# Security Engineer, Incident Response

[Fluidstack](https://gurify.com/jobs?q=Fluidstack) · London · Posted yesterday

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/fluidstack/412f8e9d-c6ae-497f-9f4e-522deeb26861?ashby_jid=cd97ec50-81f7-4fdd-a95b-602e6e1303a8&source=linkedin)

## Job description

### ABOUT FLUIDSTACK

We exist to make humanity more free. For most of human history, you farmed or you starved. Technology gave people more time for the things they wanted to do, instead of things they had to do. Powerful AI will be the biggest lever for human choice we've ever built - but only if models are aligned with what humanity actually wants. There are groups building AI who don't share these goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands human freedom or shrinks it.

We're singularly focused on delivering 10 to 100s of GWs of compute faster than anyone else, rethinking every layer of the stack. We acquire power, design and build data centers, and operate them - with teams spanning hardware and software. Speed and scale are our key differentiators. Come be a part of building civilization-scale infrastructure for AI.

We hire people who care deeply about this problem space. If that is you, please apply!

### HOW WE OPERATE

- Be a barrel. Full autonomy. Own things end to end, take on scope without being asked, no permission required to operate outside your core role.

- Insane urgency. We drive everything forward as fast as possible.

- Reason from first principles. Challenge every assumption. Zero analogy thinking, no egos, the best idea wins.

- Love of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward.

- Build something that actually matters. If you're going to spend your time, spend it on something that matters to the world.

### THE SECURITY TEAM

- Examples of key problems the team is working on

- You're securing the frontier of AI. The model weights training on our infrastructure are the most valuable and most targeted artifacts in technology, and we're standing up the compute to hold them faster than anyone ever has. A breach isn't a leak, it's the frontier walking out the door.

- Build the entire security program from scratch. Most leaders inherit someone else's system and spend a career patching it. Here you own it end to end, bare metal to boardroom, as we scale across continents.

- Your threat surface is measured in gigawatts. The customers running on our infrastructure are building the most consequential technology in human history, and being responsible for the physical and logical security of that work makes everything else feel small.

### ROLE SCOPE

- Lead incident response end to end across corporate, cloud, and data center environments, from detection and containment through eradication and post-incident review.

- Build the detection logic, response playbooks, and forensic tooling for an environment where the assets under threat are the most targeted model weights in technology.

- Run investigations across a threat surface measured in gigawatts, correlating signals from cloud, endpoint, network, and physical systems into a single picture of an attack.

- Stand up the incident response function from the ground up, defining severity models, on-call rotations, and the escalation path to leadership.

- Turn each incident into a permanent improvement by partnering with the security and IT teams to close the gaps your investigations surface.

### WHAT WE'RE LOOKING FOR

- The below is a starting point. We always make space for exceptional people, so if you don't fit this role exactly, tell us where you would https://jobs.ashbyhq.com/fluidstack/05c2e69c-42f9-4fcb-9cf0-a467aaf98f1c.

- You've personally led major security incidents from first alert to resolution, making containment calls under pressure with the business watching.

- You've built detection logic and response playbooks that caught real intrusions, not just theoretical ones.

- You've run digital forensics across cloud, endpoint, and network evidence and reconstructed what an attacker actually did.

- You've stood up or substantially rebuilt an incident response program rather than only operating inside someone else's.

- You've hunted for threats proactively and found activity that existing tooling missed.

- You write incident reports and postmortems clear enough that both engineers and executives act on them.

- Bonus: Experience defending high-value targets such as AI labs, financial infrastructure, or critical infrastructure against nation-state threat models. Cloud-native forensics (AWS, GCP). Detection engineering and SIEM or SOAR tooling. Malware analysis or reverse engineering.

We are committed to pay equity and transparency.

Fluidstack is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Fluidstack will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

You will receive a confirmation email once your application has successfully been accepted. If there is an error with your submission and you did not receive a confirmation email, please email careers@fluidstack.io with your resume/CV, the role you've applied for, and the date you submitted your application-- someone from our recruiting team will be in touch.

**Live in Fluidstack’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- WR [Security engineer, detection and response (UK)](https://gurify.com/job/security-engineer-detection-and-response-uk-at-writer-9cb21b626cf6) Writer · London, United Kingdom · 2 weeks ago
- TR [Senior Product Security Engineer](https://gurify.com/job/senior-product-security-engineer-at-trainline-40f1783e34dd) Trainline · London · 5 days ago
- RI [Application Security Engineer](https://gurify.com/job/application-security-engineer-at-rightmove-53294a38228f) Rightmove · London, United Kingdom · 5 days ago
- XA [Infrastructure Security Engineer](https://gurify.com/job/infrastructure-security-engineer-at-xai-5df6888fa213) Xai · Dublin, United Kingdom · last week
- BR [Lead Application Security Engineer](https://gurify.com/job/lead-application-security-engineer-at-brunswickgroup-5849dbce754f) Brunswickgroup · London, United Kingdom · 2 days ago
- OM [Platform Security Engineer](https://gurify.com/job/platform-security-engineer-at-omnea-79e993c63a72) Omnea · London · yesterday

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security Engineer, Incident Response","description":"\u003Ch3\u003EABOUT FLUIDSTACK\u003C/h3\u003E\u003Cp\u003EWe exist to make humanity more free. For most of human history, you farmed or you starved. Technology gave people more time for the things they wanted to do, instead of things they had to do. Powerful AI will be the biggest lever for human choice we\u0026#39;ve ever built - but only if models are aligned with what humanity actually wants. There are groups building AI who don\u0026#39;t share these goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands human freedom or shrinks it.\u003C/p\u003E\u003Cp\u003EWe\u0026#39;re singularly focused on delivering 10 to 100s of GWs of compute faster than anyone else, rethinking every layer of the stack. We acquire power, design and build data centers, and operate them - with teams spanning hardware and software. Speed and scale are our key differentiators. Come be a part of building civilization-scale infrastructure for AI.\u003C/p\u003E\u003Cp\u003EWe hire people who care deeply about this problem space. If that is you, please apply!\u003C/p\u003E\u003Ch3\u003EHOW WE OPERATE\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EBe a barrel. Full autonomy. Own things end to end, take on scope without being asked, no permission required to operate outside your core role.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EInsane urgency. We drive everything forward as fast as possible.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EReason from first principles. Challenge every assumption. Zero analogy thinking, no egos, the best idea wins.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELove of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild something that actually matters. If you\u0026#39;re going to spend your time, spend it on something that matters to the world.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ETHE SECURITY TEAM\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExamples of key problems the team is working on\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;re securing the frontier of AI. The model weights training on our infrastructure are the most valuable and most targeted artifacts in technology, and we\u0026#39;re standing up the compute to hold them faster than anyone ever has. A breach isn\u0026#39;t a leak, it\u0026#39;s the frontier walking out the door.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild the entire security program from scratch. Most leaders inherit someone else\u0026#39;s system and spend a career patching it. Here you own it end to end, bare metal to boardroom, as we scale across continents.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYour threat surface is measured in gigawatts. The customers running on our infrastructure are building the most consequential technology in human history, and being responsible for the physical and logical security of that work makes everything else feel small.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EROLE SCOPE\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ELead incident response end to end across corporate, cloud, and data center environments, from detection and containment through eradication and post-incident review.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild the detection logic, response playbooks, and forensic tooling for an environment where the assets under threat are the most targeted model weights in technology.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERun investigations across a threat surface measured in gigawatts, correlating signals from cloud, endpoint, network, and physical systems into a single picture of an attack.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStand up the incident response function from the ground up, defining severity models, on-call rotations, and the escalation path to leadership.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETurn each incident into a permanent improvement by partnering with the security and IT teams to close the gaps your investigations surface.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWHAT WE\u0026#39;RE LOOKING FOR\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EThe below is a starting point. We always make space for exceptional people, so if you don\u0026#39;t fit this role exactly, tell us where you would https://jobs.ashbyhq.com/fluidstack/05c2e69c-42f9-4fcb-9cf0-a467aaf98f1c.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;ve personally led major security incidents from first alert to resolution, making containment calls under pressure with the business watching.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;ve built detection logic and response playbooks that caught real intrusions, not just theoretical ones.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;ve run digital forensics across cloud, endpoint, and network evidence and reconstructed what an attacker actually did.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;ve stood up or substantially rebuilt an incident response program rather than only operating inside someone else\u0026#39;s.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;ve hunted for threats proactively and found activity that existing tooling missed.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou write incident reports and postmortems clear enough that both engineers and executives act on them.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBonus: Experience defending high-value targets such as AI labs, financial infrastructure, or critical infrastructure against nation-state threat models. Cloud-native forensics (AWS, GCP). Detection engineering and SIEM or SOAR tooling. Malware analysis or reverse engineering.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWe are committed to pay equity and transparency.\u003C/p\u003E\u003Cp\u003EFluidstack is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans\u2019 status, or any other characteristic protected by law. Fluidstack will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.\u003C/p\u003E\u003Cp\u003EYou will receive a confirmation email once your application has successfully been accepted. If there is an error with your submission and you did not receive a confirmation email, please email careers@fluidstack.io with your resume/CV, the role you\u0026#39;ve applied for, and the date you submitted your application--  someone from our recruiting team will be in touch.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-engineer-incident-response-at-fluidstack-acb1d52ca30b"},"url":"https://gurify.com/job/security-engineer-incident-response-at-fluidstack-acb1d52ca30b","datePosted":"2026-10-06","validThrough":"2026-11-21T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Fluidstack","sameAs":"https://jobs.ashbyhq.com/fluidstack"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Security Engineer, Incident Response","item":"https://gurify.com/job/security-engineer-incident-response-at-fluidstack-acb1d52ca30b"}]}
```
