Partner 34, Lead Engineer, Incident Response
Founded in Silicon Valley in 2009 by Marc Andreessen and Ben Horowitz, Andreessen Horowitz (aka a16z) is a venture capital firm that backs bold entrepreneurs building the future through technology. We are stage agnostic . We invest in seed to venture to growth-stage technology companies, across AI , bio + healthcare , consumer , crypto , enterprise , fintech , games , and companies building toward American dynamism . a16z has $100B+ under management across multiple funds.
We’ve established a team that is defined by respect for the entrepreneur and the company-building process; we know what it’s like to be in the founder’s shoes. We’ve invested in companies like Anduril, Airbnb, Coinbase, Cursor, Databricks, Deel, Figma, GitHub, Roblox, SpaceX, and Stripe. Our team is at the forefront of new technology, helping founders and their companies impact and change the world.
The Role
We're hiring a Lead Engineer, Incident Response to lead and shape a16z's detection and response team. This is a hands-on role: you'll spend a significant portion of your time investigating incidents, writing and reviewing detections, building automation, and making the harder technical response decisions. You'll also manage and develop the engineers on the team.
You'll build and improve detection and response capabilities across the firm's cloud, SaaS, identity, and endpoint environments, shaping the roadmap, tooling, threat hunting, and response practices. You'll also develop capabilities to protect the firm against impersonation and fraud. You'll work closely with Security Engineering, IT, Legal, Compliance, and other cross-functional teams to put these capabilities into practice and turn lessons from incidents into better detections, tooling, and controls.
Venture capital firms face threats that extend beyond their infrastructure: capital call wire fraud, impersonation, and social engineering against employees and partners, alongside attacks by organized criminal and nation-state groups. Your work protects sensitive firm and limited partner (LP) information, financial transactions, and the relationships the firm depends on.
This role requires an in-office presence 2 days a week in our San Francisco, CA office.
To join our team, you should be excited to:
Set the detection and response roadmap, prioritizing the threats that matter most to the firm and measuring detection coverage, alert quality, and response effectiveness
Lead and develop engineers through coaching, feedback, performance management, and technical reviews, working alongside them on investigations and engineering projects
Develop the team's ability to respond from triage through containment, eradication, and recovery, including vendor incidents. Lead major incidents, coordinate a16z's technical response with system owners and affected providers, and escalate decisions requiring leadership or Legal approval
Maintain and test response playbooks and escalation criteria through cross-functional tabletop exercises and incident simulations
Design and improve SIEM architecture and security logging with Security Engineering and IT, expanding detection coverage across cloud, identity, and endpoint environments, including EDR. Write, review, test, and tune detections as code, using relevant MITRE ATT&CK techniques to assess coverage and working with system owners to close visibility gaps
Run hypothesis-driven threat hunts informed by threat intelligence and prior investigations, turning findings into new detections
Build and improve brand protection capabilities including monitoring, investigation, and takedowns of lookalike domains, fraudulent websites, and social media accounts
Build AI-assisted response automation. Evaluate accuracy and reliability before deployment and define where human judgment and approvals are required
Keep technical and non-technical stakeholders aligned during incidents, including IT, Legal, Compliance, Finance, and investing teams. Clearly communicate impact, uncertainty, response options, and next steps
Develop the team's postmortem practices, lead reviews of root causes and contributing factors, and drive corrective actions to completion with the teams responsible for remediation
Participate in the Security team's on-call rotation
Minimum Qualifications
9+ years of incident response or detection and response experience, or equivalent demonstrated impact, with depth in cloud incident response across AWS and GCP
Prior experience managing security engineers, including coaching and performance management, while remaining technically hands-on
A track record of building and leading detection and response programs, making architecture and prioritization decisions, and delivering measurable improvements
Experience leading high-stakes incidents across cloud, SaaS, identity, and endpoint environments, including forensic investigation, containment, recovery, and postmortems
Strong detection engineering skills, including SIEM query languages or rule formats such as KQL or Sigma, detection-as-code, testing, and tuning
Experience designing SIEM and security log pipelines and using cloud logs, endpoint detection and response (EDR), and security orchestration and automation (SOAR) tools in investigations and response. We value transferable capability over experience with a specific product
Experience running hypothesis-driven threat hunts and investigating sophisticated attacks, including identity compromise, social engineering, and data exfiltration
Strong Python skills and experience building and reviewing maintainable security automation
Working knowledge of AI and agent systems, including their limitations and security risks when used in triage and response workflows
Experience leading cross-functional security work and communicating incident impact, uncertainty, and technical trade-offs clearly to non-technical stakeholders and senior leaders
Sound judgment under pressure, balancing security risk and business impact and recognizing when to escalate
Low ego, high empathy, and a track record of effective collaboration across teams
GCIH or an equivalent incident response certification is a bonus but not required.
The anticipated salary range for this role is between $295,000 - $347,000, actual starting pay may vary based on a range of factors which can include experience, skills, and scope.
This role is eligible to participate in the a16z carry program and various discretionary bonus programs as well as benefit and perquisite plans including health, dental, vision, disability, life insurance, 401K plan, vacation, and sick leave. a16z culture
We do only first class business and only in a first class way
We take a long view of relationships, because we are in the relationship business
We believe in the future and bet the firm that way
We are all different, we recognize that, and we win
We celebrate the good times
We do it for the team
We play to win
At a16z we are always looking to hire the absolute best talent and recognize that diversity in our experiences and backgrounds is what makes us stronger. We hire candidates of any race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, Veteran status, and any other status. These differences are what enables us to work towards the future we envision for ourselves, our portfolio companies, and the World.
Our organization participates in E-Verify. Click here to learn about E-Verify.
Andreessen Horowitz hereby reserves the right to make use of any unsolicited resumes received from outside recruiting agencies and / or individual recruiters without being responsible for payment of any fees asserted from the use of unsolicited resumes.