
Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming
CDW Corporation24 hours ago
Remote, United StatesSenior
Base Salary
$137k - $191k/yr
Responsibilities
- Engineer high-fidelity detections and automated response paths across identity, endpoint, network, cloud, and SaaS environments.
- Apply AI, machine learning, LLMs, and agentic tooling to alert triage, correlation, investigation summarization, indicator extraction, and response recommendations.
- Build autonomous and semi-autonomous playbooks for host isolation, session and token revocation, credential disabling, infrastructure blocking, and content quarantine.
- Implement confidence thresholds, blast-radius controls, human-in-the-loop escalation, rollback paths, rate limits, abort criteria, and audit trails for safe automation.
- Operate continuous automated adversary emulation against production controls and use AI to mutate attack behavior across MITRE ATT&CK techniques.
- Red team detection models, agents, and prompts for evasion, prompt injection, data poisoning, and unsafe autonomous actions.
- Run threat hunts across SIEM, XDR, identity, and cloud telemetry and translate findings into reusable detections and automated responses.
- Develop version-controlled, peer-reviewed, unit-tested detection content and Python integrations through security-gated delivery pipelines.
- Build self-healing detection and response capabilities that identify telemetry gaps, sensor degradation, and control drift and remediate or roll back issues.
- Lead technical deep dives, document detection and emulation practices, collaborate with security teams and platform owners, and mentor engineers and analysts.
Requirements
- Bachelor’s degree and 7+ years of experience in threat detection engineering, threat hunting, incident response, or offensive security, or 11+ years of equivalent experience.
- Hands-on experience building and tuning detections in SIEM platforms and cloud-scale security tooling.
- Practical knowledge of MITRE ATT&CK and experience mapping detections and automated responses to its techniques.
- Experience with adversary emulation, purple teaming, breach and attack simulation, or penetration testing against production controls.
- Proficiency in Python for production-grade automation and tooling.
- Experience applying AI/ML or LLM capabilities to security problems and designing secure, observable, maintainable AI-enabled solutions.
- Experience with security automation, orchestration, or SOAR platforms.
- Familiarity with Microsoft Defender, Microsoft Sentinel, CrowdStrike, Tines, Entra ID, and Splunk.
- Familiarity with Atomic Red Team, Caldera, Cobalt Strike, or commercial breach and attack simulation platforms.
- Detection-as-code experience including CI/CD pipelines, infrastructure-as-code, policy-as-code, and automated testing of detection content.
- Experience securing or red teaming AI systems, including prompt injection, model evasion, and agent safety testing.
- Relevant certifications such as GCIH, GCFA, GCTI, GPEN, OSCP, Azure Security, or cloud and automation certifications are a plus.
Benefits
- Benefits information is provided at https://cdw.benefit-info.com/.
- The salary range may vary based on geographic differentials.
- CDW describes a collaborative, equitable, transparent, and respectful work environment with support for employee growth and learning.