Senior Security Operations Engineer
Sword · Remote - US
- Senior
- Full-time
- $133,000 – $209,000
- Posted 2026-09-09
- Confirmed live on 25 September 2026
Job description
At Sword, we’re building AI to heal billions and unlock humanity’s full potential. In doing so, we’re pioneering AI Care, a fundamentally new approach to healthcare built for medical reasoning, safety, and real-time treatment, not generic technology applied after the fact. As both a clinical-centric frontier AI lab and an applied AI platform, Sword is reimagining how care is delivered at scale, removing traditional barriers like appointments, waiting rooms, and stigma so more people can access the care they need—and ultimately get back to lives lived in full.
Since 2020, Sword has expanded across physical therapy, women’s health, cardiometabolic, and mental health, and is now moving beyond the session to a fully AI-native, 24/7 care program that brings physical activity, therapeutic exercise, psychotherapy, nutrition, and behavior change into one connected experience. More than 700,000 members across three continents have completed over 10 million AI sessions, helping 1,000+ enterprise clients avoid more than $1 billion in unnecessary healthcare costs. Backed by 42 clinical studies, 44+ patents, and more than $500 million raised from leading investors including Khosla Ventures, General Catalyst, and Founders Fund, Sword is defining a new standard for healthcare.
AI Proficiency at Sword
AI fluency is a core expectation at Sword. Every candidate is assessed against our three-level framework — be ready to share real examples of how AI is already part of how you work.
•
Explorer (Level 1) — Uses AI daily to boost personal productivity
•
Builder (Level 2) — Creates workflows and tools that elevate the whole team
•
Integrator (Level 3) — Embeds AI into products and processes at scale
Every hire must demonstrate at least Level 1. The expected level will vary depending on the seniority of the role.
Role
As a Senior Security Engineer (Security Operations) at Sword, you will be at the forefront of safeguarding our cloud infrastructure and applications. Your expertise will ensure robust security measures, incident response, and continuous improvement.
Are you looking to join an incredible IT team, passionate about simplifying everyone's work? Look no further, we're hiring! We're a proactive team, constantly staying ahead to ensure everything runs smoothly. As an IT Team we understand the importance of technology in today's workplace and the impact that technical issues can have on productivity and efficiency. Want to join the team? Find out if you've got what it takes!
To get to know more about our Tech Stack, check here.
What you’ll be doing
• Design and continuously improve detection and alerting controls, ensuring high fidelity and contextual relevance to reduce noise and enable rapid response.
• Architect, refine, and maintain custom YARA-L detection rules and SOAR playbooks in Google SecOps to automate triage, alert enrichment, and initial incident response.
• Drive prioritization of alerts using a data-driven, scalable triage framework, aligned with business impact and threat context.
• Lead end-to-end incident investigations in Google SecOps, leveraging complex telemetry correlation to proactively hunt for threats, contain active incidents, and drive root-cause remediation.
• Proactively engage in threat intelligence and threat hunting, identifying new tactics, techniques, and procedures (TTPs), enriching existing controls, and feeding insights into the detection pipeline.
• Own incident handling from detection to resolution, collaborating with engineering, IT, and business teams to contain, eradicate, and recover from threats.
• Define and maintain operational metrics for incident response, using them to drive continuous improvement in speed, accuracy, and organizational readiness.
What you need to have
• Required: Public Trust Clearance - Candidates must be able to obtain and maintain a US public trust clearance.
• Bachelor’s degree in Computer Science, Cybersecurity, or equivalent professional experience.
• Solid experience in cloud environments (AWS, GCP, or Azure), with strong understanding of cloud-native threats.
• Proficiency in scripting languages (e.g., Python, Bash) for automation and tooling development.
• Hands-on experience with SOC tools and platforms, such as SIEM (Splunk, Sentinel, Google SecOps/Chronicle, etc.), SOAR, EDR/XDR, and log management.
• Highly Preferred: Google SecOps/Chronicle
• Strong understanding of incident containment and eradication strategies, with proven ability to coordinate response with technical teams.
• Familiarity with security frameworks and standards (NIST 800-61, CIS Controls, MITRE ATT&CK, ISO 27001).
• Excellent analytical, critical thinking, and problem-solving skills.
• Ability to consume and synthesize intelligence about actors, techniques or situations to identify emerging risk scenarios.
• Proficiency in process formulation and improvement.
• Background in threat modeling, adversary emulation, and risk-based a
Prepare for the interview
Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.
More at Sword
- Senior AI Engineer · Remote - Portugal
- Physiotherapist Part-time · Remote - Portugal
- Physiotherapist Contractor · Remote - Portugal
- Deal Operations · Remote - Portugal; United States
- Senior QA Analyst · Remote - Portugal
- Social Media Senior Manager · Remote - Portugal; Remote - US
- Women’s Health Specialist - Certified Nurse Midwife credential · Remote - US
- Women’s Health Specialist - Nurse Practitioner credential · Remote - US