CDW Corporation

Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming

CDW Corporation
Apply
24 hours ago
Remote, United StatesSenior

Base Salary

$137k - $191k/yr

Responsibilities

  • Engineer high-fidelity detections and automated response paths across identity, endpoint, network, cloud, and SaaS environments.
  • Apply AI, machine learning, LLMs, and agentic tooling to alert triage, correlation, investigation summarization, indicator extraction, and response recommendations.
  • Build autonomous and semi-autonomous playbooks for host isolation, session and token revocation, credential disabling, infrastructure blocking, and content quarantine.
  • Implement confidence thresholds, blast-radius controls, human-in-the-loop escalation, rollback paths, rate limits, abort criteria, and audit trails for safe automation.
  • Operate continuous automated adversary emulation against production controls and use AI to mutate attack behavior across MITRE ATT&CK techniques.
  • Red team detection models, agents, and prompts for evasion, prompt injection, data poisoning, and unsafe autonomous actions.
  • Run threat hunts across SIEM, XDR, identity, and cloud telemetry and translate findings into reusable detections and automated responses.
  • Develop version-controlled, peer-reviewed, unit-tested detection content and Python integrations through security-gated delivery pipelines.
  • Build self-healing detection and response capabilities that identify telemetry gaps, sensor degradation, and control drift and remediate or roll back issues.
  • Lead technical deep dives, document detection and emulation practices, collaborate with security teams and platform owners, and mentor engineers and analysts.

Requirements

  • Bachelor’s degree and 7+ years of experience in threat detection engineering, threat hunting, incident response, or offensive security, or 11+ years of equivalent experience.
  • Hands-on experience building and tuning detections in SIEM platforms and cloud-scale security tooling.
  • Practical knowledge of MITRE ATT&CK and experience mapping detections and automated responses to its techniques.
  • Experience with adversary emulation, purple teaming, breach and attack simulation, or penetration testing against production controls.
  • Proficiency in Python for production-grade automation and tooling.
  • Experience applying AI/ML or LLM capabilities to security problems and designing secure, observable, maintainable AI-enabled solutions.
  • Experience with security automation, orchestration, or SOAR platforms.
  • Familiarity with Microsoft Defender, Microsoft Sentinel, CrowdStrike, Tines, Entra ID, and Splunk.
  • Familiarity with Atomic Red Team, Caldera, Cobalt Strike, or commercial breach and attack simulation platforms.
  • Detection-as-code experience including CI/CD pipelines, infrastructure-as-code, policy-as-code, and automated testing of detection content.
  • Experience securing or red teaming AI systems, including prompt injection, model evasion, and agent safety testing.
  • Relevant certifications such as GCIH, GCFA, GCTI, GPEN, OSCP, Azure Security, or cloud and automation certifications are a plus.

Benefits

  • Benefits information is provided at https://cdw.benefit-info.com/.
  • The salary range may vary based on geographic differentials.
  • CDW describes a collaborative, equitable, transparent, and respectful work environment with support for employee growth and learning.

Tech Stack

PythonSplunk

Categories

CDW Corporation

About CDW Corporation

10,000+ employees
Contact me