Sr. Security Engineer (Detection)
SolaceJob Description
📋 Description Own Datadog Cloud SIEM pipelines and enrichment. Build and tune detection rules across identity, cloud, endpoint, data platforms, and SaaS logs. Reduce alert noise and improve detection fidelity and triage speed. Map detection coverage to MITRE ATT&CK and close high-risk gaps. Detections as code: versioned, tested, documented, peer-reviewed. Ensure logging and audit trails meet HIPAA requirements for ePHI systems. 🎯 Requirements 3-6 years in security operations, detection, or incident response. Experience building and tuning detections in a SIEM; Datadog preferred, others ok. Fluent in reading/correlating logs from cloud providers, identity providers, and SaaS. Hands-on incident response experience with triage and post-mortems. Scripting ability (Python or similar) for automation and log analysis. Strong understanding of phishing, credential compromise, and SSO abuse. Nice to have: HIPAA, SOC 2, HITRUST experience in healthcare environments. Nice to have: Detection-as-code workflows (Terraform, CI/CD) or SOAR tooling.