At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. This is not a back-office compliance role and it is not a generic sales-engineering role. You will operate as a named member of deal teams under our pod model: paired with Strategic and Enterprise Account Executives, embedded in their weekly cadences, engaged from first discovery through POC, onsite, close, and expansion. You will be the practitioner in the room that a buyer's CISO or GRC lead trusts — and the internal expert our AEs, SEs, and marketing team build around. What you’ll do as a Subject Matter Expert, GTM at Vanta: Serve as the dedicated GRC SME for a book of Strategic/Enterprise Account Executives: join discovery and qualification calls at the earliest deal stages, scope compliance programs against Vanta's platform, and support demos, POCs, workshops, and customer onsites across Compliance, Third-Party Risk Management, Risk Management, and Trust/Questionnaire Automation. Advise prospects on program architecture: multi-framework strategy, shared controls, business-unit and workspace scoping, custom frameworks, and audit sequencing. Answer field questions through our SME channels at customer-forwardable quality — including reviewing and validating AI-agent-generated answers before they reach customers. Our team runs AI-first: you'll use agents daily, act as the quality gate on their output, and (ideally) build tooling of your own. Design and deliver enablement: live sessions for GTM teams, bootcamp scenarios and mock-customer roleplay, async curriculum modules, and review of GRC marketing and SEO content. Own monthly alignment cadences with sales front-line managers; feed structured product feedback to our Product a
Jobs in United States
Security Incident Response Engineer in United States
1,214 active opportunities · Updated October 2026
Showing
15 jobs
Explore current security incident response engineer jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.
About the Team Security is foundational to OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security organization protects OpenAI’s technology, people, and products by building and operating deeply technical systems that must work reliably at massive scale. Our work underpins OpenAI’s commitments around safety, privacy, and security across research, products, and emerging platforms. The Host Assurance team exists to make bare metal and VMs dependable & scalable foundations for OpenAI: secure by default, verifiable in practice, and resilient across providers and operating models. We operate at the trust boundary between hardware and cloud-scale orchestration, ensuring that hosts are eligible to safely run workloads with predictable security properties and auditability. About the Role OpenAI is seeking a Software Engineer, Host Assurance to build and operate the services, APIs, and host software that establish and maintain trust in our compute infrastructure. You will own production software from design and implementation through testing, rollout, observability, and operation. Your work will support capabilities such as machine identity, certificate issuance and enrollment, secure bootstrap, and host attestation across bare-metal and VM environments. Success in this role requires strong technical judgment, the ability to reason across software and host-system boundaries and learn unfamiliar parts of the stack, and a practical mindset for building systems that are secure, reliable, and usable in fast-moving production environments. The systems you build will sit on the critical path of OpenAI’s frontier infrastructure investments and will directly shape how large amounts of compute are brought online - securely, responsibly, and at global scale - underpinning long-lived commitments around privacy, security, and reliability. You will partner closely with infrastructure, research, and confidential computing initiatives—inc
From $210K/yr
Drata is building the trust layer between great companies - automating compliance, managing risk, and helping organizations prove trust continuously as they scale. We're Dratanauts: a global crew of 600+ professionals united by a culture that rewards integrity, ownership, and raising the bar, no matter where in the world we're working from. Why Join the Drata Team? At Drata, you're not maintaining legacy compliance software - you're building the agentic AI platform defining what trust looks like for the next generation of companies. Here's what makes the work itself worth showing up for: Problems without a playbook: You'll work at the edge of AI and security, building agentic governance, continuous compliance, and real-time trust verification to solve problems that don't have an established answer yet. You're writing it as you go. Real ownership, not just process: Our values center on owning outcomes and raising the bar, not checking boxes. You're expected to have opinions and back them. A seat at the table: Your perspective is unique and valued. Open debate and diverse viewpoints are built into how decisions actually get made here, at every level. Growth at rocketship speed: Drata is scaling fast, which means scope grows fast too. High performers get more ownership, visibility, and experience. A crew, not just coworkers: Dratanauts consistently describe a "come as you are" culture with sharp, curious people—the kind of team that makes hard problems genuinely fun to solve. See what they say here and follow us on LinkedIn for company news, employee stories, and career updates. Job Summary: As Drata scales, we want our security and GRC leadership to be able to meet our customers’ needs in more places at once—in strategic customer conversations, on stage at industry events, and in the broader conversations happening across our security and GRC communities. We’re looking for a Field Chief Information Security Officer to join Drata’s Security & GRC organization, repo
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta's Corporate Engineering team is the infrastructure layer that keeps 1,500+ people connected, secure, and moving fast. AI is now central to how that happens, and this role leads the team that owns the backbone underneath it. Corporate Engineering owns the shared AI platform for Vanta's internal systems: identity and access for AI tools, cost visibility and controls, sanctioned tooling and guardrails, and the enablement that helps people use those tools well. We do not own product AI, which stays with Engineering, and we do not replace the AI work happening inside individual departments. We build the engineering layer that makes all of it safer, cheaper, and better supported. The company has moved fast. AI assistant use is widespread across every function, MCP infrastructure is live and self-serve company-wide, internal apps ship on a hosted platform, and AI spend has grown to the point where attribution and guardrails genuinely matter. What does not exist yet is a single owner for that platform layer. That is this role. As Sr. Manager, AI Engineering, you will lead a small, senior team, write the charter for what Corporate Engineering owns versus enables, and build the platform that lets the rest of Vanta adopt AI quickly without accumulating cost, risk, or duplication. What you’ll do as a Senior Manager, AI Corporate Engineering at Vanta: Lead, coach, and grow a senior team spanning platform engineering and technical program management. Set clear direction, hold a high bar, and give the team explicit permission to push back with data. Own the AI access layer end to end: identity and authentication for AI tools, connector
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta's Corporate Engineering team is the infrastructure layer that keeps 1,500+ people connected, secure, and moving fast. This role leads the shift from a reactive support function to a platform function the whole company relies on. Corporate Engineering owns the systems, tooling, and access infrastructure Vanta runs on. From identity and device management to AI tooling infrastructure and ITSM, CE makes sure Vanta's people have the right access, the right tools, and the right guardrails on day one and every day after. CE is at an inflection point. The company has scaled quickly, AI tooling is live company-wide, and the team is ready for a leader who sets technical direction, establishes clear ownership, and builds the leadership layer beneath them. As Sr. Manager, Systems Engineering, you will lead a team of experienced engineers, own several of the company's highest-priority platform initiatives, and make CE a function the rest of Vanta builds on rather than routes around. What you’ll do as a Senior Manager, Systems Engineering at Vanta: Lead, coach, and grow a team of systems engineers and a tech lead. Set clear expectations, hold a high bar, and develop the people who build Vanta's most critical internal systems. Own joiner, mover, and leaver automation end to end in Okta Workflows, so access is correct on day one, follows people through role changes, and closes completely on departure, including API keys and service credentials. Build and own device assurance across macOS and Windows, defining OS, browser, and device-state policy ahead of enforcement rather than in response to it. Rationalize the ITSM estate so self-servi
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Vanta for Government (V4G) is how we bring that mission to the public sector. As federal compliance undergoes its biggest shift in a decade — FedRAMP 20x, machine-readable authorization, OSCAL — we're building the platform that turns federal frameworks into automated, continuously monitored product experiences. The GRC Subject Matter Experts on this team are the people who make that possible. As Vanta's GRC Subject Matter Expert for V4G , you'll own federal compliance content used by every customer pursuing or maintaining federal authorization on our platform. This is an interpretation-and-authoring role, not a compliance program administration role: your job is to interpret underlying control requirements, identify where FedRAMP modifies or constrains the NIST framework, and translate those interpretations into precise, technically testable guidance that engineering can build and customers can act on. The content you write ships as product — a five-person startup and a Fortune 100 CSP both receive it — so calibrating depth, precision, and universality is the core craft. You'll join Vanta's Security organization, which directly influences product development, facilitates the creation of automated GRC solutions for customers, and provides expert advisory services across the company. What you’ll do as a V4G GRC SME at Vanta: Build and own federal compliance frameworks — Lead the creation, enhancement, and lifecycle management of controls, evidence requirements, and implementation guidance for FedRAMP (Low/Moderate/High), NIST SP 800-53, NIST SP 800-171, CMMC, DFARS, and StateRAMP. Author clear control rationales, acceptance crite
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Senior Product Manager , you will own GitLab's Secret Detection offering and the Vulnerability Research function that produces the detection content across security products. Secret Detection is one of the highest-signal, highest-volume security capabilities on the platform. Leaked credentials are the most common initial access vector in real breaches, and as AI agents write, commit, and configure more of the software, the surface area for exposed secrets grows faster than the number of humans watching it. You will own the full loop: detect a secret with high precision, tell the customer whether it i
From $140K/yr
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. Overview of the role We're looking for a seasoned Threat Intelligence Engineer to join us as a dedicated Senior Security Engineer, TI. You'll be joining a program established a couple of years ago, with a solid foundation already in place: reporting templates, tooling, feeds, and industry connections built out by the Security Operations team over that time. Your mission will be to provide actionable intelligence that empowers GitLab to make informed, proactive decisions about security. We want to get in front of threats before they materialize - using intelligence to see around corners and anticipate the next attack. We'll
From $192K/yr
As the Engineering Manager for Commercial Audit, you will lead a high-performing team responsible for scaling Datadog’s security and compliance posture through automation, tooling, and engineering excellence. Our GRC (Governance, Risk, and Compliance) function is a critical partner to the broader Security and Engineering organizations, ensuring that Datadog not only meets rigorous global regulatory standards but does so in a way that is efficient, scalable, and integrated into our cloud-native infrastructure. You will manage a team of engineers and analysts who are transitioning to a GRC engineering direction to treat compliance as a software problem, leveraging AI, custom tooling, CI/CD pipelines, and cloud-native services to turn complex regulatory requirements into actionable, automated controls. You will lead the strategy, roadmap, and execution of Datadog’s Commercial Audit initiatives. This is a high-impact leadership role where you will grow a team of engineers and analysts responsible for directly maintaining our compliance programs and related audits (e.g., SOC2, PCI, HIPAA, ISO) while looking to improve efficiency and effectiveness through platforms and tooling. You will act as a bridge between technical engineering, legal, and compliance, enabling the organization to move fast while maintaining a secure and compliant environment. You will champion a culture of "compliance-as-code," identifying opportunities to automate evidence collection, streamline control testing, and reduce manual toil for both your team and our partner engineering teams. At Datadog, we place value in our office culture - the relationships and collaboration it builds, and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Lead the strategy, roadmap, and execution of Datadog’s commercial security compliance efforts, shifting from manual audit processes to automated, scalable
About the Team The SaaS and Software Governance team sits within Corporate IT and helps OpenAI scale from startup-speed tooling to mature enterprise architecture. The team owns practical governance for software, SaaS, integrations, APIs, identity, data access, and agent-enabled workflows, with a mandate to improve security, reduce software sprawl, and help business teams move faster through better foundations. About the Team OpenAI is scaling from an emerging, high-velocity startup into a mature enterprise operating model. The IT Software Architect will help shape the software, SaaS, Data integration, and agent-enabled architecture that lets the company move quickly while improving security, compliance, data quality, and customer, partner, and employee experience. This role is not a traditional ivory-tower architecture function. It is a hands-on governance and enablement role that partners with business teams, IT operations, Security, Procurement, Business Platforms, Applied teams and Data Engineering to guide software decisions, reduce unmanaged sprawl, and build reusable enterprise foundations. Why This Role Matters OpenAI’s software footprint is expanding rapidly across SaaS, internally built tools, agents, integrations, APIs, third-party platforms, and application systems that OpenAI. The company needs a stronger tools architecture layer that can help teams make good decisions early, avoid duplicate tools, govern sensitive data and identities, and identify where OpenAI should build instead of buy. The person in this role will help turn software governance from an approval checkpoint into an enterprise capability: a system that improves speed, reliability, security, and business outcomes. What You'll Do Own the target architecture for enterprise software, SaaS, integrations, APIs, and agent-enabled business systems across Corporate IT. Drive deprecation and consolidate targets for enterprise software. Build lightweight governance patterns that guide teams before
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Secure Manufacturing & Stealth (SMS) team protects OpenAI’s most sensitive product, manufacturing, launch, and partnership work from theft, leakage, espionage, and unauthorized disclosure. We operate across physical, digital, human, and third-party domains, building practical protections that allow teams to move quickly while preserving strict need-to-know controls. About the Role We are seeking a senior Secure Manufacturing & Stealth Partner to serve as the dedicated SMS owner for Marketing. This person will build trusted relationships across Marketing, understand launches and sensitive information flows, identify secrecy risks early, and embed practical controls into planning, creative production, events, agencies, vendors, media, and executive communications. The role owns the Marketing relationship while coordinating shared SMS capabilities when investigative, prototype-handling, regional, or other specialist support is needed. In this role you will: Serve as the primary SMS Partner and trusted adviser to Marketing, building a deep understanding of its priorities, planning cycles, launches, events, external partners, and sensitive information flows. Identify secrecy and information-exposure risks early, then translate SMS requirements into practical controls that protect sensitive work without unnecessarily slowing execution. Build, document, and socialize durable operating mechanisms for compartmentalization, need-to-know access, agencies and vendors, sensitive creative production, events, demonstrations, launch preparation, codenames, watermarking, and password controls. Assess and approve Marketing systems and information workflows, identify gaps or duplication, establish secure handling requirements, and advise AI-native Marketing initiatives on permissions, data governance, and operational tracking. Coordinate
About the Team OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems. About the Role We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements. We are looking for someone who questions inherited assumptions, solves novel problems creatively, works closely with engineers, and makes the next audit easier by improving the underlying system. You’ll be responsible for: Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout. Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks. Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate. Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting. Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness. Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity. Reduce repeated requests and operational burden for control owners through measurable workflow improvements. Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations. We’re looking for someone with: Direct ownership
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role OpenAI is seeking to build an investigative capability for Secure Manufacturing & Stealth programs. The risk surface for unreleased products, prototypes, confidential hardware, infrastructure, supply chain, manufacturing, and launch-readiness efforts spans employees, vendors, suppliers, logistics partners, physical movement of assets, procurement records, manufacturing workflows, access systems, device telemetry, and adversarial collection. This role is intended to build and run investigations across that specialized environment. In this role, you will: Lead complex SMS investigations to proactively identify and mitigate risks to unreleased products, prototypes, confidential hardware, secure manufacturing programs, and launch-readiness efforts. Investigate unauthorized disclosure, suspected leaks, insider risk, supplier compromise, vendor misconduct, theft, diversion, tampering, counterfeiting, surveillance, adversarial collection, and suspicious activity involving sensitive programs. Connect digital evidence, physical access activity, supply chain records, manufacturing data, vendor behavior, employee activity, collaboration metadata, procurement records, shipping data, and OSINT into clear findings and risk-reduction actions. Conduct proactive threat hunting to surface early indicators of compromise, collection, leakage, or insider activity affecting sensitive programs. Develop investigative playbooks, evidence-handling standards,
About the Team The Privacy Engineering team builds secure, reliable systems that help OpenAI meet its legal obligations while protecting user data. We partner closely with Legal and Engineering teams across OpenAI to support lawful data access requests and other critical legal workflows. Our work turns complex, high-stakes processes into auditable and dependable technical systems with clear human oversight and strong privacy and security controls. About the Role We’re looking for a full-stack Software Engineer to build the internal tools and data pipelines that power lawful data access request workflows and Legal Operations. You will work across product and data systems to make authorized retrieval and case handling accurate, efficient, and auditable. This role is well suited to someone who enjoys translating ambiguous operational requirements into durable systems, cares deeply about sensitive-data handling, and wants to improve both technical reliability and the day-to-day experience of the people operating these workflows. This role is based in San Francisco, CA, with two additional locations under consideration: London, UK, and Dublin, Ireland. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Design, build, and operate backend systems and workflow tooling for the full lifecycle of lawful data access requests, from intake and scoping through authorized retrieval, review, preparation, and audit. Build reliable data pipelines and interfaces across products and data stores so authorized teams can locate and handle the right records accurately and reproducibly. Implement least-privilege access, approval gates, provenance, audit trails, data minimization, and safe failure modes for sensitive workflows. Partner with Legal and Legal Operations to translate legal and operational requirements into clear technical designs and intuitive operator experiences. Identify responsible automation o
About the Team Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Identity Infrastructure Engineering team sits at the core of this effort, designing and building the identity and access management solutions that protect model weights, customer data, and critical systems across multiple cloud environments. The team partners across OpenAI, including Applied Engineering, Research, IT, Security, Infrastructure, and Engineering, to provide secure and scalable platforms for identity, access management, permissioning, orchestration, and safe AI research. About the Role We’re looking for an engineering leader to lead Identity Infrastructure Engineering, the team building the systems that govern and scale access across OpenAI’s research, engineering, and internal platforms. This role sits at the center of cloud infrastructure, identity, software engineering, and security-critical operations. You’ll lead engineers building control planes, policy systems, workload and agent authorization patterns, infrastructure-as-code, and operational foundations that help OpenAI move quickly while keeping access reliable, auditable, least-privileged, and safe under failure. The ideal candidate has led teams responsible for large-scale, mission-critical infrastructure. They can go deep into code and architecture when needed, while giving engineers and technical leads the clarity and ownership to do their best work. They set technical direction, grow strong teams, make durable architecture decisions, and turn ambiguous 0-to-1 problems into platforms OpenAI can trust and build on for years. In this role, you will: Build and lead a high-performing Identity Infrastructure team, going deep enough technically to set direction while empowering the team to own delivery. Define the strategy for identity platform as the policy plane for access across people, agents, workloads, services, clouds, and internal systems. Scale Acc
Other cities to consider
More places hiring for this role
Get new security incident response engineer jobs in United States by email
Daily job updates · Unsubscribe anytime