Tech Lead, Detection & Response
On-siteLos Angeles, California, United States
Job Summary
Own detection and response end to end across corporate, cloud, and factory environments, designing an AI-native stack with detection-as-code, LLM-assisted triage, and agentic automation. Lead incident response from triage through containment and remediation, including high-severity scenarios, while setting technical direction for a small team and mentoring engineers. Partner with IT, infrastructure, and compliance to meet ITAR and CMMC requirements for monitoring and response. This hands-on senior IC role builds the next-generation detection stack at Hadrian, an autonomous factory manufacturer scaling its Factory-as-a-Service platform for aerospace and defense.
Required Qualifications
- 8+ years of security engineering experience with deep, hands-on detection & response expertise (SIEM, EDR, cloud and identity telemetry, SOAR)
- Strong software engineering skills with detection-as-code and infrastructure-as-code fluency
- A track record of setting technical direction as a tech lead, team lead, or anchor senior IC
- Demonstrated application of AI/LLM tooling to security workflows — and sound judgment about its limits
- Experience leading incident response end to end in production environments
- U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State
Desired Qualifications
- Red team, penetration testing, or adversary emulation experience at any point in your career
- Experience in ITAR, CMMC, or other regulated defense or government environments
- Exposure to OT/ICS or manufacturing environment security
- Production experience building agentic or LLM-based security automation
- 0→1 experience building a security capability at a fast-scaling startup
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.