Principal Software Engineer, AI SIEM

SentinelOne · United States - Remote · Engineering

Posted 2026-07-28

Apply for this role →

As a Principal Software Engineer, AI SIEM, you will be tasked with reasoning across all three layers of SentinelOne's AI SIEM: how data moves and gets queried at scale, how analysts actually work with what the system surfaces, and how detections get built and tuned. Our AI SIEM ingests petabytes of data per day, powers the analyst workflows that turn that data into alerts, findings, assets, and incidents, and drives the detection engines, both rule-based and AI-driven, that catch what matters. You will look at the system as a whole, find where it's exceptional, where it has gaps, where it has redundant or overlapping effort, and drive the architectural decisions that close those gaps.

This is not a role scoped to one service or one team's backlog. It's for someone who can sit above the individual pillars, understand how they're supposed to fit together, and act when they don't.

What Will You Do?

Primary responsibilities include:

Build a working mental model of the full system, including ingest and storage, query and retrieval, analyst-facing workflows (alerts, findings, assets, incidents), and the detection engines (rule-based and beyond), and use it to identify where architecture is solid, where it's fragile, and where teams are unknowingly duplicating effort or leaving gaps between their boundaries.

Drive cross-team architectural decisions that affect multiple parts of the system at once, for example, how ingest-time enrichment should relate to detection logic, or how detection output should shape what an analyst sees and can act on.

Partner with the engineering leads of each pillar (data platform, analyst experience, detection engines) as a peer thought partner, not a top-down authority, influencing through technical credibility and clear reasoning, not mandate.

Identify and prioritize the highest-leverage architectural investments across the system, and make the case for them to engineering leadership and product.

Get hands-on where it matters: prototype, review, and occasionally build the connective tissue between pillars when no single team naturally owns it.

Establish and champion cross-cutting technical standards, for APIs, data contracts, and service boundaries, that keep independently-developed pillars interoperable as they evolve.

Mentor senior and staff engineers across teams, raising the bar for architectural thinking org-wide, not just within one team.

Represent the technical health of the overall system in planning and leadership conversations, translating "what's exceptional, what's a gap, what's redundant" into a roadmap.

What Skills and Knowledge Will You Bring?

Ideal candidates will have:

Deep experience (15 or more years) building and operating large-scale distributed backend systems, with direct experience in at least two of: high-throughput data ingest/storage, query engines, or detection/rules systems.

A demonstrated track record of reasoning about systems at the architecture level, not just implementing a spec, but identifying where a system's boundaries are wrong, where responsibilities overlap, and where they leave gaps.

Experience designing APIs and service contracts that need to hold up across teams and years, not just within one codebase.

Comfort operating without a single clear chain of command, influencing peer teams and senior engineers through the strength of your reasoning.

A four-year degree in Computer Science or equivalent practical experience.

Familiarity with security operations concepts (alerts, findings, assets, incidents, detection rules) is preferred; if you don't have direct SIEM/XDR background, you should be someone who can get fluent in a new domain fast.

Experience with modern cloud infrastructure and data-intensive systems (distributed storage, high-cardinality querying, streaming pipelines) is preferred; specific tools matter less than demonstrated judgment about tradeoffs at scale.

Exposure to both rule-based and ML/AI-driven detection approaches is a plus, but the more important trait is being able to reason about when each is the right tool.

Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

Equity & Rewards

Restricted Stock Units (RSUs)

Employee Stock Purchase Plan (ESPP)

Time Off & Wellbeing

Flexible time off

Paid company holidays and paid sick time

Gender-neutral parental leave

Grandparent leave

Insurance & Financial Security

Medical, dental, and vision coverage

401(k) retirement plan with company match

Life and disability insurance

Health and dependent care FSA

Voluntary benefits (hospital, accident, critical illness)

Employee Assistance Program (EAP)

ARAG pre-paid legal

Nationwide pet insurance

Cancer Care program

Global business travel medical insurance

Work Perks & Flexibility

Home office allowance

Mobile phone reimbursement

Wellness & Lifestyle

Wellness coach

Wellness/gym reimbursement

Fertility coverage

Adoption & surrogacy reimbursement

This U.S. role has a base pay range that will vary based on the location of the candidate. For some locations, a different pay range may apply.  If so, this range will be provided to you during the recruiting process. You can also reach out to the recruiter with any questions.

Base Salary Range

$216,000—$297,000 USD

Apply for this role →

← Back to all jobs