Partner 34, Lead Engineer, Incident Response
What security roles in crypto pay
84 salaries · our own dataThis role pays $295k-$347k, above the $200k median for security roles in crypto on this board.
As a Lead Engineer, Incident Response at a16z crypto, you lead and shape the firm's detection and response team. This is a hands-on role where you spend significant time investigating incidents, writing and reviewing detections, building automation, and making critical technical response decisions while managing and developing the engineers on your team. You build and improve detection and response capabilities across the firm's cloud, SaaS, identity, and endpoint environments, and develop capabilities to protect against impersonation and fraud. Your work protects sensitive firm and limited partner information, financial transactions, and the relationships a venture capital firm depends on.
What you'll do
- Set the detection and response roadmap, prioritizing threats and measuring detection coverage, alert quality, and response effectiveness
- Lead and develop engineers through coaching, feedback, performance management, and technical reviews, working alongside them on investigations and engineering projects
- Develop the team's ability to respond from triage through containment, eradication, and recovery, including vendor incidents. Lead major incidents, coordinate a16z's technical response with system owners and affected providers, and escalate decisions requiring leadership or Legal approval
- Maintain and test response playbooks and escalation criteria through cross-functional tabletop exercises and incident simulations
- Design and improve SIEM architecture and security logging with Security Engineering and IT, expanding detection coverage across cloud, identity, and endpoint environments including EDR. Write, review, test, and tune detections as code using relevant MITRE ATT&CK techniques to assess coverage and close visibility gaps
- Run hypothesis-driven threat hunts informed by threat intelligence and prior investigations, turning findings into new detections
- Build and improve brand protection capabilities including monitoring, investigation, and takedowns of lookalike domains, fraudulent websites, and social media accounts
- Build AI-assisted response automation. Evaluate accuracy and reliability before deployment and define where human judgment and approvals are required
- Keep technical and non-technical stakeholders aligned during incidents, including IT, Legal, Compliance, Finance, and investing teams. Clearly communicate impact, uncertainty, response options, and next steps
- Develop the team's postmortem practices, lead reviews of root causes and contributing factors, and drive corrective actions to completion
- Participate in the Security team's on-call rotation
What you bring
- 9+ years of incident response or detection and response experience with depth in cloud incident response across AWS and GCP
- Prior experience managing security engineers, including coaching and performance management, while remaining technically hands-on
- A track record of building and leading detection and response programs, making architecture and prioritization decisions, and delivering measurable improvements
- Experience leading high-stakes incidents across cloud, SaaS, identity, and endpoint environments, including forensic investigation, containment, recovery, and postmortems
- Strong detection engineering skills, including SIEM query languages or rule formats such as KQL or Sigma, detection-as-code, testing, and tuning
- Experience designing SIEM and security log pipelines and using cloud logs, endpoint detection and response (EDR), and security orchestration and automation (SOAR) tools in investigations and response
- Experience running hypothesis-driven threat hunts and investigating sophisticated attacks, including identity compromise, social engineering, and data exfiltration
- Strong Python skills and experience building and reviewing maintainable security automation
- Working knowledge of AI and agent systems, including their limitations and security risks when used in triage and response workflows
- Experience leading cross-functional security work and communicating incident impact, uncertainty, and technical trade-offs clearly to non-technical stakeholders and senior leaders
- Sound judgment under pressure, balancing security risk and business impact and recognizing when to escalate
- Low ego, high empathy, and a track record of effective collaboration across teams
Nice to have
- GCIH or an equivalent incident response certification
What we offer
- Anticipated salary range of $295,000-$347,000, with actual starting pay based on experience, skills, and scope
- Participation in the a16z carry program and discretionary bonus programs
- Health, dental, vision, disability, and life insurance
- 401K plan, vacation, and sick leave
- In-office presence 2 days per week in San Francisco, CA
About a16z crypto
Andreessen Horowitz, founded in 2009, is a venture capital firm with $100B+ under management investing across AI, bio and healthcare, consumer, crypto, enterprise, fintech, games, and American dynamism. a16z backs bold entrepreneurs building the future and has invested in companies including Anduril, Airbnb, Coinbase, Databricks, Figma, GitHub, Roblox, SpaceX, and Stripe.
Context for this role
From the live jobs we track on CryptoJobsHQ, updated daily.
a16z crypto has 17 open roles on CryptoJobsHQ: 5 in Security, 4 in Engineering and 3 in Marketing. 12% are fully remote, most of the rest in the US. 3 were posted in the last 7 days. The median advertised base salary is $264k, from 17 listings that publish pay.
All 17 a16z crypto roles →956 Security roles are open across crypto right now.
Browse Security Jobs →- Security Engineer - AppSec at Rain · Remote
- Data Protection Officer at Bitvavo · On-site
- Office Assistant at Gemini · On-site
- [Security] Senior Application Security Engineer at Bybit · On-site
