Jobs · Information Technology

Sr. Security Engineer (Detection)

Solace · United States · 1 mo ago
RemoteRemoteInformation TechnologyFull-time

About the role

We're looking for a Sr. Security Engineer to join our growing security team at Solace. You'll be a generalist at heart, but your first and most important mission is clear: own our detection and alerting program end to end.

Responsibilities

  • Detection Engineering & SIEM Ownership (Primary Focus)
  • Own our Datadog Cloud SIEM: log pipelines, parsing, enrichment, retention, and cost management
  • Build, tune, and maintain detection rules across our environment — identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (GitHub, Slack, and more)
  • Systematically reduce alert noise and drive alert quality metrics (fidelity, time-to-triage, false-positive rates)
  • Map detection coverage against real-world threats (MITRE ATT&CK) and close the highest-risk gaps first
  • Treat detections as code: version-controlled, tested, documented, and peer-reviewed
  • Ensure logging and audit trails meet HIPAA requirements for ePHI systems
  • Incident Response
  • Serve as a primary responder for security alerts and incidents: triage, investigate, contain, and document
  • Improve and extend our incident response playbooks, and run post-incident reviews that produce real fixes
  • Build automation to speed up triage and response (enrichment, auto-containment, workflow automation)
  • Participate in and help mature our on-call rotation as the team grows
  • Generalist Security Engineering
  • Contribute to cloud and infrastructure security hardening across AWS and GCP
  • Support identity and access management improvements (Okta policies, access reviews, least privilege)
  • Pitch in on vendor security reviews, security questionnaires, and audit evidence gathering (HIPAA, SOC 2)
  • Help build a security-first culture through documentation, tooling, and partnership with engineering teams

Qualifications

  • Required: 3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles
  • Real experience building and tuning detections in a SIEM — Datadog Cloud SIEM strongly preferred, but deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther translates well
  • Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms
  • Hands-on incident response experience: you've triaged real alerts, worked real incidents, and written the post-mortems
  • Scripting ability (Python or similar) for automation, log analysis, and detection tooling
  • Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks
  • Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal

Nice to have

  • Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST)
  • Detection-as-code workflows (Terraform, CI/CD for detections)
  • SOAR or workflow automation experience (Tines, Windmill, custom tooling)
  • Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective
  • Threat hunting experience or contributions to open-source detection content

Similar jobs

Sr. Security Engineer

Early WarningScottsdale, AZ· 1 mo ago
Information Technology$132k–$165k/yrapply on earlywarning.wd5.myworkdayjobs.com

Sr. Security Engineer

OpenSpaceSan Francisco, CA· 3 days ago
RemoteInformation Technology$180k–$230k/yrapply on grnh.se