Remote job
Sr. Security Engineer (Detection)
Job details
About this role
Role overview Senior Security Engineer leading the detection and alerting program at a U.S.-based healthcare technology startup. The role sits on a small security team in a HIPAA-regulated environment and combines detection engineering, incident response, and generalist security work. The engineer will shape foundational security operations, turning existing log telemetry into a high-signal detection program that supports fast, accurate response.
Responsibilities - Own the Datadog Cloud SIEM end-to-end, including log pipelines, parsing, enrichment, retention, and cost management. - Build, tune, and maintain detection rules across identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (GitHub, Slack, and more). - Reduce alert noise and track alert quality metrics such as fidelity, time-to-triage, and false-positive rates, mapping coverage against MITRE ATT&CK. - Treat detections as code, with version control, testing, documentation, and peer review. - Serve as a primary responder for security alerts and incidents, and extend incident response playbooks and post-incident review practices. - Contribute to cloud and infrastructure hardening, IAM improvements, vendor reviews, and HIPAA and SOC 2 audit evidence gathering.
Requirements - 3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles. - Real experience building and tuning detections in a SIEM (Datadog Cloud SIEM preferred; Splunk, Elastic, Chronicle, Sentinel, or Panther also relevant). - Fluency reading and correlating logs from cloud providers, identity providers, and SaaS platforms. - Hands-on incident response experience, including triaged alerts, worked incidents, and written post-mortems. - Scripting ability in Python or similar for automation, log analysis, and detection tooling. - Strong understanding of common attack patterns such as phishing, credential compromise, SSO abuse, cloud misconfigurations, and supply chain risks. - Comfortable working with ambiguity and building from scratch; startup or small-team experience is a strong signal.
Nice to have - Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST). - Detection-as-code workflows using Terraform or CI/CD pipelines. - SOAR or workflow automation experience with tools like Tines or Windmill. - Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective. - Threat hunting experience or contributions to open-source detection content.
Benefits and work setup - Applicants must be based in the United States.