Tandem Health

Senior Security Operations Engineer

Tandem Health Stockholm, Stockholm County, Sweden

Hospitals and Health Care · 51-200 employees

19 h ago
Senior (5-10 yrs) Full-time Sweden
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will lead the engineering of the security operations program, including telemetry management, detection engineering, and incident response. You will also build an effective operating model with MDR providers and implement AI-driven security workflows.

What they look for

Security operations Telemetry Detection engineering Incident response SIEM Cloud security Automation Risk management Incident command Data analysis Security training Compliance AI-assisted investigation Identity security Endpoint security Network security

Requirements

The role requires experience in coordinating security incidents across technical teams and managing telemetry from cloud, identity, and endpoint systems. You must be capable of building SIEM integrations, writing clear playbooks, and making sound decisions under pressure.

Benefits

Competitive salary Company stock options On-call compensation 30 days paid holiday Wellness allowance Health-related initiatives allowance Parental leave top-up Private medical insurance Mental health support Pension programme

Full description

Build something monumental for Healthcare!

At Tandem Health we’re reimagining healthcare by putting clinicians first. Our platform - designed by clinicians, for clinicians - is built on deep insight into real-world pain points, with intuitive medical notes and workflows that truly support patient care.

We’re a fast-scaling health-tech company backed by top investors and expanding globally. We move fast, stay curious, and believe building something that matters starts with an extraordinary team. If you're passionate about impact and innovation, we'd love to meet you!

About the role

You will lead the engineering of our security operations programme in Stockholm. The role is hands-on and spans telemetry, detection engineering, incident response and the way we work with our managed detection and response (MDR) provider.

The work is varied. You might trace an identity alert across cloud logs or guide a containment decision during an incident. On another day, you might test whether an AI-assisted investigation workflow is safe enough to use.

You will have a real say in the tools we choose, the processes we build and the skills we add as the team grows. The decisions you make will shape how Tandem handles security incidents for years to come.

This is a senior individual contributor role today. You do not need to want a management role to grow here. If people management interests you later, we can explore that path as the team grows.

What you will do

  • Own a risk-prioritised plan for bringing data sources into our security information and event management (SIEM) platform.
  • Make telemetry dependable. Build checks that show when important data is missing, delayed or incomplete.
  • Develop a repeatable detection lifecycle that covers creation, testing, tuning, ownership and retirement.
  • Lead the technical response to security incidents. Establish scope, urgency and likely impact, then guide containment and remediation.
  • Make containment decisions with the Head of Security and relevant system owners. Take direct action when an approved playbook and delegated authority allow it.
  • Coordinate security incidents from detection to closure. Keep playbooks, decision records, escalation paths and after-action reviews useful and current.
  • Run practical security incident training and exercises. Help colleagues understand their roles and respond with confidence under pressure.
  • Give our medical device regulation compliance and legal teams the technical evidence they need to assess potential privacy incidents.
  • Build an effective operating model with our MDR provider and other security partners. Make ownership and hand-offs clear.
  • Measure what matters, including telemetry coverage, detection quality, response time, hand-off quality and completed follow-up actions.
  • Find practical uses for AI in security operations. Put clear data boundaries, evaluation, human approval, audit and fallback controls around those workflows.
  • Document the systems and decisions you build so future team members can contribute quickly.

What success looks like

In your first year, your work will allow us to scale out the clear and repeatable process of resolving security incidents from detection to closure. Important telemetry gaps and detection quality should be visible. MDR hand-offs should be seamless, and after-action reviews should lead to delivered improvements.

You will also lay the groundwork for the next phase of security operations at Tandem. The next phase needs clearer ownership, more internal capability and systems that a growing team can build on.

What you bring

  • Coordinate security incidents across technical and non-technical teams.
  • Judge when to gather more evidence, when to contain and when to escalate.
  • Work with telemetry from identity, endpoint, cloud, network and application systems.
  • Build and operate SIEM integrations, detections and telemetry health checks.
  • Use code or automation to remove repetitive work and make response more reliable.
  • Distinguish expected behavior, control failures and credible malicious activity.
  • Write clear playbooks, investigation notes and after-action reviews.
  • Explain technical risk to engineers, leaders and colleagues outside security.
  • Bring structure to an incomplete process without waiting for perfect conditions.
  • Work collaboratively and stay calm when the answer is not yet clear.

We are looking for someone who makes sound decisions with incomplete information and explains their reasoning. You should always improve the system after the immediate problem is over.

We care more about demonstrated capability than a particular degree, certification or toolset.

Bonus points

  • Experience working with a co-managed MDR or managed security service provider.
  • Detection engineering experience, including validation and tuning.
  • Experience with incident command, security exercises or internal training.
  • Experience in healthcare, another regulated environment or a high-growth technology company.
  • Experience managing detections, automation or integrations as version-controlled code.
  • Experience using AI or machine learning in security operations, including ways to assess output quality and failure modes.

On-call

Our MDR provider monitors and triages alerts around the clock. You will join a shared after-hours rotation for escalations that need company context or a containment decision. On call rotations include additional compensation.

Location

We work best when we spend time together. You will work primarily from our headquarters in central Stockholm.

How to apply

We review applications continuously. Please apply with your CV in English.

Because Tandem handles sensitive patient data, we conduct a background check before hiring.

Benefits

  • Competitive salary and company stock options.
  • Additional compensation for on-call rotations
  • 30 days of paid holiday each year.
  • 5,000 SEK wellness allowance, plus 6,000 SEK each year for other health-related initiatives.
  • Parental leave top-up for new parents.
  • Private medical insurance.
  • Mental health support through Mindler.
  • Pension programme.
  • Regular social and team activities, including off-sites and seasonal events.

We review our benefits regularly and may change them from time to time.

Culture at Tandem

At Tandem, we move fast, think big, and take ownership. We're a high-performing, diverse team with a shared drive to change the future of healthcare - and we’re just getting started.

Our culture is built on action, ambition, and learning. You'll be trusted to take the lead, challenge yourself, and make an impact from day one. We believe real growth happens when you're stretched, supported, and surrounded by smart, passionate teammates who want to win together.

Even though we’re spread across countries, we come together often in Sweden for team meetings, social events, and offsites - blending global reach with real human connection.

We hire for talent, potential, and attitude - valuing different backgrounds and fresh perspectives. Great ideas come from everywhere, and we’re building a team that reflects the world we want to change.

Tandem handles sensitive patient data and will conduct a background check before hiring any candidate.