Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Solace

Senior Security Engineer, Detection

Solace

Sr. Security Engineer responsible for detection and alerting program at Solace.

Posted 7/24/2026full-timeRemote • 🇺🇸 United StatesSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in security operations, incident response, and detection engineering, with a strong focus on building and tuning detection rules in Datadog Cloud SIEM and ensuring compliance with HIPAA requirements. Proficient in automation and log analysis, with a solid understanding of common attack patterns and threat hunting.

Highest-signal resume keywords
Datadog Cloud SIEMIncident ResponseDetection EngineeringScripting (Python)HIPAA Compliance

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Detection Rule TuningLog AnalysisAutomationThreat HuntingIncident TriageCloud Security (AWS, GCP)Data ParsingAlert Quality MetricsDetection-as-Code WorkflowsSecurity Auditing
Soft Skills
Problem SolvingCollaborationAdaptabilityCommunicationAttention to Detail
Tools & Technologies
OktaJamfSnowflakeGitHubCloudTrailGCP Audit LogsSOAR ToolsTerraformCI/CDTines
Industry Keywords
Security OperationsIncident ResponseRegulated EnvironmentsHIPAASOC 2MITRE ATT&CKCloud MisconfigurationsPhishingCredential CompromiseSupply Chain Risks

Tech Stack

Tools & technologies
AWSCloudGoogle Cloud PlatformJamfPythonSplunkTerraform

About the role

Key responsibilities & impact
  • Own our Datadog Cloud SIEM: log pipelines, parsing, enrichment, retention, and cost management
  • Build, tune, and maintain detection rules across our environment — identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (GitHub, Slack, and more)
  • Systematically reduce alert noise and drive alert quality metrics (fidelity, time-to-triage, false-positive rates)
  • Map detection coverage against real-world threats (MITRE ATT&CK) and close the highest-risk gaps first
  • Treat detections as code: version-controlled, tested, documented, and peer-reviewed
  • Ensure logging and audit trails meet HIPAA requirements for ePHI systems
  • Serve as a primary responder for security alerts and incidents: triage, investigate, contain, and document
  • Improve and extend our incident response playbooks, and run post-incident reviews that produce real fixes
  • Build automation to speed up triage and response (enrichment, auto-containment, workflow automation)
  • Participate in and help mature our on-call rotation as the team grows
  • Contribute to cloud and infrastructure security hardening across AWS and GCP
  • Support identity and access management improvements (Okta policies, access reviews, least privilege)
  • Pitch in on vendor security reviews, security questionnaires, and audit evidence gathering (HIPAA, SOC 2)
  • Help build a security-first culture through documentation, tooling, and partnership with engineering teams

Requirements

What you’ll need
  • 3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles
  • Real experience building and tuning detections in a SIEM — Datadog Cloud SIEM strongly preferred, but deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther translates well
  • Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms
  • Hands-on incident response experience: you've triaged real alerts, worked real incidents, and written the post-mortems
  • Scripting ability (Python or similar) for automation, log analysis, and detection tooling
  • Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks
  • Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal
  • Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST) (Nice to Have)
  • Detection-as-code workflows (Terraform, CI/CD for detections) (Nice to Have)
  • SOAR or workflow automation experience (Tines, Windmill, custom tooling) (Nice to Have)
  • Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective (Nice to Have)
  • Threat hunting experience or contributions to open-source detection content (Nice to Have)

Benefits

Comp & perks
  • Applicants must be based in the United States.