Staff Detection Security Operations Engineer
Arkenstone Defense · Menlo Park, CA · Yesterday
Information TechnologyFull-time
About UsAt Arkenstone Defense, we empower defense tech startups with the tools, infrastructure, and compliance solutions they need to become successful prime contractors. Our mission is to remove barriers and help innovators grow - from day one to becoming a trusted prime for the U.S. Government.We're early, we're lean, and we're building something that actually matters. The people who do well here aren't waiting to be told what to do; they see a gap and fill it.OverviewWe are seeking a Staff Detection Security Operations Engineer (Remote, US) to focus on leading the design and implementation of operational excellence across our multi-cloud environments for threat monitoring, detection, and security data analytics supporting our federal and commercial customer base. You will identify complex security and technical compliance issues, recognize patterns and root causes, and help design innovative solutions that improve our threat monitoring and detection services. You will bring your experience with security systems and incident response — both on-premises and in cloud environments — to a team growing around supporting FedRAMP-authorized Cloud Service Providers.This role operates on the frontline of the Mission Assurance Center (MAC), working to triage alerts, investigate threats, and protect internal and customer-facing environments. It is ideal for a motivated analyst who wants to grow quickly in a compliance-heavy, mission-critical environment where your work directly supports the security of cleared workforces. You will execute defi ned tasks under direct supervision, follow established playbooks, and build the foundational skills that drive career progression within the MAC.This role is central to ensuring the scalability, reliability, and performance of our products running in AWS, Azure, and GCP infrastructure. As the Staff Detection Security Operations Engineer, you will own the uptime, observability, and system resilience for our critical services. This includes driving architecture decisions, automation practices, and incident response strategies—working closely with the product owner(s), developer teams, and security operations teams.What You’ll DoEngineeringDesign and review security architectures, reference implementations, and control patterns for FedRAMP/CMMC-aligned environments.Lead complex security assessments and technical deep-dives; identify root causes and drive sustainable remediation across the customer portfolio.Guide the confi guration and evolution of core security tooling — including SIEM, EDR, vulnerability management, logging pipelines, and data ingestion architectures.Develop advanced automation, reusable modules, and infrastructure-as-code patterns that engineering teams adopt across programs.Lead cross-functional technical initiatives spanning security, IT, compliance, and product engineering teams.Drive observability improvements across the security stack — metrics, alerting, and dashboards for operational health.Evaluate emerging technologies and tooling; make build-vs-buy recommendations to MAC leadership.Provide technical mentorship and code/design review for engineers; infl uence standards, runbooks, and best practices across the team.Design, implement, and own the infrastructure reliability strategy across AWS, Azure, and GCPChampion observability by developing and maintaining effective logging, monitoring, and alerting systemsLead efforts in performance tuning, system hardening, capacity planning, and disaster recoveryAutomate deployment, scaling, and recovery workfl ows to reduce manual toilAct as a mentor and technical leader to junior engineers and cross-functional partnersPerform any other related duties as required or assignedThreat Monitoring & DetectionOwn the incident management lifecycle: from detection to postmortem and root cause analysisMonitor SIEM and security tools for alerts; perform initial triage and escalate per documented playbooks; tune and create detection SIEM alertsCollect and correlate security data from multiple sources to distinguish true positives from noiseMonitor and analyze threat intelligence sources to detect potential security threats and vulnerabilities; implement continuous monitoring systems to ensure real-time awareness of security eventsParticipate in on-call rotation for after-hours security monitoring and incident response.Process & Knowledge DevelopmentMaintain and improve runbooks, knowledge base articles, and repetitive task automationsWork closely with internal engineering, development, and compliance teams to implement security measures and address compliance requirementsStay current on industry trends, emerging threats, and changes in compliance standards to ensure ongoing effectiveness.Requirements5-8 years of experience in Security Engineering and/or Detection engineering rolesHands-on exposure to AWS AthenaProfi ciency in detection engineering: alert creation and tuning - writing SQL, KQL, Sigma, or YARA rules for threat detectionProven track record of operating large-scale systems in multi-cloud environmentsStrong knowledge of cloud-native architecture, container orchestration (e.g., Kubernetes), and CI/CD pipelinesProfi cient in scripting (Python, Bash, etc.) and infrastructure automation toolsExperience with monitoring/observability platforms (e.g., Prometheus, Grafana, Datadog, etc.)Excellent problem-solving skills and a bias toward ownership and actionFamiliarity with SIEM platformsWorking knowledge of incident response processes, procedures, and documentation standardsComfortable making decisions under pressure and leading through incidentsWorking knowledge of FedRAMP or NIST 800-53 controls preferredComfortable participating in customer discussionsClear communicator who can translate technical concepts to mixed audiencesWho You AreDrive a culture of accountability, ownership, and continuous improvementYou thrive on building meaningful relationships and helping others succeedYou understand the unique challenges that defense tech startups face, and can speak their languageMission AlignmentWe are a Defense-focused company supporting sensitive and cleared workforces. The Staff Detection Security Operations Engineer will embrace our commitment to operational excellence, compliance rigor, and a world-class employee experience.Physical RequirementsProlonged periods of sitting at a desk and working on a computerMust be able to lift up to 15 pounds at timesMay require occasional travel to office locations or client sitesAbility to communicate effectively in written and verbal formBenefits for working with us!We are committed to supporting our employees both professionally and personally. Our robust benefits package is designed to promote your well-being, growth, and work-life balanceCompetitive Salary: Recognizing your hard work with attractive compensation and rewarding excellence.Health and Wellness Programs: Including medical, dental, & vision insurance options, along with mental health support & wellness initiatives.Retirement Planning: Secure your future with our flexible 401(k) plan and matching company contributions.Paid Time Off & Holidays: Generous PTO, sick leave, and holiday pay to help you recharge and enjoy life outside of work.Employee Assistance Program: Confidential resources for personal and professional support.Professional Development: Access to training, certifications, and continuing education to foster your career growth. We are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, disability, genetic information, veteran status, or any other characteristic protected under applicable law.