Enter a job title or keyword

Partner 20, Staff Engineer, Incident Response

A16z


Job Location:

San Francisco, CA - USA

Monthly Salary: $ 243000 - 284000
Posted: 3 June 2026 (30+ days ago)
Application Deadline: 1 September 2026
Vacancies: 1 Vacancy
The job posting is outdated and position may be filled

Job Summary

Founded in Silicon Valley in 2009 by Marc Andreessen and Ben Horowitz Andreessen Horowitz (aka a16z) is a venture capital firm that backs bold entrepreneurs building the future through technology. We are stage agnostic. We invest in seed to venture to growth-stage technology companies across AI bio healthcare consumer crypto enterprise fintech games and companies building toward American dynamism. a16z has $100B under management across multiple funds.

Weve established a team that is defined by respect for the entrepreneur and the company-building process; we know what its like to be in the founders shoes. Weve invested in companies like Anduril Airbnb Coinbase Cursor Databricks Deel Figma GitHub Roblox SpaceX and Stripe. Our team is at the forefront of new technology helping founders and their companies impact and change the world.

The Role

Were hiring a Staff Incident Response Engineer to anchor a16zs detection and response work. Youll own incident triage and response across AWS and GCP write the detections that catch real threats in our SIEM and run point when something serious happens.

The threats here are not theoretical. We see capital call wire fraud attempts vishing campaigns social engineering against IT and partners and occasionally more sophisticated actors (nation-state groups organized criminal operations) who specifically target venture capital firms. Your work protects the firm our LPs and our portfolio companies. Youll work day to day with the Head of Cybersecurity Security Engineering IT and Legal.

This role requires an in-office presence 2 days a week in our San Francisco CA office.

To join our team you should be excited to:
  • Run incidents end to end from first alert to post-mortem across cloud and SaaS environments
  • Write the detections that catch real threats with a strong bias toward signal over noise and broad MITRE ATT&CK coverage
  • Help shape the next generation of our SOC including AI agent integration into triage and response workflows
  • Partner across the firm during incidents: investing teams Legal Compliance Finance IT and firm leadership all get pulled in and this role keeps every audience aligned under pressure
  • Drive post-mortems that lead to operational change not process for its own sake
  • Work against real adversaries including nation-state groups organized criminal operations and threat actors who specifically target venture capital firms
Minimum Qualifications
  • 5 years of incident response experience or equivalent demonstrated impact with cloud IR depth across both AWS and GCP
  • Experience leading live incidents end to end triage containment eradication forensic investigation and post-mortem across cloud SaaS identity and endpoint surfaces
  • Experience running proactive hypothesis-driven threat hunts using current TTPs and intel
  • Hands-on detection authoring in modern SIEM platforms (Sigma KQL or equivalent) and experience working with detection-as-code
  • Experience building detection frameworks and contributing to SIEM architecture decisions
  • Strong Python scripting. This is a role where you build automation not one where you only operate someone elses
  • Demonstrated capability across modern security tooling categories (cloud telemetry EDR SOAR SIEM). We weight transferable capability over experience with any specific product
  • GCIH or equivalent IR certification preferred
  • Comfortable in a fast-moving environment where security is expected to enable the business
  • Experience defending against nation-state threat actors or organized criminal groups
  • Working knowledge of AI/agent systems and their security implications particularly in SOC workflows
  • Experience translating the technical reality of an incident (blast radius containment status disclosure decisions) into language non-technical stakeholders can act on.
  • Low ego high empathy and the capacity to collaborate effectively with diverse teams

The anticipated salary range for this role is between $243000 - $284000 actual starting pay may vary based on a range of factors which can include experience skills and scope.

This role is eligible to participate in the a16z carry program and various discretionary bonus programs as well as benefit and perquisite plans including health dental vision disability life insurance 401K plan vacation and sick leave.

a16z culture
  • We do only first class business and only in a first class way
  • We take a long view of relationships because we are in the relationship business
  • We believe in the future and bet the firm that way
  • We are all different we recognize that and we win
  • We celebrate the good times
  • We do it for the team
  • We play to win

At a16z we are always looking to hire the absolute best talent and recognize that diversity in our experiences and backgrounds is what makes us stronger. We hire candidates of any race color ancestry religion sex national origin sexual orientation gender identity age marital or family status disability Veteran status and any other status. These differences are what enables us to work towards the future we envision for ourselves our portfolio companies and the World.

Our organization participates in E-Verify. Click here to learn about E-Verify.

Andreessen Horowitz hereby reserves the right to make use of any unsolicited resumes received from outside recruiting agencies and / or individual recruiters without being responsible for payment of any fees asserted from the use of unsolicited resumes.


Required Experience:

Staff IC


About Company

Company Logo

Andreessen Horowitz (a16z) is a venture capital firm in Silicon Valley, California, investing in bold founders, innovators, and entrepreneurs building the future through technology.

View Profile View Profile