Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
CDW

Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming

CDW

Senior Threat Engineer building AI-powered detection and response for CDW, a technology solutions provider. Continuously red teaming defenses and AI systems against real-world attacks.

Posted 9/8/2026full-timeRemote • 🇺🇸 United StatesSenior💰 $137,000 - $190,600 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in threat detection engineering and incident response, with a strong focus on AI and machine learning applications in security. Proficient in building and tuning detections across various platforms, including SIEM and cloud-scale security tooling.

Highest-signal resume keywords
Threat Detection EngineeringPython AutomationMITRE ATT&CK FrameworkAdversary EmulationSecurity Automation

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Threat Detection EngineeringIncident ResponseAdversary EmulationPython ProgrammingAI/ML ApplicationDetection-as-CodeSecurity AutomationSIEM TuningCloud Security ToolingBreach and Attack Simulation
Soft Skills
MentoringCollaborationDocumentation
Tools & Technologies
Microsoft DefenderMicrosoft SentinelCrowdStrikeSplunkTinesAtomic Red TeamCalderaCobalt Strike
Certifications & Qualifications
GCIHGCFAGCTIGPENOSCPAzure Security
Industry Keywords
Threat HuntingPurple TeamingIncident ResponseSecurity OrchestrationContinuous Automated Emulation

Tech Stack

Tools & technologies
AzureCloudPythonSplunk

About the role

Key responsibilities & impact
  • Engineer high-fidelity detections across identity, endpoint, network, cloud, and SaaS, pairing each with automated response paths
  • Apply AI and machine learning to triage, correlate, and enrich alerts into incident narratives
  • Build autonomous and semi-autonomous playbooks to isolate hosts, revoke sessions and tokens, disable credentials, block infrastructure, and quarantine content
  • Implement confidence thresholds, blast-radius controls, human-in-the-loop escalation, and tested rollback paths
  • Measure mean time to detect, mean time to contain, false-positive rate, and MITRE ATT&CK coverage
  • Use LLMs and agentic tooling for investigation summaries, containment recommendations, indicator extraction, and human-reviewed detection logic generation
  • Operate continuous automated adversary emulation against production controls
  • Generate and mutate attack behavior across ATT&CK techniques using AI
  • Convert emulation misses into detection backlog items and noisy hits into tuning tasks, then automatically re-test fixes
  • Red team AI systems for evasion, prompt injection, data poisoning, and unsafe autonomous action
  • Operate safe production emulation with scoped targets, rate limits, abort criteria, deconfliction, and audit trails
  • Report living coverage metrics and prioritize the detection roadmap
  • Track adversary tradecraft and translate intelligence into emulation plans, detections, and response actions
  • Run hypothesis-driven hunts across SIEM, XDR, identity, and cloud telemetry
  • Lead technical deep dives on incidents and emulation findings
  • Develop Python integrations and tooling against platform APIs and event-driven architectures
  • Build self-healing detection and response capabilities that identify and correct telemetry gaps, sensor degradation, and control drift
  • Partner with Threat Response, Cyber Defense Engineering, security platform owners, and business unit owners
  • Contribute to backlogs and design reviews, mentor engineers and analysts, and document detection and automation decisions

Requirements

What you’ll need
  • Bachelor’s degree and 7+ years of experience in threat detection engineering, threat hunting, incident response, or offensive security, or 11+ years of equivalent experience
  • Hands-on experience building and tuning detections in SIEM platforms and cloud-scale security tooling
  • Practical working knowledge of the MITRE ATT&CK framework
  • Experience with adversary emulation, purple teaming, breach and attack simulation, or penetration testing against production controls
  • Proficiency in Python for production-grade automation and tooling
  • Experience applying AI/ML or LLM-based capabilities to security problems
  • Experience designing secure, observable, and maintainable AI-enabled solutions
  • Working experience with security automation, orchestration, or SOAR platforms
  • Experience building detection and response capability for large, diverse enterprise environments is a plus
  • Familiarity with Microsoft Defender, Microsoft Sentinel, CrowdStrike, Tines, Entra ID, and Splunk is a plus
  • Familiarity with Atomic Red Team, Caldera, Cobalt Strike, or commercial breach and attack simulation platforms is a plus
  • Detection-as-code practice, including CI/CD pipelines, infrastructure-as-code, policy-as-code, and automated testing, is a plus
  • Experience securing or red teaming AI systems, including prompt injection, model evasion, and agent safety testing, is a plus
  • Relevant certifications such as GCIH, GCFA, GCTI, GPEN, OSCP, Azure Security, or cloud and automation certifications are a plus

Benefits

Comp & perks
  • Annual bonus target 10% subject to terms and conditions of plan
  • Benefits provided; details available at https://cdw.benefit-info.com/
  • AI-fluent, curiosity-driven learning and experimentation culture
  • Equitable, transparent, and respectful hiring process
  • Support for professional growth and contributions in a collaborative environment