×
Register Here to Apply for Jobs or Post Jobs. X

Sr. Security Engineer (Detection

Job in Columbus, Franklin County, Ohio, 43224, USA
Listing for: Socket.dev
Full Time position
Listed on 2026-08-02
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 140000 - 190000 USD Yearly USD 140000.00 190000.00 YEAR
Job Description & How to Apply Below
Position: Sr. Security Engineer (Detection)

About Solace

Healthcare in the U.S. is fundamentally broken. The system is so complex that 88% of U.S. adults do not have the health literacy necessary to navigate it without help. Solace cuts through the red tape of healthcare by pairing patients with expert advocates and giving them the tools to make better decisions—and get better outcomes.

We're a Series C startup, founded in 2022 and backed by Inspired Capital, Craft Ventures, Torch Capital, Menlo Ventures, Signalfire, and IVP. Our U.S. based team is lean, mission-driven, and growing quickly.

Solace isn't a place to coast. We're here to redefine healthcare—and that demands urgency, precision, and heart. If you're looking to stretch yourself, sharpen your edge, and do the best work of your life alongside a team that cares deeply, you're in the right place. We’re intense, and we like it that way.

Read more in our Bloomberg funding announcement here.

About the Role

We're looking for a Sr. Security Engineer to join our growing security team 'll be a generalist at heart, but your first and most important mission is clear: own our detection and alerting program end to end.

We have the raw materials in place — a Datadog SIEM with logs flowing in from across our identity, cloud, endpoint, and SaaS stack — but we need someone who can turn that telemetry into a high-signal detection program. You'll decide what we detect, write and tune the rules, kill the noise, and make sure that when something real happens, we know fast and respond well.

This is a hands-on, high-ownership role on a small team in a HIPAA-regulated environment. You'll report to our Staff Security Engineer and work alongside engineers focused on application and infrastructure security. What you build here will be the foundation of security operations at Solace for years.

What You'll DoDetection Engineering & SIEM Ownership (Primary Focus)
  • Own our Datadog Cloud SIEM: log pipelines, parsing, enrichment, retention, and cost management
  • Build, tune, and maintain detection rules across our environment — identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (Git Hub, Slack, and more)
  • Systematically reduce alert noise and drive alert quality metrics (fidelity, time-to-triage, false-positive rates)
  • Map detection coverage against real-world threats (MITRE ATT&CK) and close the highest-risk gaps first
  • Treat detections as code: version-controlled, tested, documented, and peer-reviewed
  • Ensure logging and audit trails meet HIPAA requirements for ePHI systems
Incident Response
  • Serve as a primary responder for security alerts and incidents: triage, investigate, contain, and document
  • Improve and extend our incident response playbooks, and run post-incident reviews that produce real fixes
  • Build automation to speed up triage and response (enrichment, auto-containment, workflow automation)
  • Participate in and help mature our on-call rotation as the team grows
Generalist Security Engineering
  • Contribute to cloud and infrastructure security hardening across AWS and GCP
  • Support identity and access management improvements (Okta policies, access reviews, least privilege)
  • Pitch in on vendor security reviews, security questionnaires, and audit evidence gathering (HIPAA, SOC
    2)
  • Help build a security-first culture through documentation, tooling, and partnership with engineering teams
What We’re Looking For

Required:
  • 3–6 years in security operations, detection engineering, incident response, or similar hands‑on security roles
  • Real experience building and tuning detections in a SIEM — Datadog Cloud SIEM strongly preferred, but deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther translates well
  • Fluency reading and correlating logs from cloud providers (Cloud Trail, GCP audit logs), identity providers, and SaaS platforms
  • Hands‑on incident response experience: you've triaged real alerts, worked real incidents, and written the post‑mortems
  • Scripting ability (Python or similar) for automation, log analysis, and detection tooling
  • Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks
  • Comfo…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary