Staff Detection Security Operations Engineer

3 days ago

Menlo Park, CA, United States Arkenstone Defense Full-time
About Us At Arkenstone Defense, we empower defense tech startups with the tools, infrastructure, and compliance solutions they need to become successful prime contractors. Our mission is to remove barriers and help innovators grow - from day one to becoming a trusted prime for the U.S. Government.

We're early, we're lean, and we're building something that actually matters. The people who do well here aren't waiting to be told what to do; they see a gap and fill it.

Overview We are seeking a

Staff Detection Security Operations Engineer

(Remote, US) to focus on leading the design and implementation of operational excellence across our multi-cloud environments for threat monitoring, detection, and security data analytics supporting our federal and commercial customer base. You will identify complex security and technical compliance issues, recognize patterns and root causes, and help design innovative solutions that improve our threat monitoring and detection services. You will bring your experience with security systems and incident response — both on-premises and in cloud environments — to a team growing around supporting FedRAMP-authorized Cloud Service Providers.

This role operates on the frontline of the Mission Assurance Center (MAC), working to triage alerts, investigate threats, and protect internal and customer-facing environments. It is ideal for a motivated analyst who wants to grow quickly in a compliance-heavy, mission-critical environment where your work directly supports the security of cleared workforces. You will execute defi ned tasks under direct supervision, follow established playbooks, and build the foundational skills that drive career progression within the MAC.

This role is central to ensuring the scalability, reliability, and performance of our products running in AWS, Azure, and GCP infrastructure. As the Staff Detection Security Operations Engineer, you will own the uptime, observability, and system resilience for our critical services. This includes driving architecture decisions, automation practices, and incident response strategies—working closely with the product owner(s), developer teams, and security operations teams.

What You’ll Do Engineering

Design and review security architectures, reference implementations, and control patterns for FedRAMP/CMMC-aligned environments.

Lead complex security assessments and technical deep-dives; identify root causes and drive sustainable remediation across the customer portfolio.

Guide the confi guration and evolution of core security tooling — including SIEM, EDR, vulnerability management, logging pipelines, and data ingestion architectures.

Develop advanced automation, reusable modules, and infrastructure-as-code patterns that engineering teams adopt across programs.

Lead cross-functional technical initiatives spanning security, IT, compliance, and product engineering teams.

Drive observability improvements across the security stack — metrics, alerting, and dashboards for operational health.

Evaluate emerging technologies and tooling; make build-vs-buy recommendations to MAC leadership.

Provide technical mentorship and code/design review for engineers; infl uence standards, runbooks, and best practices across the team.

Design, implement, and own the infrastructure reliability strategy across AWS, Azure, and GCP

Champion observability by developing and maintaining effective logging, monitoring, and alerting systems

Lead efforts in performance tuning, system hardening, capacity planning, and disaster recovery

Automate deployment, scaling, and recovery workfl ows to reduce manual toil

Act as a mentor and technical leader to junior engineers and cross-functional partners

Perform any other related duties as required or assigned

Threat Monitoring & Detection

Own the incident management lifecycle: from detection to postmortem and root cause analysis

Monitor SIEM and security tools for alerts; perform initial triage and escalate per documented playbooks; tune and create detection SIEM alerts

Collect and correlate security data from multiple sources to distinguish true positives from noise

Monitor and analyze threat intelligence sources to detect potential security threats and vulnerabilities; implement continuous monitoring systems to ensure real-time awareness of security events

Participate in on-call rotation for after-hours security monitoring and incident response.

Process & Knowledge Development

Maintain and improve runbooks, knowledge base articles, and repetitive task automations

Work closely with internal engineering, development, and compliance teams to implement security measures and address compliance requirements

Stay current on industry trends, emerging threats