Level

Tandem Health

Senior Security Operations Engineer

AI in this role

Lead security operations, detection engineering, and incident response for a healthcare platform, including evaluating security of AI workflows.

siem
security-operationsincident-responsethreat-detectiontelemetrycompliance
Build something monumental for Healthcare!

At Tandem Health we’re reimagining healthcare by putting clinicians first. Our platform - designed by clinicians, for clinicians - is built on deep insight into real-world pain points, with intuitive medical notes and workflows that truly support patient care.

We’re a fast-scaling health-tech company backed by top investors and expanding globally. We move fast, stay curious, and believe building something that matters starts with an extraordinary team. If you're passionate about impact and innovation, we'd love to meet you!

About the role

You will lead the engineering of our security operations programme in Stockholm. The role is hands-on and spans telemetry, detection engineering, incident response and the way we work with our managed detection and response (MDR) provider.

The work is varied. You might trace an identity alert across cloud logs or guide a containment decision during an incident. On another day, you might test whether an AI-assisted investigation workflow is safe enough to use.

You will have a real say in the tools we choose, the processes we build and the skills we add as the team grows. The decisions you make will shape how Tandem handles security incidents for years to come.

This is a senior individual contributor role today. You do not need to want a management role to grow here. If people management interests you later, we can explore that path as the team grows.

What you will do

  • Own a risk-prioritised plan for bringing data sources into our security information and event management (SIEM) platform.

  • Make telemetry dependable. Build checks that show when important data is missing, delayed or incomplete.

  • Develop a repeatable detection lifecycle that covers creation, testing, tuning, ownership and retirement.

  • Lead the technical response to security incidents. Establish scope, urgency and likely impact, then guide containment and remediation.

  • Make containment decisions with the Head of Security and relevant system owners. Take direct action when an approved playbook and delegated authority allow it.

  • Coordinate security incidents from detection to closure. Keep playbooks, decision records, escalation paths and after-action reviews useful and current.

  • Run practical security incident training and exercises. Help colleagues understand their roles and respond with confidence under pressure.

  • Give our medical device regulation compliance and legal teams the technical evidence they need to assess potential privacy incidents.

  • Build an effective operating model with our MDR provider and other security partners. Make ownership and hand-offs clear.

  • Measure what matters, including telemetry coverage, detection quality, response time, hand-off quality and completed follow-up actions.

  • Find practical uses for AI in security operations. Put clear data boundaries, evaluation, human approval, audit and fallback controls around those workflows.

  • Document the systems and decisions you build so future team members can contribute quickly.

What success looks like

In your first year, your work will allow us to scale out the clear and repeatable process of resolving security incidents from detection to closure. Important telemetry gaps and detection quality should be visible. MDR hand-offs should be seamless, and after-action reviews should lead to delivered improvements.

You will also lay the groundwork for the next phase of security operations at Tandem. The next phase needs clearer ownership, more internal capability and systems that a growing team can build on.

What you bring

  • Coordinate security incidents across technical and non-technical teams.

  • Judge when to gather more evidence, when to contain and when to escalate.

  • Work with telemetry from identity, endpoint, cloud, network and application systems.

  • Build and operate SIEM integrations, detections and telemetry health checks.

  • Use code or automation to remove repetitive work and make response more reliable.

  • Distinguish expected behavior, control failures and credible malicious activity.

  • Write clear playbooks, investigation notes and after-action reviews.

  • Explain technical risk to engineers, leaders and colleagues outside security.

  • Bring structure to an incomplete process without waiting for perfect conditions.

  • Work collaboratively and stay calm when the answer is not yet clear.

We are looking for someone who makes sound decisions with incomplete information and explains their reasoning. You should always improve the system after the immediate problem is over.

We care more about demonstrated capability than a particular degree, certification or toolset.

Bonus points

  • Experience working with a co-managed MDR or managed security service provider.

  • Detection engineering experience, including validation and tuning.

  • Experience with incident command, security exercises or internal training.

  • Experience in healthcare, another regulated environment or a high-growth technology company.

  • Experience managing detections, automation or integrations as version-controlled code.

  • Experience using AI or machine learning in security operations, including ways to assess output quality and failure modes.

On-call

Our MDR provider monitors and triages alerts around the clock. You will join a shared after-hours rotation for escalations that need company context or a containment decision. On call rotations include additional compensation.

Location

We work best when we spend time together. You will work primarily from our headquarters in central Stockholm.

How to apply

We review applications continuously. Please apply with your CV in English.

Because Tandem handles sensitive patient data, we conduct a background check before hiring.

Benefits

  • Competitive salary and company stock options.

  • Additional compensation for on-call rotations

  • 30 days of paid holiday each year.

  • 5,000 SEK wellness allowance, plus 6,000 SEK each year for other health-related initiatives.

  • Parental leave top-up for new parents.

  • Private medical insurance.

  • Mental health support through Mindler.

  • Pension programme.

  • Regular social and team activities, including off-sites and seasonal events.

We review our benefits regularly and may change them from time to time.

Culture at Tandem

At Tandem, we move fast, think big, and take ownership. We're a high-performing, diverse team with a shared drive to change the future of healthcare - and we’re just getting started.

Our culture is built on action, ambition, and learning. You'll be trusted to take the lead, challenge yourself, and make an impact from day one. We believe real growth happens when you're stretched, supported, and surrounded by smart, passionate teammates who want to win together.

Even though we’re spread across countries, we come together often in Sweden for team meetings, social events, and offsites - blending global reach with real human connection.

We hire for talent, potential, and attitude - valuing different backgrounds and fresh perspectives. Great ideas come from everywhere, and we’re building a team that reflects the world we want to change.

Tandem handles sensitive patient data and will conduct a background check before hiring any candidate.

How we rate this

Senior Security Operations Engineer at Tandem Health rates 20 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

Security OperationsIncident ResponseThreat DetectionTelemetryComplianceSiem

Questions you could be asked

  1. Tell me about a project where security operations was part of your work. What did you do?
  2. Tell me about a project where incident response was part of your work. What did you do?
  3. Tell me about a project where threat detection was part of your work. What did you do?
  4. Tell me about a project where telemetry was part of your work. What did you do?
  5. Tell me about a project where compliance was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: Security Operations, Incident Response, Threat Detection, Telemetry, and Compliance. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new AI jobs by email

One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Operations roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Tandem Health

Related searches

Same AI level