> Markdown version of [/jobs/ext/2282550-staff-detection-security-operations-engineer](https://www.wearedevelopers.com/jobs/ext/2282550-staff-detection-security-operations-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Detection Security Operations Engineer - **Company:** The Arkenstone Ltd - **Location:** Menlo Park, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Engineering, Software Documentation, Cyber Security, Disaster Recovery, Intrusion Detection and Prevention, Python (Programming Language), Performance Tuning, Cloud Services, Prometheus, Kusto Query Language, Runbook, Security Information and Event Management, SQL Databases, Software Vulnerability Management, Datadog, Data Logging, Scripting, Google Cloud, Cloud Platform System, Data Ingestion, Grafana, Multi-Cloud, Reliability of Systems, Kubernetes, Infrastructure Automation Frameworks, Deployment Automation, Data Analytics - **Published:** August 28, 2026 - **Apply:** https://www.wayup.com/i-j-Staff-Detection-Security-Operations-Engineer-Arkenstone-799692287663796/ ## About the Role + 5-8 years of experience in Security Engineering and/or Detection engineering roles + Hands-on exposure to AWS Athena + Profi ciency in detection engineering: alert creation and tuning - writing SQL, KQL, Sigma, or YARA rules for threat detection + Proven track record of operating large-scale systems in multi-cloud environments + Strong knowledge of cloud-native architecture, container orchestration (e.g., Kubernetes), and CI/CD pipelines + Profi cient in scripting (Python, Bash, etc.) and infrastructure automation tools + Experience with monitoring/observability platforms (e.g., Prometheus, Grafana, Datadog, etc.) + Excellent problem-solving skills and a bias toward ownership and action + Familiarity with SIEM platforms + Working knowledge of incident response processes, procedures, and documentation standards + Comfortable making decisions under pressure and leading through incidents + Working knowledge of FedRAMP or NIST 800-53 controls preferred + Comfortable participating in customer discussions + Clear communicator who can translate technical concepts to mixed audiences, + Drive a culture of accountability, ownership, and continuous improvement + You thrive on building meaningful relationships and helping others succeed + You understand the unique challenges that defense tech startups face, and can speak their language, + Prolonged periods of sitting at a desk and working on a computer + Must be able to lift up to 15 pounds at times + May require occasional travel to office locations or client sites + Ability to communicate effectively in written and verbal form ## Description We are seeking a Staff Detection Security Operations Engineer (Remote, US) to focus on leading the design and implementation of operational excellence across our multi-cloud environments for threat monitoring, detection, and security data analytics supporting our federal and commercial customer base. You will identify complex security and technical compliance issues, recognize patterns and root causes, and help design innovative solutions that improve our threat monitoring and detection services. You will bring your experience with security systems and incident response - both on-premises and in cloud environments - to a team growing around supporting FedRAMP-authorized Cloud Service Providers. This role operates on the frontline of the Mission Assurance Center (MAC), working to triage alerts, investigate threats, and protect internal and customer-facing environments. It is ideal for a motivated analyst who wants to grow quickly in a compliance-heavy, mission-critical environment where your work directly supports the security of cleared workforces. You will execute defi ned tasks under direct supervision, follow established playbooks, and build the foundational skills that drive career progression within the MAC. This role is central to ensuring the scalability, reliability, and performance of our products running in AWS, Azure, and GCP infrastructure. As the Staff Detection Security Operations Engineer, you will own the uptime, observability, and system resilience for our critical services. This includes driving architecture decisions, automation practices, and incident response strategies-working closely with the product owner(s), developer teams, and security operations teams., + Design and review security architectures, reference implementations, and control patterns for FedRAMP/CMMC-aligned environments. + Lead complex security assessments and technical deep-dives; identify root causes and drive sustainable remediation across the customer portfolio. + Guide the confi guration and evolution of core security tooling - including SIEM, EDR, vulnerability management, logging pipelines, and data ingestion architectures. + Develop advanced automation, reusable modules, and infrastructure-as-code patterns that engineering teams adopt across programs. + Lead cross-functional technical initiatives spanning security, IT, compliance, and product engineering teams. + Drive observability improvements across the security stack - metrics, alerting, and dashboards for operational health. + Evaluate emerging technologies and tooling; make build-vs-buy recommendations to MAC leadership. + Provide technical mentorship and code/design review for engineers; infl uence standards, runbooks, and best practices across the team. + Design, implement, and own the infrastructure reliability strategy across AWS, Azure, and GCP + Champion observability by developing and maintaining effective logging, monitoring, and alerting systems + Lead efforts in performance tuning, system hardening, capacity planning, and disaster recovery + Automate deployment, scaling, and recovery workfl ows to reduce manual toil + Act as a mentor and technical leader to junior engineers and cross-functional partners + Perform any other related duties as required or assigned Threat Monitoring & Detection + Own the incident management lifecycle: from detection to postmortem and root cause analysis + Monitor SIEM and security tools for alerts; perform initial triage and escalate per documented playbooks; tune and create detection SIEM alerts + Collect and correlate security data from multiple sources to distinguish true positives from noise + Monitor and analyze threat intelligence sources to detect potential security threats and vulnerabilities; implement continuous monitoring systems to ensure real-time awareness of security events + Participate in on-call rotation for after-hours security monitoring and incident response. Process & Knowledge Development + Maintain and improve runbooks, knowledge base articles, and repetitive task automations + Work closely with internal engineering, development, and compliance teams to implement security measures and address compliance requirements + Stay current on industry trends, emerging threats, and changes in compliance standards to ensure ongoing effectiveness., We are a Defense-focused company supporting sensitive and cleared workforces. The Staff Detection Security Operations Engineer will embrace our commitment to operational excellence, compliance rigor, and a world-class employee experience. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [5 steps for running a Kubernetes environment at scale](https://www.wearedevelopers.com/videos/88-5-steps-for-running-a-kubernetes-environment-at-scale) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Software Engineering Social Connection: Yubo’s lean approach to scaling an 80M-user infrastructure](https://www.wearedevelopers.com/videos/1583-software-engineering-social-connection-yubo-s-lean-approach-to-scaling-an-80m-user-infrastructure) - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)