> Markdown version of [/jobs/ext/1888614-telecommute-principal-software-engineer-ai-siem](https://www.wearedevelopers.com/jobs/ext/1888614-telecommute-principal-software-engineer-ai-siem). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # TELECOMMUTE Principal Software Engineer, AI SIEM - **Company:** ยท Sentinelone - **Location:** United States (Remote available) - **Salary:** $216,000.0 - $297,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Cyber Security, Data Infrastructure, Distributed Data Store, Security Information and Event Management, Backend, Information Technology - **Published:** August 1, 2026 - **Apply:** https://www.dice.com/job-detail/ede2966b-a3d7-409a-bb1d-02123c860243 ## About the Role * Deep experience (15 or more years) building and operating large-scale distributed backend systems, with direct experience in at least two of: high-throughput data ingest/storage, query engines, or detection/rules systems. * A demonstrated track record of reasoning about systems at the architecture level, not just implementing a spec, but identifying where a system's boundaries are wrong, where responsibilities overlap, and where they leave gaps. * Experience designing APIs and service contracts that need to hold up across teams and years, not just within one codebase. * Comfort operating without a single clear chain of command, influencing peer teams and senior engineers through the strength of your reasoning. * A four-year degree in Computer Science or equivalent practical experience. * Familiarity with security operations concepts (alerts, findings, assets, incidents, detection rules) is preferred; if you don't have direct SIEM/XDR background, you should be someone who can get fluent in a new domain fast. * Experience with modern cloud infrastructure and data-intensive systems (distributed storage, high-cardinality querying, streaming pipelines) is preferred; specific tools matter less than demonstrated judgment about tradeoffs at scale. * Exposure to both rule-based and ML/AI-driven detection approaches is a plus, but the more important trait is being able to reason about when each is the right tool. ## Description * Build a working mental model of the full system, including ingest and storage, query and retrieval, analyst-facing workflows (alerts, findings, assets, incidents), and the detection engines (rule-based and beyond), and use it to identify where architecture is solid, where it's fragile, and where teams are unknowingly duplicating effort or leaving gaps between their boundaries. * Drive cross-team architectural decisions that affect multiple parts of the system at once, for example, how ingest-time enrichment should relate to detection logic, or how detection output should shape what an analyst sees and can act on. * Partner with the engineering leads of each pillar (data platform, analyst experience, detection engines) as a peer thought partner, not a top-down authority, influencing through technical credibility and clear reasoning, not mandate. * Identify and prioritize the highest-leverage architectural investments across the system, and make the case for them to engineering leadership and product. * Get hands-on where it matters: prototype, review, and occasionally build the connective tissue between pillars when no single team naturally owns it. * Establish and champion cross-cutting technical standards, for APIs, data contracts, and service boundaries, that keep independently-developed pillars interoperable as they evolve. * Mentor senior and staff engineers across teams, raising the bar for architectural thinking org-wide, not just within one team. * Represent the technical health of the overall system in planning and leadership conversations, translating "what's exceptional, what's a gap, what's redundant" into a roadmap. ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Shipping Faster with Less: Render on Cloud Hosting, AI Workloads, and the Future of DevOps](https://www.wearedevelopers.com/videos/1894-shipping-faster-with-less-render-on-cloud-hosting-ai-workloads-and-the-future-of-devops) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this)