FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security operations, incident response, and detection engineering, with a strong focus on building and tuning detection rules in Datadog Cloud SIEM and ensuring compliance with HIPAA requirements. Proficient in automation and log analysis, with a solid understanding of common attack patterns and threat hunting.
Highest-signal resume keywords
Datadog Cloud SIEMIncident ResponseDetection EngineeringScripting (Python)HIPAA Compliance
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Detection Rule TuningLog AnalysisAutomationThreat HuntingIncident TriageCloud Security (AWS, GCP)Data ParsingAlert Quality MetricsDetection-as-Code WorkflowsSecurity Auditing
Soft Skills
Problem SolvingCollaborationAdaptabilityCommunicationAttention to Detail
Tools & Technologies
OktaJamfSnowflakeGitHubCloudTrailGCP Audit LogsSOAR ToolsTerraformCI/CDTines
Industry Keywords
Security OperationsIncident ResponseRegulated EnvironmentsHIPAASOC 2MITRE ATT&CKCloud MisconfigurationsPhishingCredential CompromiseSupply Chain Risks
Tech Stack
Tools & technologiesAWSCloudGoogle Cloud PlatformJamfPythonSplunkTerraform
About the role
Key responsibilities & impact- Own our Datadog Cloud SIEM: log pipelines, parsing, enrichment, retention, and cost management
- Build, tune, and maintain detection rules across our environment — identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (GitHub, Slack, and more)
- Systematically reduce alert noise and drive alert quality metrics (fidelity, time-to-triage, false-positive rates)
- Map detection coverage against real-world threats (MITRE ATT&CK) and close the highest-risk gaps first
- Treat detections as code: version-controlled, tested, documented, and peer-reviewed
- Ensure logging and audit trails meet HIPAA requirements for ePHI systems
- Serve as a primary responder for security alerts and incidents: triage, investigate, contain, and document
- Improve and extend our incident response playbooks, and run post-incident reviews that produce real fixes
- Build automation to speed up triage and response (enrichment, auto-containment, workflow automation)
- Participate in and help mature our on-call rotation as the team grows
- Contribute to cloud and infrastructure security hardening across AWS and GCP
- Support identity and access management improvements (Okta policies, access reviews, least privilege)
- Pitch in on vendor security reviews, security questionnaires, and audit evidence gathering (HIPAA, SOC 2)
- Help build a security-first culture through documentation, tooling, and partnership with engineering teams
Requirements
What you’ll need- 3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles
- Real experience building and tuning detections in a SIEM — Datadog Cloud SIEM strongly preferred, but deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther translates well
- Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms
- Hands-on incident response experience: you've triaged real alerts, worked real incidents, and written the post-mortems
- Scripting ability (Python or similar) for automation, log analysis, and detection tooling
- Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks
- Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal
- Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST) (Nice to Have)
- Detection-as-code workflows (Terraform, CI/CD for detections) (Nice to Have)
- SOAR or workflow automation experience (Tines, Windmill, custom tooling) (Nice to Have)
- Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective (Nice to Have)
- Threat hunting experience or contributions to open-source detection content (Nice to Have)
Benefits
Comp & perks- Applicants must be based in the United States.
