Staff Detection Security Operations Engineer
About Us
At Arkenstone Defense, we empower defense tech startups with the tools, infrastructure, and compliance solutions they need to become successful prime contractors. Our mission is to remove barriers and help innovators grow - from day one to becoming a trusted prime for the U.S. Government.
We're early, we're lean, and we're building something that actually matters. The people who do well here aren't waiting to be told what to do; they see a gap and fill it.
Overview
We are seeking a Staff Detection Security Operations Engineer (Remote, US) to focus on leading the design and implementation of operational excellence across our multi-cloud environments for threat monitoring, detection, and security data analytics supporting our federal and commercial customer base. You will identify complex security and technical compliance issues, recognize patterns and root causes, and help design innovative solutions that improve our threat monitoring and detection services. You will bring your experience with security systems and incident response — both on-premises and in cloud environments — to a team growing around supporting FedRAMP-authorized Cloud Service Providers.
This role operates on the frontline of the Mission Assurance Center (MAC), working to triage alerts, investigate threats, and protect internal and customer-facing environments. It is ideal for a motivated analyst who wants to grow quickly in a compliance-heavy, mission-critical environment where your work directly supports the security of cleared workforces. You will execute defi ned tasks under direct supervision, follow established playbooks, and build the foundational skills that drive career progression within the MAC.
This role is central to ensuring the scalability, reliability, and performance of our products running in AWS, Azure, and GCP infrastructure. As the Staff Detection Security Operations Engineer, you will own the uptime, observability, and system resilience for our critical services. This includes driving architecture decisions, automation practices, and incident response strategies—working closely with the product owner(s), developer teams, and security operations teams.
What You’ll Do
Engineering
- Design and review security architectures, reference implementations, and control patterns for FedRAMP/CMMC-aligned environments.
- Lead complex security assessments and technical deep-dives; identify root causes and drive sustainable remediation across the customer portfolio.
- Guide the confi guration and evolution of core security tooling — including SIEM, EDR, vulnerability management, logging pipelines, and data ingestion architectures.
- Develop advanced automation, reusable modules, and infrastructure-as-code patterns that engineering teams adopt across programs.
- Lead cross-functional technical initiatives spanning security, IT, compliance, and product engineering teams.
- Drive observability improvements across the security stack — metrics, alerting, and dashboards for operational health.
- Evaluate emerging technologies and tooling; make build-vs-buy recommendations to MAC leadership.
- Provide technical mentorship and code/design review for engineers; infl uence standards, runbooks, and best practices across the team.
- Design, implement, and own the infrastructure reliability strategy across AWS, Azure, and GCP
- Champion observability by developing and maintaining effective logging, monitoring, and alerting systems
- Lead efforts in performance tuning, system hardening, capacity planning, and disaster recovery
- Automate deployment, scaling, and recovery workfl ows to reduce manual toil
- Act as a mentor and technical leader to junior engineers and cross-functional partners
- Perform any other related duties as required or assigned
Threat Monitoring & Detection
- Own the incident management lifecycle: from detection to postmortem and root cause analysis
- Monitor SIEM and security tools for alerts; perform initial triage and escalate per documented playbooks; tune and create detection SIEM alerts
- Collect and correlate security data from multiple sources to distinguish true positives from noise
- Monitor and analyze threat intelligence sources to detect potential security threats and vulnerabilities; implement continuous monitoring systems to ensure real-time awareness of security events
- Participate in on-call rotation for after-hours security monitoring and incident response.
Process & Knowledge Development
- Maintain and improve runbooks, knowledge base articles, and repetitive task automations
- Work closely with internal engineering, development, and compliance teams to implement security measures and address compliance requirements
- Stay current on industry trends, emerging threats, and changes in compliance standards to ensure ongoing effectiveness.
Requirements
- 5-8 years of experience in Security Engineering and/or Detection engineering roles
- Hands-on exposure to AWS Athena
- Profi ciency in detection engineering: alert creation and tuning - writing SQL, KQL, Sigma, or YARA rules for threat detection
- Proven track record of operating large-scale systems in multi-cloud environments
- Strong knowledge of cloud-native architecture, container orchestration (e.g., Kubernetes), and CI/CD pipelines
- Profi cient in scripting (Python, Bash, etc.) and infrastructure automation tools
- Experience with monitoring/observability platforms (e.g., Prometheus, Grafana, Datadog, etc.)
- Excellent problem-solving skills and a bias toward ownership and action
- Familiarity with SIEM platforms
- Working knowledge of incident response processes, procedures, and documentation standards
- Comfortable making decisions under pressure and leading through incidents
- Working knowledge of FedRAMP or NIST 800-53 controls preferred
- Comfortable participating in customer discussions
- Clear communicator who can translate technical concepts to mixed audiences
Who You Are
- Drive a culture of accountability, ownership, and continuous improvement
- You thrive on building meaningful relationships and helping others succeed
- You understand the unique challenges that defense tech startups face, and can speak their language
Mission Alignment
We are a Defense-focused company supporting sensitive and cleared workforces. The Staff Detection Security Operations Engineer will embrace our commitment to operational excellence, compliance rigor, and a world-class employee experience.
Physical Requirements
- Prolonged periods of sitting at a desk and working on a computer
- Must be able to lift up to 15 pounds at times
- May require occasional travel to office locations or client sites
- Ability to communicate effectively in written and verbal form
Benefits for working with us!
We are committed to supporting our employees both professionally and personally. Our robust benefits package is designed to promote your well-being, growth, and work-life balance
- Competitive Salary: Recognizing your hard work with attractive compensation and rewarding excellence.
- Health and Wellness Programs: Including medical, dental, & vision insurance options, along with mental health support & wellness initiatives.
- Retirement Planning: Secure your future with our flexible 401(k) plan and matching company contributions.
- Paid Time Off & Holidays: Generous PTO, sick leave, and holiday pay to help you recharge and enjoy life outside of work.
- Employee Assistance Program: Confidential resources for personal and professional support.
- Professional Development: Access to training, certifications, and continuing education to foster your career growth.
We are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, disability, genetic information, veteran status, or any other characteristic protected under applicable law.