Sr. Security Engineer (Detection)
RemoteUnited States
Job Summary
Own the Datadog Cloud SIEM end-to-end by managing log pipelines, tuning detection rules across identity, cloud, endpoint, and SaaS sources, and systematically reducing alert noise to improve fidelity and time-to-triage. Serve as the primary responder for security incidents, triaging alerts, investigating threats mapped to MITRE ATT&CK, and executing containment while documenting post-incident reviews. Build automation for faster triage and response, contribute to cloud and infrastructure hardening on AWS and GCP, and ensure all logging and audit trails meet HIPAA requirements for ePHI systems. This hands-on, high-ownership role sits within a lean, HIPAA-regulated startup focused on patient advocacy technology.
Required Qualifications
- 3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles
- Real experience building and tuning detections in a SIEM
- Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms
- Hands-on incident response experience: you've triaged real alerts, worked real incidents, and written the post-mortems
- Scripting ability (Python or similar) for automation, log analysis, and detection tooling
- Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks
- Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal
- Applicants must be based in the United States
Desired Qualifications
- Datadog Cloud SIEM strongly preferred
- Deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther
- Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST)
- Detection-as-code workflows (Terraform, CI/CD for detections)
- SOAR or workflow automation experience (Tines, Windmill, custom tooling)
- Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective
- Threat hunting experience or contributions to open-source detection content
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.