Fluidstack
AI
PrincipalIncidentResponder
Neural analysis suggests this role is
optimal for Lead candidates.
“Principal Incident Responder at Fluidstack. Skills: incident command, incident response program building, cross-functional coordination, risk analysis, process improvement. Run material incidents as incident commander, coordinating across detection, response, physical security, data center operations, legal, communications, and customers.. Build the IR program: runbook standards, severity definitions, materiality methodology, evidence contracts, and post-incident review cadence.”
What You'll Achieve.
Define what material-incident response looks like at Fluidstack; set the runbook standard the rest of the IR function operates inside; lead the room when those systems come under attack; Define and track the IR program’s KPIs and report on them to security and engineering leadership; Set the tabletop and exercise cadence for IR readiness, executive crisis-comms, and audit-readiness drills
Industry & Context.
Analyze incident trends and patterns to surface systemic risks and recurring root causes; turn the learnings into runbook, detection, or program improvements
on-call rotation
What They're Looking For.
Must Have
run material incidents at companies with sophisticated threat models, as the most senior commander on the call, made disclosure-grade calls under regulatory and customer reporting clocks, written runbooks that other engineers followed under pressure, and rewritten them after they did not work, built operational processes from the ground up in environments where structure did not previously exist, read the agent-first thesis as one of the most interesting design choices in incident response today, well-founded opinions on what makes a runbook actually used or an incident response process actually effective, move fluently between technical containment and executive, legal, or customer-facing conversations during a declared incident, see what is needed, scope it yourself, and run with it
Nice to Have
Experience running incidents that bridge cyber, physical, and OT or ICS surfaces, Experience at critical-infrastructure operators, data centers, or industrial environments, Experience designing or operating agent-augmented incident response, including triage, investigation, or response automation, Experience tuning LLM-based IR systems against measured precision and recall
What You'll Do.
Run material incidents as incident commander
coordinating across detection
data center operations
Build the IR program: runbook standards
materiality methodology
and post-incident review cadence.
Define the agent-human contract for response: escalation criteria
evidence packages required from agents
and human verdict feedback into agent quality.
Design and operate the senior-IR on-call rotation (ack SLAs
fan-out logic) and remain an active senior IC inside it.
Analyze incident trends and patterns to surface systemic risks and recurring root causes
and turn the learnings into runbook
or program improvements.
Drive cross-functional follow-through after every significant incident
tracking remediation and systemic fixes to completion across detection
Define and track the IR program’s KPIs and report on them to security and engineering leadership.
Set the tabletop and exercise cadence for IR readiness
executive crisis-comms
and audit-readiness drills.
Carry the external face of IR for regulatory and customer disclosure obligations
How You'll Work.
Team & Collaboration
coordinating across detection, response, physical security, data center operations, legal, communications, and customers; Drive cross-functional follow-through after every significant incident, tracking remediation and systemic fixes to completion across detection, response, infrastructure, and other teams; report on them to security and engineering leadership
Communication Scope
executive, legal, or customer-facing conversations
Process & Methodology
tracking remediation and systemic fixes to completion
Full Job Description
ABOUT FLUIDSTACK At Fluidstack, we build the compute, data centers, and power that will fuel artificial superintelligence. We supply GWs of compute capabilities to the world’s biggest AI Labs at industry-defining speeds. Our team is small, fast, and obsessed with quality. We own outcomes end-to-end, challenge assumptions, and treat our customers' problems as our own. No task is beneath anyone here. There are a few thousand people who will shape the trajectory of superintelligence. Come and be one of them. ABOUT THE ROLE Fluidstack operates the compute infrastructure powering frontier AI. The work running on it is among the most consequential being done today, and the adversaries interested in it are among the most sophisticated, persistent, and well-resourced anywhere. We are building Detection & Response Engineering from the ground up: engineering-led, agent-first, and built to scale across IT, OT, and physical surfaces. As the Principal Incident Responder, you are the most senior incident commander in the program. You define what material-incident response looks like at Fluidstack, set the runbook standard the rest of the IR function operates inside, and lead the room when those systems come under attack. WHAT YOU’LL DO - Run material incidents as incident commander, coordinating across detection, response, physical security, data center operations, legal, communications, and customers. - Build the IR program: runbook standards, severity definitions, materiality methodology, evidence contracts, and post-incident review cadence. - Define the agent-human contract for response: escalation criteria, evidence packages required from agents, and human verdict feedback into agent quality. - Design and operate the senior-IR on-call rotation (ack SLAs, escalation chain, fan-out logic) and remain an active senior IC inside it. - Analyze incident trends and patterns to surface systemic risks and recurring root causes, and turn the learnings into runbook, detection, or program
Applying for this Principal Incident Responder role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about Fluidstack?
Real rants from real employees. Read before you apply.