RemoteJobs.org mascotRemoteJobs.org
Remote JobsCompaniesAPISign inPost a Job
RemoteJobs.org mascotRemoteJobs.org

Find your dream remote job. Browse thousands of remote positions from top companies worldwide.

Job Categories

  • General
  • Programming
  • Design
  • Marketing
  • Sales
  • Customer Support

Resources

  • Browse Jobs
  • Companies
  • Post a Job
  • For Developers
  • Blog

Company

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service
© 2026 RemoteJobs.org. All rights reserved.
    ← Back to all jobs
    Solace

    Sr. Security Engineer (Detection)

    Solace
    Full-time
    USACyber SecurityToday

    About this role

    About Solace

    Healthcare in the U.S. is fundamentally broken. The system is so complex that 88% of U.S. adults do not have the health literacy necessary to navigate it without help. Solace cuts through the red tape of healthcare by pairing patients with expert advocates and giving them the tools to make better decisions—and get better outcomes.

    We're a Series C startup, founded in 2022 and backed by Inspired Capital, Craft Ventures, Torch Capital, Menlo Ventures, Signalfire, and IVP. Our U.S. based team is lean, mission-driven, and growing quickly.

    Solace isn't a place to coast. We're here to redefine healthcare—and that demands urgency, precision, and heart. If you're looking to stretch yourself, sharpen your edge, and do the best work of your life alongside a team that cares deeply, you're in the right place. We’re intense, and we like it that way.

    Read more in our Bloomberg funding announcement here.

    About the Role

    We're looking for a Sr. Security Engineer to join our growing security team at Solace. You'll be a generalist at heart, but your first and most important mission is clear: own our detection and alerting program end to end.

    We have the raw materials in place — a Datadog SIEM with logs flowing in from across our identity, cloud, endpoint, and SaaS stack — but we need someone who can turn that telemetry into a high-signal detection program. You'll decide what we detect, write and tune the rules, kill the noise, and make sure that when something real happens, we know fast and respond well.

    This is a hands-on, high-ownership role on a small team in a HIPAA-regulated environment. You'll report to our Staff Security Engineer and work alongside engineers focused on application and infrastructure security. What you build here will be the foundation of security operations at Solace for years.

    What You'll Do

    Detection Engineering & SIEM Ownership (Primary Focus)

    Own our Datadog Cloud SIEM: log pipelines, parsing, enrichment, retention, and cost management

    Build, tune, and maintain detection rules across our environment — identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (GitHub, Slack, and more)

    Systematically reduce alert noise and drive alert quality metrics (fidelity, time-to-triage, false-positive rates)

    Map detection coverage against real-world threats (MITRE ATT&CK) and close the highest-risk gaps first

    Treat detections as code: version-controlled, tested, documented, and peer-reviewed

    Ensure logging and audit trails meet HIPAA requirements for ePHI systems

    Incident Response

    Serve as a primary responder for security alerts and incidents: triage, investigate, contain, and document

    Improve and extend our incident response playbooks, and run post-incident reviews that produce real fixes

    Build automation to speed up triage and response (enrichment, auto-containment, workflow automation)

    Participate in and help mature our on-call rotation as the team grows

    Generalist Security Engineering

    Contribute to cloud and infrastructure security hardening across AWS and GCP

    Support identity and access management improvements (Okta policies, access reviews, least privilege)

    Pitch in on vendor security reviews, security questionnaires, and audit evidence gathering (HIPAA, SOC 2)

    Help build a security-first culture through documentation, tooling, and partnership with engineering teams

    What We're Looking For

    Required:

    3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles

    Real experience building and tuning detections in a SIEM — Datadog Cloud SIEM strongly preferred, but deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther translates well

    Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms

    Hands-on incident response experience: you've triaged real alerts, worked real incidents, and written the post-mortems

    Scripting ability (Python or similar) for automation, log analysis, and detection tooling

    Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks

    Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal

    Nice to Have:

    Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST)

    Detection-as-code workflows (Terraform, CI/CD for detections)

    SOAR or workflow automation experience (Tines, Windmill, custom tooling)

    Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective

    Threat hunting experience or contributions to open-source detection content

    Working Style:

    Bias toward action — you'd rather ship a good detection today and iterate than design the perfect one for a month

    High signal in communication: clear incident writeups, honest post-mortems, and the ability to explain risk to non-security audiences

    Strong ownership mentality — you notice gaps and close them without being asked

    Collaborative and low-ego on a small team where everyone wears multiple hats

    Care about doing security right in an environment where patient data is at stake

    Applicants must be based in the United States.

    Up for the Challenge?

    We look forward to meeting you.

    Fraudulent Recruitment Advisory: Solace Health will NEVER request bank details or offer employment without an interview. All legitimate communications come from official solace.health emails only or ashbyhq.com. Report suspicious activity to recruiting@solace.health or advocate@solace.health.

    About Solace

    Solace
    Solace

    Solace is a healthcare technology company that addresses the complexity of the U.S. healthcare system by pairing patients with expert advocates and providing tools to help them make better healthcare decisions and achieve better outcomes. The company recognizes that 88% of U.S. adults lack the health literacy necessary to navigate healthcare without assistance, and positions itself as a solution that cuts through bureaucratic red tape. Solace operates a patient care program that connects patients with healthcare advocates and physicians to holistically address their needs, including social determinants of health such as food resources, transportation access, and home support. The company is a Series C startup backed by prominent investors including Inspired Capital, Craft Ventures, Torch Capital, Menlo Ventures, Signalfire, and IVP.

    Hiring remote talent?

    Reach active remote job seekers from $149.

    Related Jobs

    Information Security Engineer

    Algolia

    Enterprise Account Executive - PNW

    Pentera

    Cybersecurity Founding Engineer (100 % remote) (m/f/d)

    EWOR GmbH