Solace logo
SolacePosted 1 month ago

Sr. Security Engineer (Detection)

RemoteUnited States

Full TimeSenior LevelStartupHealthcare

Job Summary

Own the Datadog Cloud SIEM end-to-end by managing log pipelines, tuning detection rules across identity, cloud, endpoint, and SaaS sources, and systematically reducing alert noise to improve fidelity and time-to-triage. Serve as the primary responder for security incidents, triaging alerts, investigating threats mapped to MITRE ATT&CK, and executing containment while documenting post-incident reviews. Build automation for faster triage and response, contribute to cloud and infrastructure hardening on AWS and GCP, and ensure all logging and audit trails meet HIPAA requirements for ePHI systems. This hands-on, high-ownership role sits within a lean, HIPAA-regulated startup focused on patient advocacy technology.

Required Qualifications

  • 3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles
  • Real experience building and tuning detections in a SIEM
  • Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms
  • Hands-on incident response experience: you've triaged real alerts, worked real incidents, and written the post-mortems
  • Scripting ability (Python or similar) for automation, log analysis, and detection tooling
  • Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks
  • Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal
  • Applicants must be based in the United States

Desired Qualifications

  • Datadog Cloud SIEM strongly preferred
  • Deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther
  • Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST)
  • Detection-as-code workflows (Terraform, CI/CD for detections)
  • SOAR or workflow automation experience (Tines, Windmill, custom tooling)
  • Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective
  • Threat hunting experience or contributions to open-source detection content

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce