[All remote jobs](https://jobicy.com/jobs.md)[![Solace logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/4e37a66b-221.png)](https://jobicy.com/company/solace.md)[Solace](https://jobicy.com/company/solace.md)

# Sr. Security Engineer (Detection)

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/solace.md)ShareRemote from[USA](https://jobicy.com/job-region/usa.md)SalaryUndisclosedDepartment[Cybersecurity](https://jobicy.com/categories/cybersecurity.md)EmploymentFull TimeExperienceSeniorPublished28 Sep 2026Apply before28 Oct 2026Listing views56Application actions1Application toolkit

## Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

## The role, at a glance.

Solace is hiring a Senior Security Engineer to own and mature its detection and alerting program in a HIPAA-regulated healthcare startup. The role centers on Datadog Cloud SIEM administration, detection engineering, log pipeline quality, MITRE ATT&CK coverage, and reducing false positives across identity, cloud, endpoint, and SaaS systems. The engineer will also act as an incident responder, improve response playbooks, automate triage and containment, and contribute to cloud and identity hardening. This is a high-ownership role on a small U.S.-based team supporting sensitive patient-data systems.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

4/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

4/5IndependentCollaborative

AI insightThe role requires hands-on ownership of a detection program from the ground up, including SIEM tuning, incident response, automation, and compliance-aware logging. Success depends on sound threat-detection judgment, fast prioritization, and the ability to operate effectively with startup ambiguity and on-call responsibilities.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$165,000US market range$140k–$195k0$215k

AI insightNo actual salary range is disclosed in the posting. This is an estimated U.S. annual base-salary market range for a senior detection/security engineer with 3–6 years of security operations, SIEM engineering, incident-response, cloud-security, and healthcare-compliance responsibilities; actual compensation may vary by location, equity, and benefits.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Detection engineering](https://jobicy.com/jobs?search_keywords=Detection%20engineering.md)[Datadog Cloud SIEM](https://jobicy.com/jobs?search_keywords=Datadog%20Cloud%20SIEM.md)[Incident response](https://jobicy.com/jobs?search_keywords=Incident%20response.md)[Threat hunting](https://jobicy.com/jobs?search_keywords=Threat%20hunting.md)[MITRE ATT&CK](https://jobicy.com/jobs?search_keywords=MITRE%20ATTCK.md)[AWS security](https://jobicy.com/jobs?search_keywords=AWS%20security.md)[GCP security](https://jobicy.com/jobs?search_keywords=GCP%20security.md)[Python automation](https://jobicy.com/jobs?search_keywords=Python%20automation.md)[Okta](https://jobicy.com/jobs?search_keywords=Okta.md)[HIPAA compliance](https://jobicy.com/jobs?search_keywords=HIPAA%20compliance.md)

Sample interview questionsHow would you prioritize detections to build first in a new SIEM environment?I would begin by inventorying high-value assets, identity systems, data stores, and existing telemetry, then map the highest-impact attack paths to MITRE ATT&CK. I would prioritize detections for credential compromise, privileged access changes, suspicious cloud activity, data exfiltration, and logging tampering, while validating that each rule has actionable response steps.

Describe your approach to reducing SIEM alert fatigue without creating coverage gaps.

I measure alert quality through true-positive rate, false-positive rate, time to triage, and analyst feedback. I tune rules using contextual enrichment, thresholds, allowlists with expiry and ownership, entity baselines, and correlation across data sources; I also document rationale and periodically retest suppressed scenarios.

How would you investigate a suspected compromised Okta account?

I would review Okta authentication, MFA, session, factor-reset, application-assignment, and administrative events, then correlate them with Google Workspace, endpoint, VPN, and cloud activity. I would contain the account by revoking sessions and tokens, resetting credentials or factors as appropriate, assessing affected resources, preserving evidence, and documenting root cause and follow-up controls.

What does treating detections as code mean in practice?

It means storing rule definitions, parsers, tests, documentation, and deployment configuration in version control. Changes should be peer-reviewed, tested against representative logs and known attack cases, deployed through controlled CI/CD workflows, and accompanied by rollback plans and rule-performance monitoring.

How would you ensure security logging supports HIPAA obligations?

I would identify systems that create, access, or transmit ePHI and define required audit events, retention, access controls, and integrity protections for their logs. I would validate ingestion coverage regularly, limit access to sensitive log data, document control evidence, and work with compliance stakeholders to ensure the logging program supports audit and incident-investigation needs.

Opportunity details

## About this role.

### About Solace

Healthcare in the U.S. is fundamentally broken. The system is so complex that 88% of U.S. adults do not have the health literacy necessary to navigate it without help. Solace cuts through the red tape of healthcare by pairing patients with expert advocates and giving them the tools to make better decisions—and get better outcomes.

We’re a Series C startup, founded in 2022 and backed by Inspired Capital, Craft Ventures, Torch Capital, Menlo Ventures, Signalfire, and IVP. Our U.S. based team is lean, mission-driven, and growing quickly.

Solace isn’t a place to coast. We’re here to redefine healthcare—and that demands urgency, precision, and heart. If you’re looking to stretch yourself, sharpen your edge, and do the best work of your life alongside a team that cares deeply, you’re in the right place. We’re intense, and we like it that way.

Read more in our Bloomberg funding announcement [here](https://www.bloomberg.com/news/articles/2026-02-10/vcs-give-solace-health-1-billion-valuation-for-patient-advocacy-tech?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc3MDczMDg4MywiZXhwIjoxNzcxMzM1NjgzLCJhcnRpY2xlSWQiOiJUQThVUzhLR0NURzEwMCIsImJjb25uZWN0SWQiOiJBRDYxODI0MTc0ODM0MTk0QTRENUZFNzkwMzNGMDJGNSJ9.TE2pFUAOQAPMUXFlzoQ7zeJvctq7cSibbZqtIwhW-2U&leadSource=uverify+wall).

### About the Role

We’re looking for a Sr. Security Engineer to join our growing security team at Solace. You’ll be a generalist at heart, but your first and most important mission is clear: own our detection and alerting program end to end.

We have the raw materials in place — a Datadog SIEM with logs flowing in from across our identity, cloud, endpoint, and SaaS stack — but we need someone who can turn that telemetry into a high-signal detection program. You’ll decide what we detect, write and tune the rules, kill the noise, and make sure that when something real happens, we know fast and respond well.

This is a hands-on, high-ownership role on a small team in a HIPAA-regulated environment. You’ll report to our Staff Security Engineer and work alongside engineers focused on application and infrastructure security. What you build here will be the foundation of security operations at Solace for years.

### What You’ll Do

Detection Engineering & SIEM Ownership (Primary Focus)

*

Own our Datadog Cloud SIEM: log pipelines, parsing, enrichment, retention, and cost management

*

Build, tune, and maintain detection rules across our environment — identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (GitHub, Slack, and more)

*

Systematically reduce alert noise and drive alert quality metrics (fidelity, time-to-triage, false-positive rates)

*

Map detection coverage against real-world threats (MITRE ATT&CK) and close the highest-risk gaps first

*

Treat detections as code: version-controlled, tested, documented, and peer-reviewed

*

Ensure logging and audit trails meet HIPAA requirements for ePHI systems

Incident Response

*

Serve as a primary responder for security alerts and incidents: triage, investigate, contain, and document

*

Improve and extend our incident response playbooks, and run post-incident reviews that produce real fixes

*

Build automation to speed up triage and response (enrichment, auto-containment, workflow automation)

*

Participate in and help mature our on-call rotation as the team grows

Generalist Security Engineering

*

Contribute to cloud and infrastructure security hardening across AWS and GCP

*

Support identity and access management improvements (Okta policies, access reviews, least privilege)

*

Pitch in on vendor security reviews, security questionnaires, and audit evidence gathering (HIPAA, SOC 2)

*

Help build a security-first culture through documentation, tooling, and partnership with engineering teams

### What We’re Looking For

Required:

*

3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles

*

Real experience building and tuning detections in a SIEM — Datadog Cloud SIEM strongly preferred, but deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther translates well

*

Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms

*

Hands-on incident response experience: you’ve triaged real alerts, worked real incidents, and written the post-mortems

*

Scripting ability (Python or similar) for automation, log analysis, and detection tooling

*

Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks

*

Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal

Nice to Have:

*

Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST)

*

Detection-as-code workflows (Terraform, CI/CD for detections)

*

SOAR or workflow automation experience (Tines, Windmill, custom tooling)

*

Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective

*

Threat hunting experience or contributions to open-source detection content

Working Style:

*

Bias toward action — you’d rather ship a good detection today and iterate than design the perfect one for a month

*

High signal in communication: clear incident writeups, honest post-mortems, and the ability to explain risk to non-security audiences

*

Strong ownership mentality — you notice gaps and close them without being asked

*

Collaborative and low-ego on a small team where everyone wears multiple hats

*

Care about doing security right in an environment where patient data is at stake

Applicants must be based in the United States.

Up for the Challenge?

We look forward to meeting you.

Fraudulent Recruitment Advisory: Solace Health will NEVER request bank details or offer employment without an interview. All legitimate communications come from official solace.health emails only or [ashbyhq.com](http://ashbyhq.com). Report suspicious activity to recruiting@solace.health or advocate@solace.health.

Show more

[Apply now >](https://jobicy.com/jobs/154125-sr-security-engineer-detection.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

*
![GitLab logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/12/WRILS-201207055737-109952.jpg)
GitLab Sep 28  New

### [Senior Security Engineer, Security Incident Response Team (SIRT) – EMEA](https://jobicy.com/jobs/149309-senior-security-engineer-security-incident-response-team-sirt-emea.md)

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50…

*
![Vercel logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/a6aded72-221.png)
Vercel Sep 28  New

### [Security Software Engineer, IAM](https://jobicy.com/jobs/147750-security-software-engineer-iam.md)

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built….

*
![LastPass logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13842160-221.png)
LastPass Sep 27  New

### [Principal Cloud Security Engineer](https://jobicy.com/jobs/151831-principal-cloud-security-engineer.md)

About LastPassLastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and…

*
![Ada logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/666ef11e-221.png)
Ada Sep 27  New

### [Compliance and Security Lead](https://jobicy.com/jobs/151791-compliance-and-security-lead.md)

About Us Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service…

*
![Bloomreach logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/60790cd5-221.png)
Bloomreach Sep 26

### [Director, AI Enablement & Security](https://jobicy.com/jobs/151780-director-ai-enablement-security.md)

Bloomreach is building the world’s premier agentic platform for personalization.We’re revolutionizing how businesses connect with their customers, building and deploying AI agents to personalize the entire customer journey. We’re taking…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI Sep 26

### [Security Engineer, Infrastructure Security](https://jobicy.com/jobs/151778-security-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI Sep 26

### [Technical Threat Investigator, Threat Intel Engineering](https://jobicy.com/jobs/151752-technical-threat-investigator-threat-intel-engineering.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Threat Intelligence team protects OpenAI’s technology, people, research,…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI Sep 26

### [Security Engineer, Agent Security](https://jobicy.com/jobs/151775-security-engineer-agent-security.md)

About the TeamThe team’s mission is to accelerate the secure evolution of agentic AI systems at OpenAI. To achieve this, the team designs, implements, and continuously refines security policies, frameworks,…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI Sep 26

### [Security Engineer, Detection and Response](https://jobicy.com/jobs/151765-security-engineer-detection-and-response.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![FastSpring logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2024/04/76c6c41f-221.jpeg)
FastSpring Sep 26

### [Sr. Security Engineer](https://jobicy.com/jobs/151709-sr-security-engineer.md)

About FastSpring: FastSpring is how AI, SaaS, gaming, software, and digital product companies sell online in more places around the world. We handle all payment needs from checkout to taxes…

[Browse all jobs](https://jobicy.com/jobs.md)