About The Position

Solace is a Series C startup founded in 2022, aiming to simplify healthcare navigation for patients by pairing them with expert advocates and providing tools for better decision-making and outcomes. The company is backed by prominent investors and is experiencing rapid growth. Solace is seeking a Sr. Security Engineer to join its security team, with a primary focus on owning the end-to-end detection and alerting program. This role involves transforming raw telemetry from various sources into a high-signal detection program, deciding on detection strategies, writing and tuning rules, reducing noise, and ensuring rapid detection and response to security events. It is a hands-on, high-ownership position within a small team operating in a HIPAA-regulated environment. The successful candidate will report to the Staff Security Engineer and collaborate with application and infrastructure security engineers, building the foundation for Solace's security operations.

Requirements

  • 3–6 years in security operations, detection engineering, incident response, or similar hands-on security roles
  • Real experience building and tuning detections in a SIEM — Datadog Cloud SIEM strongly preferred, but deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther translates well
  • Fluency reading and correlating logs from cloud providers (CloudTrail, GCP audit logs), identity providers, and SaaS platforms
  • Hands-on incident response experience: you've triaged real alerts, worked real incidents, and written the post-mortems
  • Scripting ability (Python or similar) for automation, log analysis, and detection tooling
  • Strong understanding of common attack patterns — phishing, credential compromise, SSO abuse, cloud misconfigurations, supply chain risks
  • Comfortable with ambiguity and building from scratch; startup or small-team experience is a strong signal

Nice To Haves

  • Experience in healthcare or other regulated environments (HIPAA, SOC 2, HITRUST)
  • Detection-as-code workflows (Terraform, CI/CD for detections)
  • SOAR or workflow automation experience (Tines, Windmill, custom tooling)
  • Familiarity with Okta, Jamf, Snowflake, GitHub, or Vanta from a security operations perspective
  • Threat hunting experience or contributions to open-source detection content

Responsibilities

  • Own our Datadog Cloud SIEM: log pipelines, parsing, enrichment, retention, and cost management
  • Build, tune, and maintain detection rules across our environment — identity (Okta, Google Workspace), cloud (AWS, GCP), endpoint (Jamf), data platforms (Snowflake), and SaaS audit logs (GitHub, Slack, and more)
  • Systematically reduce alert noise and drive alert quality metrics (fidelity, time-to-triage, false-positive rates)
  • Map detection coverage against real-world threats (MITRE ATT&CK) and close the highest-risk gaps first
  • Treat detections as code: version-controlled, tested, documented, and peer-reviewed
  • Ensure logging and audit trails meet HIPAA requirements for ePHI systems
  • Serve as a primary responder for security alerts and incidents: triage, investigate, contain, and document
  • Improve and extend our incident response playbooks, and run post-incident reviews that produce real fixes
  • Build automation to speed up triage and response (enrichment, auto-containment, workflow automation)
  • Participate in and help mature our on-call rotation as the team grows
  • Contribute to cloud and infrastructure security hardening across AWS and GCP
  • Support identity and access management improvements (Okta policies, access reviews, least privilege)
  • Pitch in on vendor security reviews, security questionnaires, and audit evidence gathering (HIPAA, SOC 2)
  • Help build a security-first culture through documentation, tooling, and partnership with engineering teams
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service