Skip to main content
Solace Health

Sr. Security Engineer (Detection)

RemoteUnited States only
Published
Role
Unknown
Employment
Full-time
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Own our detection and alerting program end to end: build, tune, and maintain high-signal detection rules on our Datadog SIEM, kill alert noise, serve as primary responder for incidents, and grow security operations at a healthcare startup.

Core skills

Datadog Cloud SIEMDetection engineeringIncident response

Required skills

SplunkElasticChronicleSentinelPantherPythonCloudTrailGCP audit logsOktaGoogle WorkspaceAWSGCPJamfSnowflakeGitHubSlackTerraformCI/CD for detectionsTinesWindmillVanta

Optional skills

Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST)Detection-as-code workflows (Terraform, CI/CD for detections)SOAR or workflow automation experience (Tines, Windmill, custom tooling)Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspectiveThreat hunting experience or contributions to open-source detection content

What you'll do

  • Own our Datadog Cloud SIEM: log pipelines, parsing, enrichment, retention, and cost management
  • Build, tune, and maintain detection rules across our environment — identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (GitHub, Slack, and more)
  • Systematically reduce alert noise and drive alert quality metrics (fidelity, time-to-triage, false-positive rates)
  • Map detection coverage against real-world threats (MITRE ATT&CK) and close the highest-risk gaps first
  • Treat detections as code: version-controlled, tested, documented, and peer-reviewed
  • Ensure logging and audit trails meet HIPAA requirements for ePHI systems
  • Serve as a primary responder for security alerts and incidents: triage, investigate, contain, and document
  • Improve and extend our incident response playbooks, and run post-incident reviews that produce real fixes
  • Build automation to speed up triage and response (enrichment, auto-containment, workflow automation)
  • Participate in and help mature our on-call rotation as the team grows
  • Contribute to cloud and infrastructure security hardening across AWS and GCP
  • Support identity and access management improvements (Okta policies, access reviews, least privilege)
  • Pitch in on vendor security reviews, security questionnaires, and audit evidence gathering (HIPAA, SOC 2)
  • Help build a security-first culture through documentation, tooling, and partnership with engineering teams

What they require

  • 3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles
  • Real experience building and tuning detections in a SIEM — Datadog Cloud SIEM strongly preferred, but deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther translates well
  • Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms
  • Hands-on incident response experience: you've triaged real alerts, worked real incidents, and wrote the post-mortems
  • Scripting ability (Python or similar) for automation, log analysis, and detection tooling
  • Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks
  • Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal
  • Bias toward action — you'd rather ship a good detection today and iterate than design the perfect one for a month
  • High signal in communication: clear incident writeups, honest post-mortems, and the ability to explain risk to non-security audiences
  • Strong ownership mentality — you notice gaps and close them without being asked
  • Collaborative and low-ego that on a small team where everyone wears multiple hats
  • Care about doing security right in an environment where patient data is at stake

Solace is committed to transforming healthcare navigation for millions of Americans.

HealthcareStartup
Salary not disclosed