Principal Software Engineer, AI SIEM

SentinelOne
$216,000 - $297,000

About The Position

As a Principal Software Engineer, AI SIEM, you will be tasked with reasoning across all three layers of SentinelOne's AI SIEM: how data moves and gets queried at scale, how analysts actually work with what the system surfaces, and how detections get built and tuned. Our AI SIEM ingests petabytes of data per day, powers the analyst workflows that turn that data into alerts, findings, assets, and incidents, and drives the detection engines, both rule-based and AI-driven, that catch what matters. You will look at the system as a whole, find where it's exceptional, where it has gaps, where it has redundant or overlapping effort, and drive the architectural decisions that close those gaps. This is not a role scoped to one service or one team's backlog. It's for someone who can sit above the individual pillars, understand how they're supposed to fit together, and act when they don't.

Requirements

  • Deep experience (15 or more years) building and operating large-scale distributed backend systems, with direct experience in at least two of: high-throughput data ingest/storage, query engines, or detection/rules systems.
  • A demonstrated track record of reasoning about systems at the architecture level, not just implementing a spec, but identifying where a system's boundaries are wrong, where responsibilities overlap, and where they leave gaps.
  • Experience designing APIs and service contracts that need to hold up across teams and years, not just within one codebase.
  • Comfort operating without a single clear chain of command, influencing peer teams and senior engineers through the strength of your reasoning.
  • A four-year degree in Computer Science or equivalent practical experience.
  • Familiarity with security operations concepts (alerts, findings, assets, incidents, detection rules) is preferred; if you don't have direct SIEM/XDR background, you should be someone who can get fluent in a new domain fast.
  • Experience with modern cloud infrastructure and data-intensive systems (distributed storage, high-cardinality querying, streaming pipelines) is preferred; specific tools matter less than demonstrated judgment about tradeoffs at scale.
  • Exposure to both rule-based and ML/AI-driven detection approaches is a plus, but the more important trait is being able to reason about when each is the right tool.

Responsibilities

  • Build a working mental model of the full system, including ingest and storage, query and retrieval, analyst-facing workflows (alerts, findings, assets, incidents), and the detection engines (rule-based and beyond), and use it to identify where architecture is solid, where it's fragile, and where teams are unknowingly duplicating effort or leaving gaps between their boundaries.
  • Drive cross-team architectural decisions that affect multiple parts of the system at once, for example, how ingest-time enrichment should relate to detection logic, or how detection output should shape what an analyst sees and can act on.
  • Partner with the engineering leads of each pillar (data platform, analyst experience, detection engines) as a peer thought partner, not a top-down authority, influencing through technical credibility and clear reasoning, not mandate.
  • Identify and prioritize the highest-leverage architectural investments across the system, and make the case for them to engineering leadership and product.
  • Get hands-on where it matters: prototype, review, and occasionally build the connective tissue between pillars when no single team naturally owns it.
  • Establish and champion cross-cutting technical standards, for APIs, data contracts, and service boundaries, that keep independently-developed pillars interoperable as they evolve.
  • Mentor senior and staff engineers across teams, raising the bar for architectural thinking org-wide, not just within one team.
  • Represent the technical health of the overall system in planning and leadership conversations, translating "what's exceptional, what's a gap, what's redundant" into a roadmap.

Benefits

  • Equity & Rewards
  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
  • Flexible time off
  • Paid company holidays and paid sick time
  • Gender-neutral parental leave
  • Grandparent leave
  • Medical, dental, and vision coverage
  • 401(k) retirement plan with company match
  • Life and disability insurance
  • Health and dependent care FSA
  • Voluntary benefits (hospital, accident, critical illness)
  • Employee Assistance Program (EAP)
  • ARAG pre-paid legal
  • Nationwide pet insurance
  • Cancer Care program
  • Global business travel medical insurance
  • Home office allowance
  • Mobile phone reimbursement
  • Wellness coach
  • Wellness/gym reimbursement
  • Fertility coverage
  • Adoption & surrogacy reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service