Senior Security Engineer, Detection

Job not on LinkedIn

🔥 2 hours ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Solace

Solace

1 - 10 employees

⚕️ Healthcare Insurance

🧘 Wellness

🌍 Social Impact

Healthcare Insurance • Wellness • Social Impact

Solace is a healthcare advocacy company that connects patients and their families with skilled advocates, such as doctors, nurses, and other healthcare experts. Their mission is to empower patients and improve healthcare outcomes by assisting with the navigation of the complex healthcare system. Solace provides support in areas like scheduling, communicating with medical teams, and insurance dealings, and advocates are covered by Medicare and Medicare Advantage plans. The platform ensures patients receive personalized support through phone or video consultations, assisting with everything from chronic illness management to healthcare paperwork.

📋 Description

• Own our Datadog Cloud SIEM: log pipelines, parsing, enrichment, retention, and cost management • Build, tune, and maintain detection rules across our environment — identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (GitHub, Slack, and more) • Systematically reduce alert noise and drive alert quality metrics (fidelity, time-to-triage, false-positive rates) • Map detection coverage against real-world threats (MITRE ATT&CK) and close the highest-risk gaps first • Treat detections as code: version-controlled, tested, documented, and peer-reviewed • Ensure logging and audit trails meet HIPAA requirements for ePHI systems • Serve as a primary responder for security alerts and incidents: triage, investigate, contain, and document • Improve and extend our incident response playbooks, and run post-incident reviews that produce real fixes • Build automation to speed up triage and response (enrichment, auto-containment, workflow automation) • Participate in and help mature our on-call rotation as the team grows • Contribute to cloud and infrastructure security hardening across AWS and GCP • Support identity and access management improvements (Okta policies, access reviews, least privilege) • Pitch in on vendor security reviews, security questionnaires, and audit evidence gathering (HIPAA, SOC 2) • Help build a security-first culture through documentation, tooling, and partnership with engineering teams

🎯 Requirements

• 3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles • Real experience building and tuning detections in a SIEM — Datadog Cloud SIEM strongly preferred, but deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther translates well • Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms • Hands-on incident response experience: you've triaged real alerts, worked real incidents, and written the post-mortems • Scripting ability (Python or similar) for automation, log analysis, and detection tooling • Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks • Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal • Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST) (Nice to Have) • Detection-as-code workflows (Terraform, CI/CD for detections) (Nice to Have) • SOAR or workflow automation experience (Tines, Windmill, custom tooling) (Nice to Have) • Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective (Nice to Have) • Threat hunting experience or contributions to open-source detection content (Nice to Have)

🏖️ Benefits

• Applicants must be based in the United States.

Apply Now

Similar Jobs

🔥 3 hours ago

Highmark Health

10,000+ employees

⚕️ Healthcare Insurance

🤝 Non-profit

🌍 Social Impact

Manager Information Security & Risk Management at Highmark Health ensuring alignment with security needs and managing personnel activities. Overseeing technology products and contributing to strategic planning efforts.

Cyber Security

🔥 4 hours ago

Abbott

10,000+ employees

⚕️ Healthcare Insurance

🧬 Biotechnology

💊 Pharmaceuticals

Senior Cybersecurity Specialist ensuring compliance with cybersecurity standards and internal audits at Abbott. Collaborates with cross-functional teams, leveraging strong analytical skills in a remote capacity.

Cyber Security

🔥 4 hours ago

Hewlett Packard Enterprise

10,000+ employees

🏢 Enterprise

🔧 Hardware

☁️ SaaS

North America Cybersecurity Sales Leader for HPE developing SSE Security solutions and leading sales strategy across North America.

🔥 5 hours ago

Galaxy

201 - 500

₿ Crypto

💸 Finance

Security Engineer managing SOC operations for Galaxy, a leader in digital assets and data centers. Overseeing security alerts, incidents, and developing automation scripts to enhance operations.

AWS

Azure

Cloud

Cyber Security

Firewalls

Linux

Python

Splunk

VMware

🔥 5 hours ago

Marigold

1001 - 5000

🤝 B2B

☁️ SaaS

Security Engineering Manager at Marigold leading security initiatives for enhancing cybersecurity measures. Responsible for managing a team and developing strategies for safeguarding enterprise environments.

AWS

Cloud

Cyber Security

Firewalls

Google Cloud Platform