Sr. Security Engineer (Detection)
Solace · United States · 1 mo ago
RemoteRemoteInformation TechnologyFull-time
About the role
We're looking for a Sr. Security Engineer to join our growing security team at Solace. You'll be a generalist at heart, but your first and most important mission is clear: own our detection and alerting program end to end.
Responsibilities
- Detection Engineering & SIEM Ownership (Primary Focus)
- Own our Datadog Cloud SIEM: log pipelines, parsing, enrichment, retention, and cost management
- Build, tune, and maintain detection rules across our environment — identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (GitHub, Slack, and more)
- Systematically reduce alert noise and drive alert quality metrics (fidelity, time-to-triage, false-positive rates)
- Map detection coverage against real-world threats (MITRE ATT&CK) and close the highest-risk gaps first
- Treat detections as code: version-controlled, tested, documented, and peer-reviewed
- Ensure logging and audit trails meet HIPAA requirements for ePHI systems
- Incident Response
- Serve as a primary responder for security alerts and incidents: triage, investigate, contain, and document
- Improve and extend our incident response playbooks, and run post-incident reviews that produce real fixes
- Build automation to speed up triage and response (enrichment, auto-containment, workflow automation)
- Participate in and help mature our on-call rotation as the team grows
- Generalist Security Engineering
- Contribute to cloud and infrastructure security hardening across AWS and GCP
- Support identity and access management improvements (Okta policies, access reviews, least privilege)
- Pitch in on vendor security reviews, security questionnaires, and audit evidence gathering (HIPAA, SOC 2)
- Help build a security-first culture through documentation, tooling, and partnership with engineering teams
Qualifications
- Required: 3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles
- Real experience building and tuning detections in a SIEM — Datadog Cloud SIEM strongly preferred, but deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther translates well
- Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms
- Hands-on incident response experience: you've triaged real alerts, worked real incidents, and written the post-mortems
- Scripting ability (Python or similar) for automation, log analysis, and detection tooling
- Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks
- Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal
Nice to have
- Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST)
- Detection-as-code workflows (Terraform, CI/CD for detections)
- SOAR or workflow automation experience (Tines, Windmill, custom tooling)
- Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective
- Threat hunting experience or contributions to open-source detection content