seen on Joblaze August 21, 2026. Last confirmed on Fireworks AI's careers page October 8, 2026.
  • Python appears in 30.6% of 98 comparable lead security roles; MITRE ATT&CK appears in 1% of 98 comparable lead security roles.

Quick facts

How much experience is required?
At least 7 years of relevant experience for this Security Operations Lead role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Azure, CrowdStrike, GCP, Incident.io, MITRE ATT&CK.
What seniority level is this role?
Fireworks AI targets lead candidates for this position.
Is this full-time or contract?
Full-time for this Security Operations Lead role at Fireworks AI.

From the original posting

About the role

We're hiring our first Security Operations Lead to build and run the SecOps function at Fireworks AI. As we scale our AI infrastructure platform globally, we're investing in a modern detection and response capability anchored on CrowdStrike (EDR and SIEM, 365-day retention), Console AI for ticketing, and Incident.io for on-call and incident management. We have a Security Incident Response Plan (SIRP) in place that you'll build on, and you'll own the function end-to-end: standing up detection content, operationalizing our incident response playbooks, running threat intel into action, and building the operational muscle that keeps Fireworks resilient as we grow. This role sits within the Security team and will primarily support Corporate Security and own incident response broadly, while partnering closely with Security Engineering on infrastructure-related incidents — bridging both areas. This is an IC-to-manager role: you’ll start hands-on building and running the function, growing into a people leader as the team scales.

What you'll do

  • Lead the rollout, tuning, and ongoing operation of CrowdStrike across our endpoint and cloud environment and SIEM use cases, partnering with IT and Security Engineering on deployment and coverage

  • Define and operate our detection and response program: build detection content, establish triage and escalation workflows, and continuously measure and improve coverage against frameworks like MITRE ATT&CK

  • Own incident response end-to-end: operationalize our existing SIRP into detailed playbooks, run incidents, lead post-incident reviews, and drive lessons learned into program improvements

  • Stand up our security operations workflow, including SOAR automation with Incident.io for alerting, on-call, and incident orchestration, while also defining how incidents self-submitted through our IT ticketing system are triaged and handled as one-off cases — along with the SLAs and metrics the function runs on

  • Build and operationalize a threat intelligence capability: track threats relevant to AI infrastructure and our customer base, and translate intel into detections, hardening, and tabletop scenarios

  • Partner closely with Infrastructure, Corporate Security, and other cross-functional teams across the organization, engaging as needed to support incidents and shared initiatives

How the role will grow

As the function matures, you'll have the opportunity to:

  • Hire and build the SecOps team, growing from IC to people leader

  • Expand 24x7 coverage and adjacent capabilities like cloud detection engineering, insider threat, or red team / purple team operations

  • Shape the broader security strategy as a senior leader in the function

What we're looking for

  • 7+ years in security operations, detection and response, incident response, or a closely related field

  • Hands-on experience with EDR platforms (CrowdStrike strongly preferred; SentinelOne, Defender, or similar also relevant) including detection engineering and tuning

  • Strong detection engineering background: you've written, tested, and maintained detection content at scale and understand the tradeoffs between coverage, fidelity, and analyst load

  • Demonstrated incident response leadership: you've run real incidents from triage through executive communication and post-incident review

  • Strong scripting and automation skills (Python, SOAR platforms) applied to detection, response, and reporting workflows

  • Working knowledge of cloud security operations (AWS, GCP, or Azure) and the unique telemetry, attack patterns, and response considerations of cloud-native environments

  • Experience building or significantly maturing a SecOps function, including tooling selection, process design, and metrics

  • Comfort operating in a build phase: you can write the playbook and run the playbook, and you know when to invest in process versus when to just get things done

Nice to have

  • Experience with SIEM detection engineering at scale (CrowdStrike Falcon LogScale/NG-SIEM, Splunk, Sumo Logic, Panther, or similar)

  • Experience with Incident.io, PagerDuty, or comparable incident management tooling

  • Threat intelligence experience, including operationalizing intel into detection and hardening outcomes

  • Prior experience at an AI, cloud infrastructure, or high-growth SaaS company

  • Certifications such as GCIA, GCIH, GCFA, OSCP, or similar

Why Fireworks?

  • Solve Hard Problems: Tackle challenges at the forefront of AI infrastructure, from low-latency inference to scalable model serving.

Standard company text repeated across Fireworks AI's postings is omitted here.

Similar positions

Fireworks AI
MTS, Security
Fireworks AI · San Mateo
Fireworks AI
Manager, Field Engineering
Fireworks AI · San Mateo
Fireworks AI
Senior GRC Specialist
Fireworks AI · San Mateo
Fireworks AI