# Security engineer, detection and response (UK)

[Writer](https://gurify.com/jobs?q=Writer) · London, United Kingdom · Posted last week

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/WRITER/c4508e49-bfd4-44f2-af41-bf695a83605d)

## Job description

🚀 About WRITER

WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we're proving it's possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER's end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company's data and fueled by WRITER's enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we're looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

Join WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's transforming how the world works. You'll build sophisticated detection systems that identify attacks targeting our AI platform, training data, and model deployments while creating automated response capabilities that scale with our explosive growth. This isn't just traditional security work – you're defending cutting-edge AI/AGI systems against adversaries who are evolving their tactics as fast as AI itself advances.

This role combines hands-on security engineering with strategic thinking to stay ahead of novel threats that don't exist in textbooks yet. You'll be the operational arm of our security function, translating threat intelligence into real-time detections, coordinating incident response across multiple teams, and hunting for sophisticated attacks across GPU clusters and distributed training environments. If you're excited by the challenge of securing systems that are fundamentally different from anything you've protected before, this is your opportunity to define what AI security engineering looks like at scale.

You'll work closely with our AI Security research team, Cloud Infrastructure, Software Security Engineering, and AI researchers to build a defense-in-depth strategy that protects one of the most valuable AI platforms in the industry. The threats are real, the stakes are high, and the problems are intellectually fascinating.

This role can be based in San reporting to our head of security operations.

🦸🏻‍♀️ What you’ll do

- Design and implement detection strategies that identify AI-specific threats including prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training datasets or model weights across our distributed infrastructure

- Build automated response playbooks and orchestration workflows that contain threats without human intervention, creating self-healing security systems that reduce mean time to response from hours to minutes while automatically remediating compromised inference endpoints

- Lead security incident response coordination across all teams (Cloud, AppSec, Enterprise, AI Security) when AI infrastructure or models are compromised, conducting forensic investigations on training pipeline attacks and model manipulation attempts while drafting clear incident communications for engineering and executive leadership

- Hunt proactively for sophisticated threats across GPU clusters and training infrastructure by analyzing model outputs for signs of compromise, reproducing AI-specific vulnerabilities from security research, and identifying visibility gaps in distributed training environments before adversaries exploit them

- Build detection-as-code frameworks with version control and automated deployment, onboard telemetry from AI training infrastructure and inference endpoints, and create dashboards that track model security metrics, GPU utilization patterns, and access to sensitive research data

- Collaborate cross-functionally as the operational security partner for all teams – translating AI Security's threat research into production detections, monitoring Cloud Infrastructure's GPU clusters for threats, detecting customer-impacting incidents for Software Security Engineering, and enabling responsible AI development through security guardrails

- Maintain 24/7 on-call rotation for critical AI security incidents, responding to real-time threats targeting our platform while continuously improving detection coverage and automation capabilities as our AI systems evolve

⭐️ What you need

- 3-5+ years in security operations, detection engineering, or incident response with a proven track record of identifying and stopping sophisticated attacks in production environments, plus 3+ years specifically securing AI/ML infrastructure, high-performance computing environments, or other distributed systems at scale

- Strong programming skills in Python, KQL, SPL, or similar languages that allow you to build custom detection logic, automate response workflows, and create tools that operationalize security at scale across cloud-native and distributed computing environments

- Experience with SIEM platforms, detection technologies, and forensic investigation techniques with demonstrated ability to build detection for novel attack techniques that don't have established patterns yet and to conduct forensics in complex distributed environments

- Self-directed execution mindset with a track record of securing high-value intellectual property, automating incident response in complex environments, and identifying critical security gaps through proactive threat hunting before they become incidents

- Deep alignment with WRITER's values – you naturally Connect across security, infrastructure, and AI research teams to build comprehensive defenses, you Challenge assumptions about what's possible in AI security engineering, and you Own the protection of our AI platform with unwavering accountability and a commitment to staying ahead of evolving threats

🍩 Benefits & perks (UK full-time employees):

- Generous PTO, plus company holidays

- Comprehensive medical and dental insurance

- Paid parental leave for all parents (16 weeks)

- Fertility and family planning support

- Early-detection cancer testing through Galleri https://www.galleri.com/partner/writer

- Competitive pension scheme and company contribution

- Annual work-life stipends for:

 - Wellness stipend for gym, massage/chiropractor, personal training, etc.

 - Learning and development stipend

- Company-wide off-sites and team off-sites

- Competitive compensation and company stock options

**Live in Writer’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- SN [Senior Network Security Engineer (Palo Alto SASE) - Natilik](https://gurify.com/job/senior-network-security-engineer-palo-alto-sase-natilik-56f1fadf72a1) London, United Kingdom · 3 days ago
- IS [Security Engineer (Corporate ...](https://gurify.com/job/security-engineer-corporate-at-isomorphiclabs-17e7d61d3f92) Isomorphiclabs · London · yesterday
- SN [Senior Network Security Engineer - Natilik](https://gurify.com/job/senior-network-security-engineer-natilik-4350d3f41943) London, United Kingdom · 3 days ago
- AN [Product Security Engineer](https://gurify.com/job/product-security-engineer-at-andurilindustries-c480be193db1) Andurilindustries · London, United Kingdom · 2 weeks ago
- CA [Lead Application Security Engineer](https://gurify.com/job/lead-application-security-engineer-at-cais-2e04484adf2f) Cais · London, United Kingdom · 2 weeks ago
- LE [Senior Security Engineer](https://gurify.com/job/senior-security-engineer-at-lendable-b45c1c616d15) Lendable · London · 2 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security engineer, detection and response (UK)","description":"\u003Cp\u003E\u0026#128640; About WRITER\u003C/p\u003E\u003Cp\u003EWRITER is where the world\u0026#39;s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we\u0026#39;re proving it\u0026#39;s possible \u2013 through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER\u0026#39;s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company\u0026#39;s data and fueled by WRITER\u0026#39;s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.\u003C/p\u003E\u003Cp\u003EFounded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we\u0026#39;re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.\u003C/p\u003E\u003Cp\u003E\u0026#128208; About the role\u003C/p\u003E\u003Cp\u003EJoin WRITER\u0026#39;s security team as a staff detection and response engineer and help protect the AI infrastructure that\u0026#39;s transforming how the world works. You\u0026#39;ll build sophisticated detection systems that identify attacks targeting our AI platform, training data, and model deployments while creating automated response capabilities that scale with our explosive growth. This isn\u0026#39;t just traditional security work \u2013 you\u0026#39;re defending cutting-edge AI/AGI systems against adversaries who are evolving their tactics as fast as AI itself advances.\u003C/p\u003E\u003Cp\u003EThis role combines hands-on security engineering with strategic thinking to stay ahead of novel threats that don\u0026#39;t exist in textbooks yet. You\u0026#39;ll be the operational arm of our security function, translating threat intelligence into real-time detections, coordinating incident response across multiple teams, and hunting for sophisticated attacks across GPU clusters and distributed training environments. If you\u0026#39;re excited by the challenge of securing systems that are fundamentally different from anything you\u0026#39;ve protected before, this is your opportunity to define what AI security engineering looks like at scale.\u003C/p\u003E\u003Cp\u003EYou\u0026#39;ll work closely with our AI Security research team, Cloud Infrastructure, Software Security Engineering, and AI researchers to build a defense-in-depth strategy that protects one of the most valuable AI platforms in the industry. The threats are real, the stakes are high, and the problems are intellectually fascinating.\u003C/p\u003E\u003Cp\u003EThis role can be based in San  reporting to our head of security operations.\u003C/p\u003E\u003Cp\u003E\u0026#129464;\u0026#127995;\u200D\u2640\uFE0F What you\u2019ll do\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EDesign and implement detection strategies that identify AI-specific threats including prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training datasets or model weights across our distributed infrastructure\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild automated response playbooks and orchestration workflows that contain threats without human intervention, creating self-healing security systems that reduce mean time to response from hours to minutes while automatically remediating compromised inference endpoints\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELead security incident response coordination across all teams (Cloud, AppSec, Enterprise, AI Security) when AI infrastructure or models are compromised, conducting forensic investigations on training pipeline attacks and model manipulation attempts while drafting clear incident communications for engineering and executive leadership\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHunt proactively for sophisticated threats across GPU clusters and training infrastructure by analyzing model outputs for signs of compromise, reproducing AI-specific vulnerabilities from security research, and identifying visibility gaps in distributed training environments before adversaries exploit them\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild detection-as-code frameworks with version control and automated deployment, onboard telemetry from AI training infrastructure and inference endpoints, and create dashboards that track model security metrics, GPU utilization patterns, and access to sensitive research data\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECollaborate cross-functionally as the operational security partner for all teams \u2013 translating AI Security\u0026#39;s threat research into production detections, monitoring Cloud Infrastructure\u0026#39;s GPU clusters for threats, detecting customer-impacting incidents for Software Security Engineering, and enabling responsible AI development through security guardrails\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMaintain 24/7 on-call rotation for critical AI security incidents, responding to real-time threats targeting our platform while continuously improving detection coverage and automation capabilities as our AI systems evolve\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E\u2B50\uFE0F What you need\u003C/p\u003E\u003Cul\u003E\u003Cli\u003E3-5\u002B years in security operations, detection engineering, or incident response with a proven track record of identifying and stopping sophisticated attacks in production environments, plus 3\u002B years specifically securing AI/ML infrastructure, high-performance computing environments, or other distributed systems at scale\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong programming skills in Python, KQL, SPL, or similar languages that allow you to build custom detection logic, automate response workflows, and create tools that operationalize security at scale across cloud-native and distributed computing environments\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with SIEM platforms, detection technologies, and forensic investigation techniques with demonstrated ability to build detection for novel attack techniques that don\u0026#39;t have established patterns yet and to conduct forensics in complex distributed environments\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESelf-directed execution mindset with a track record of securing high-value intellectual property, automating incident response in complex environments, and identifying critical security gaps through proactive threat hunting before they become incidents\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDeep alignment with WRITER\u0026#39;s values \u2013 you naturally Connect across security, infrastructure, and AI research teams to build comprehensive defenses, you Challenge assumptions about what\u0026#39;s possible in AI security engineering, and you Own the protection of our AI platform with unwavering accountability and a commitment to staying ahead of evolving threats\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E\u0026#127849; Benefits \u0026amp; perks (UK full-time employees):\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EGenerous PTO, plus company holidays\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EComprehensive medical and dental insurance\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPaid parental leave for all parents (16 weeks)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFertility and family planning support\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEarly-detection cancer testing through Galleri https://www.galleri.com/partner/writer\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECompetitive pension scheme and company contribution\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E- Annual work-life stipends for:\u003Cbr /\u003E   \u003Cbr /\u003E   - Wellness stipend for gym, massage/chiropractor, personal training, etc.\u003Cbr /\u003E   \u003Cbr /\u003E   - Learning and development stipend\u003C/p\u003E\u003Cul\u003E\u003Cli\u003ECompany-wide off-sites and team off-sites\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECompetitive compensation and company stock options\u003C/li\u003E\u003C/ul\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-engineer-detection-and-response-uk-at-writer-7fb5e9f3ad33"},"url":"https://gurify.com/job/security-engineer-detection-and-response-uk-at-writer-7fb5e9f3ad33","datePosted":"2026-07-30","validThrough":"2026-09-21T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Writer","sameAs":"https://jobs.ashbyhq.com/WRITER"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Security engineer, detection and response (UK)","item":"https://gurify.com/job/security-engineer-detection-and-response-uk-at-writer-7fb5e9f3ad33"}]}
```
