Senior Security Operations Engineer
Tandem Health2 days ago
Stockholm, SwedenSenior
Responsibilities
- Own a risk-prioritized plan for integrating data sources into the SIEM and build telemetry health checks for missing, delayed, or incomplete data.
- Develop and maintain the detection lifecycle, including creation, testing, tuning, ownership, and retirement.
- Lead and coordinate technical security incident response, including scope assessment, containment, remediation, escalation, and after-action reviews.
- Make containment decisions with security leadership and system owners and take authorized actions under approved playbooks.
- Run practical incident-response training and exercises for colleagues.
- Provide technical evidence to medical-device compliance and legal teams for potential privacy incidents.
- Build an effective operating model with the MDR provider and other security partners.
- Measure telemetry coverage, detection quality, response time, hand-off quality, and follow-up actions.
- Evaluate AI uses in security operations with data boundaries, evaluation, human approval, audit, and fallback controls.
- Document systems, processes, and decisions for future team members.
Requirements
- Demonstrated ability to coordinate security incidents across technical and non-technical teams and make sound decisions with incomplete information.
- Experience working with identity, endpoint, cloud, network, and application telemetry.
- Ability to build and operate SIEM integrations, detections, and telemetry health checks.
- Ability to use code or automation to reduce repetitive work and improve response reliability.
- Ability to distinguish expected behavior, control failures, and credible malicious activity.
- Ability to write clear playbooks, investigation notes, and after-action reviews and explain technical risk to varied audiences.
- Ability to bring structure to incomplete processes and remain calm during ambiguous situations.
- A particular degree or certification is not required; demonstrated capability is prioritized.
- Bonus: experience with co-managed MDR or managed security service providers, detection validation and tuning, incident command, security exercises, or internal training.
- Bonus: experience in healthcare, regulated environments, high-growth technology companies, version-controlled detections or integrations, or AI and machine learning in security operations.
Benefits
- Competitive salary and company stock options.
- Additional compensation for on-call rotations.
- 30 days of paid holiday annually.
- 5,000 SEK wellness allowance plus 6,000 SEK annually for other health-related initiatives.
- Parental leave top-up, private medical insurance, mental health support through Mindler, and a pension programme.
- Regular social and team activities, including off-sites and seasonal events.
- Primarily based at the headquarters in central Stockholm, with a shared after-hours escalation rotation.
- Background check required before hiring.