Sword Health logo
Sword Health·

Senior Security Operations Engineer - Sword Health

Fully remoteFull-timeSenior$133K - $209KUTC-8–-4USA only#Python#AWS#siemEquityCommissionBonusHealthMental health

At Sword, we’re building AI to heal billions and unlock humanity’s full potential. In doing so, we’re pioneering AI Care, a fundamentally new approach to healthcare built for medical reasoning, safety, and real-time treatment.

AI Proficiency at Sword

AI fluency is a core expectation at Sword. Every candidate is assessed against our three-level framework:

  • Explorer (Level 1) — Uses AI daily to boost personal productivity
  • Builder (Level 2) — Creates workflows and tools that elevate the whole team
  • Integrator (Level 3) — Embeds AI into products and processes at scale

Every hire must demonstrate at least Level 1.

Role Overview

As a Senior Security Operations Engineer at Sword, you will be at the forefront of safeguarding our cloud infrastructure and applications. Your expertise will ensure robust security measures, incident response, and continuous operational improvement.

What You’ll Be Doing

  • Design and continuously improve detection and alerting controls, ensuring high fidelity and contextual relevance to reduce noise and enable rapid response.
  • Build, test, and automate incident response playbooks and runbooks, increasing efficiency across the incident lifecycle.
  • Drive prioritization of alerts using a data-driven, scalable triage framework aligned with business impact and threat context.
  • Lead in-depth investigations, including root cause analysis and digital forensics, converting findings into actionable insights.
  • Proactively engage in threat intelligence and threat hunting, identifying new TTPs and enriching existing controls.
  • Own incident handling from detection to resolution, collaborating with engineering, IT, and business teams.
  • Define and maintain operational metrics for incident response to drive continuous improvement in speed, accuracy, and readiness.

What You Need to Have

  • Clearance: Required to obtain and maintain a US Public Trust Clearance.
  • Bachelor’s degree in Computer Science, Cybersecurity, or equivalent professional experience.
  • Solid experience in cloud environments (AWS, GCP, or Azure) with a strong understanding of cloud-native threats.
  • Proficiency in scripting languages (e.g., Python, Bash) for automation and tooling development.
  • Hands-on experience with SOC tools and platforms, such as SIEM (Splunk, Sentinel), SOAR, EDR/XDR, and log management.
  • Strong understanding of incident containment, eradication strategies, and digital evidence preservation.
  • Familiarity with security frameworks and standards (NIST 800-61, CIS Controls, MITRE ATT&CK, ISO 27001).
  • Background in threat modeling, adversary emulation, and risk-based alert tuning.
  • Leverage AI to automate and optimize security operations workflows, including alert triage, enrichment, classification, and AI-assisted runbooks.
  • Excellent analytical, communication, and cross-functional leadership skills under high-pressure situations.

Compensation & Benefits

  • Total Compensation Range: $133,000 – $209,000 USD (Reflects base salary, variable incentives, and estimated equity value).

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Sword Health

Similar remote roles