SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tandem Health is a fast-scaling healthtech company reimagining healthcare by building intuitive medical notes and workflows designed by clinicians, for clinicians. You will lead the engineering of the security operations programme in Stockholm as a senior individual contributor.
This is a hands-on role spanning telemetry, detection engineering, incident response, and coordination with the managed detection and response (MDR) provider. You will own a risk-prioritized plan for bringing data sources into the SIEM platform, making telemetry dependable through checks that surface missing, delayed, or incomplete data. You will develop a repeatable detection lifecycle covering creation, testing, tuning, ownership, and retirement.
You will lead technical response to security incidents—establishing scope, urgency, and likely impact, then guiding containment and remediation. You will make containment decisions with the Head of Security and relevant system owners, taking direct action when approved playbooks and delegated authority allow it. You will coordinate incidents from detection to closure, keeping playbooks, decision records, escalation paths, and after-action reviews current and useful.
Additional responsibilities include running practical security incident training and exercises, providing technical evidence to medical device regulation compliance and legal teams for privacy incident assessment, building an effective operating model with MDR partners, measuring telemetry coverage and detection quality, exploring practical AI applications in security operations with appropriate controls, and documenting systems and decisions for team scalability.
Success in your first year means scaling a clear, repeatable incident resolution process from detection to closure, making telemetry gaps and detection quality visible, ensuring seamless MDR hand-offs, and delivering improvements from after-action reviews. You will lay groundwork for the next phase of security operations with clearer ownership, more internal capability, and systems a growing team can build on.
You should coordinate security incidents across technical and non-technical teams, judge when to gather evidence versus contain versus escalate, work with telemetry from identity, endpoint, cloud, network, and application systems, build and operate SIEM integrations and detections, use code or automation to reduce repetitive work, distinguish expected behavior from control failures and malicious activity, write clear playbooks and investigation notes, explain technical risk to non-security stakeholders, and bring structure to incomplete processes. You make sound decisions with incomplete information and continuously improve systems after resolving immediate problems.
The role includes shared after-hours on-call rotation for escalations requiring company context or containment decisions, with additional compensation provided. You will work primarily from Tandem's headquarters in central Stockholm.