368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$121k – $225k per year (Estimated)
Location
Remote (United States)
Seniority
Senior · 3+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Solace is on a health tech startup mission to empower patients, improve outcomes, and restore the promise of the U.S. healthcare system.

About Solace

Healthcare in the U.S. is fundamentally broken. The system is so complex that 88% of U.S. adults do not have the health literacy necessary to navigate it without help. Solace cuts through the red tape of healthcare by pairing patients with expert advocates and giving them the tools to make better decisions-and get better outcomes.

We're a Series C startup, founded in 2022 and backed by Inspired Capital, Craft Ventures, Torch Capital, Menlo Ventures, Signalfire, and IVP. Our U.S. based team is lean, mission-driven, and growing quickly.

Solace isn't a place to coast. We're here to redefine healthcare-and that demands urgency, precision, and heart. If you're looking to stretch yourself, sharpen your edge, and do the best work of your life alongside a team that cares deeply, you're in the right place. We’re intense, and we like it that way.

Read more in our Bloomberg funding announcementhere.

About the Role

We're looking for a Sr. Security Engineer to join our growing security team at Solace. You'll be a generalist at heart, but your first and most important mission is clear: own our detection and alerting program end to end.

We have the raw materials in place - a Datadog SIEM with logs flowing in from across our identity, cloud, endpoint, and SaaS stack - but we need someone who can turn that telemetry into a high-signal detection program. You'll decide what we detect, write and tune the rules, kill the noise, and make sure that when something real happens, we know fast and respond well.

This is a hands-on, high-ownership role on a small team in a HIPAA-regulated environment. You'll report to our Staff Security Engineer and work alongside engineers focused on application and infrastructure security. What you build here will be the foundation of security operations at Solace for years.

What You'll Do

Detection Engineering & SIEM Ownership (Primary Focus)

  • Own our Datadog Cloud SIEM: log pipelines, parsing, enrichment, retention, and cost management

  • Build, tune, and maintain detection rules across our environment - identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (GitHub, Slack, and more)

  • Systematically reduce alert noise and drive alert quality metrics (fidelity, time-to-triage, false-positive rates)

  • Map detection coverage against real-world threats (MITRE ATT&CK) and close the highest-risk gaps first

  • Treat detections as code: version-controlled, tested, documented, and peer-reviewed

  • Ensure logging and audit trails meet HIPAA requirements for ePHI systems

Incident Response

  • Serve as a primary responder for security alerts and incidents: triage, investigate, contain, and document

  • Improve and extend our incident response playbooks, and run post-incident reviews that produce real fixes

  • Build automation to speed up triage and response (enrichment, auto-containment, workflow automation)

  • Participate in and help mature our on-call rotation as the team grows

Generalist Security Engineering

  • Contribute to cloud and infrastructure security hardening across AWS and GCP

  • Support identity and access management improvements (Okta policies, access reviews, least privilege)

  • Pitch in on vendor security reviews, security questionnaires, and audit evidence gathering (HIPAA, SOC 2)

  • Help build a security-first culture through documentation, tooling, and partnership with engineering teams

What We're Looking For

Required:

  • 3-6 years in security operations, detection engineering, incident response, or similar hands-on security roles

  • Real experience building and tuning detections in a SIEM - Datadog Cloud SIEM strongly preferred, but deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther translates well

  • Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms

  • Hands-on incident response experience: you've triaged real alerts, worked real incidents, and written the post-mortems

  • Scripting ability (Python or similar) for automation, log analysis, and detection tooling

  • Strong understanding of common attack patterns - phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks

  • Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal

Nice to Have:

  • Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST)

  • Detection-as-code workflows (Terraform, CI/CD for detections)

  • SOAR or workflow automation experience (Tines, Windmill, custom tooling)

  • Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective

  • Threat hunting experience or contributions to open-source detection content

Working Style:

  • Bias toward action - you'd rather ship a good detection today and iterate than design the perfect one for a month

  • High signal in communication: clear incident writeups, honest post-mortems, and the ability to explain risk to non-security audiences

  • Strong ownership mentality - you notice gaps and close them without being asked

  • Collaborative and low-ego on a small team where everyone wears multiple hats

  • Care about doing security right in an environment where patient data is at stake

Applicants must be based in the United States.

Up for the Challenge?

We look forward to meeting you.

Fraudulent Recruitment Advisory: Solace Health will NEVER request bank details or offer employment without an interview. All legitimate communications come from official solace.health emails only or ashbyhq.com. Report suspicious activity to [email protected] or [email protected].

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$73k – $186k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Toronto
Java
Python
SQL
Databases
Databricks
AI/ML
Spark
DevOps
AWS
Azure
Bitbucket
GCP
Git
Analytics
ETL/ELT
Apply
$88k – $224k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Waterloo
Java
Python
SQL
Databases
Databricks
AI/ML
Spark
DevOps
AWS
Azure
Bitbucket
GCP
Git
Analytics
ETL/ELT
Apply
Remote/Hybrid • Internship • Bachelor's Degree • Toronto
Java
Python
SQL
Databases
Databricks
AI/ML
Spark
DevOps
AWS
Azure
Bitbucket
GCP
Git
Analytics
ETL/ELT
Apply
$73k – $183k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • Zug
Python
Python
FastAPI
Databases
PostgreSQL
Redis
AI/ML
AI Agents
AWS Bedrock
AWS Bedrock AgentCore
LLM
DevOps
Amazon EKS
AWS
AWS CDK
CI/CD
Datadog
Kubernetes
OpenTelemetry
Platform Engineering
Apply
$136k – $253k per year • Equity • Remote/Hybrid • Full-Time • 10+ years exp • Frisco • New York • Toronto • Ann Arbor
Python
SQL
Java
Java
Flyway
AI/ML
AWS Bedrock
Claude
LLM
Anthropic
AWS Bedrock AgentCore
LLM Guardrails
LLMOps
DevOps
Amazon EKS
AWS
CI/CD
Datadog
Docker
Kubernetes
Apply
$61k – $174k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Redwood City
Python
SQL
Databases
Snowflake
AI/ML
dbt
NLP
NumPy
Scikit-learn
Time Series Forecasting
DevOps
AWS
Docker
Analytics
A/B Testing
Apply
$55k – $119k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Redwood City
Python
SQL
AI/ML
dbt
DevOps
Git
Analytics
Tableau
Apply
$62k – $177k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Redwood City
Python
SQL
Databases
PostgreSQL
Snowflake
AI/ML
dbt
DevOps
AWS
Docker
GCP
Terraform
Analytics
ETL/ELT
Apply
$64k – $167k per year (Estimated) • In office • Full-Time • Redwood City
Apply
$45k – $150k per year (Estimated) • In office • Full-Time • Redwood City
Design
Figma
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.