1 day ago
Base Salary
$168k - $311k/yr
Responsibilities
- Build and tune high-confidence detections using Splunk, Microsoft Sentinel, Microsoft Defender, CrowdStrike, cloud-native logs, identity telemetry, endpoint data, SaaS platforms, and developer systems.
- Translate incidents, threat hunts, threat intelligence, red-team findings, and vulnerability context into tested detection logic.
- Investigate telemetry, including field behavior, timing, joins, baselines, missing data, and false positives, before deploying alerts.
- Own the detection lifecycle from design and query development through validation, peer review, documentation, deployment, tuning, monitoring, and retirement.
- Strengthen detection-as-code workflows with test data, quality checks, metadata, rollout safety, coverage tracking, and detection health reporting.
- Partner with responders to reduce noise, add context, improve severity decisions, and create follow-up detections.
- Shape logging, normalization, enrichment, and retention requirements when needed telemetry is unavailable or difficult to use.
- Coach analysts and engineers through detection design reviews, query reviews, and guidance on credible detections.
Requirements
- At least 8 years of experience in detection engineering, security engineering, threat hunting, incident response, SOC engineering, or information security monitoring.
- A degree in Computer Science, Cybersecurity, or Engineering, or equivalent experience.
- Hands-on experience building and tuning detections in a major SIEM or security analytics platform.
- Strong query and scripting skills, especially SPL, KQL, SQL, Python, or similar languages used for security telemetry analysis and automation.
- Practical understanding of attacker behavior across identity, endpoint, cloud, network, email, collaboration tools, developer infrastructure, secrets, and data theft.
- Ability to turn raw logs into production-ready detections, including field semantics, thresholds, joins, baselines, false positives, missing data, and triage context.
- Comfort with Git, code review, automated checks, documentation, and operational ownership of shipped content.
- Clear communication and sound judgment when explaining detection value, limitations, next steps, and when not to alert.
- Preferred experience leading or materially improving detection-as-code programs across multiple security platforms.
- Preferred background in cloud, identity, Kubernetes, CI/CD, supply-chain, or AI-tooling attack paths.
- Preferred experience detecting abuse in developer systems, package ecosystems, secrets workflows, AI coding tools, agents, or model-serving infrastructure.
- Preferred collaboration with incident response, threat hunting, red team, purple team, malware analysis, or forensics teams.
- Preferred experience building replay tests, synthetic telemetry, attack emulation, detection unit tests, or coverage reporting.
Benefits
- Eligible for equity and benefits.
- Base salary varies by location, experience, and comparable employee pay; the listed ranges are $168,000–$270,250 for Level 4 and $196,000–$310,500 for Level 5.
- Applications are accepted at least until September 13, 2026.
Tech Stack
Categories
About Nvidia
Nvidia designs and sells GPUs and accelerated computing platforms for data centers, AI/ML, graphics, gaming, and automotive, monetizing through hardware, software platforms (CUDA, AI frameworks), and systems like DGX and networking. Customers include cloud providers, enterprises, researchers, and OEMs. Founded in 1993 and headquartered in Santa Clara, it is a public company traded on NASDAQ under NVDA.
