We are building AI to simulate the world through merging art and science.We believe that world models are at the frontier of progress in artificial intelligence. Language models alone won't solve the world's hardest problems – robotics, disease, scientific discovery. Real progress requires models that experience the world and learn from their mistakes, the same way that humans do. And this kind of trial and error can be massively accelerated when done in simulation, rather than in the real world.World models offer the most clear path to general-purpose simulation, changing how stories are told, how scientific progress is made and how the next frontiers of humanity are reached.Our team consists of creative, open minded, caring and ambitious people who are determined to change the world. We aspire to continuously build impossible things and our ability to do so relies on building an incredible team. If you are driven to do the same, we'd love to hear from you.About the roleOpen to hiring remote — we also have offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv.Runway is hiring a Detection & Response Engineer to own how we find and stop attacks against our infrastructure, our research environment and our products.Securing a company that trains and serves frontier video models is a different problem from securing a typical SaaS product. The environment includes research compute, large training datasets, a fast-moving build pipeline and engineers who work inside AI-assisted tooling every day. Each of those changes what an attack looks like and what you need to see to catch it.You'll join the Security team and build our detection and response program the way an engineer would: detections as code, response as automation, evidence as something you can query. This is a role with real ownership: you'll own the detection program end to end, from what we log to how quickly we close an incident. You'll report to the head of security, partner with engineers across platform and research, and shape how this function grows from here.What you'll doOwn detection and response end to end: what we log, what we alert on, how we triage and how we recoverWrite and tune detections as code across multiple cloud environments, Kubernetes, identity systems, endpoints and SaaS, and measure them on coverage and precision rather than alert volumeLead incident response from the first alert through containment and forensics, then write the post-incident review people actually readBuild automation that takes toil out of triage, including enrichment, correlation, containment actions and evidence collection, and use LLM-based tooling where it holds up under auditMonitor AI agents and developer tooling operating inside our environment, and turn that into concrete telemetry and controlsPartner with platform and research engineers so new systems ship with logging and response playbooks in place on day oneRun threat hunts and tabletop exercises against the parts of the environment that worry you most, and fix what you findTurn incident and detection metrics into evidence for SOC 2, ISO 27001 and enterprise customer security reviews, working with our GRC teamParticipate in an on-call rotation for security incidentsWhat you'll needHands-on incident response experience: you've triaged live alerts, led investigations and written up what happened afterwardExperience building and tuning detections in a modern SIEM, ideally managed as codeWorking knowledge of how attackers move through cloud and Kubernetes environments (IAM abuse, container escape, credential theft, supply chain compromise) and what that leaves behind in logsComfort writing Python, Typescript, Rust or another language to automate response work and connect security toolsFamiliarity with at least one major cloud platform and with Kubernetes at the level of audit logs, RBAC and workload identityClear writing. Incident timelines, detection documentation and updates to leadership are all part of the jobJudgment about what to alert on, what to automate and when to wake someone upEven better if you haveExperience monitoring GPU or HPC-style infrastructure, or research environments with large datasetsExperience building detections or guardrails for AI agents, LLM tooling or MCP serversCloud forensics experience: disk and memory acquisition, cloud audit trail reconstruction, chain of custodyPublished open source detection contentWorking at RunwayGreat things come from great teams. We'd love to hear from you.We're committed to creating a space where our employees can bring their full selves to work and have equal opportunity to succeed. So regardless of race, gender identity or expression, sexual orientation, religion, origin, ability, age, veteran status, if joining this mission speaks to you, we encourage you to apply.