FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming
CDWSenior Threat Engineer building AI-powered detection and response for CDW, a technology solutions provider. Continuously red teaming defenses and AI systems against real-world attacks.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in threat detection engineering and incident response, with a strong focus on AI and machine learning applications in security. Proficient in building and tuning detections across various platforms, including SIEM and cloud-scale security tooling.
Highest-signal resume keywords
Threat Detection EngineeringPython AutomationMITRE ATT&CK FrameworkAdversary EmulationSecurity Automation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Threat Detection EngineeringIncident ResponseAdversary EmulationPython ProgrammingAI/ML ApplicationDetection-as-CodeSecurity AutomationSIEM TuningCloud Security ToolingBreach and Attack Simulation
Soft Skills
MentoringCollaborationDocumentation
Tools & Technologies
Microsoft DefenderMicrosoft SentinelCrowdStrikeSplunkTinesAtomic Red TeamCalderaCobalt Strike
Certifications & Qualifications
GCIHGCFAGCTIGPENOSCPAzure Security
Industry Keywords
Threat HuntingPurple TeamingIncident ResponseSecurity OrchestrationContinuous Automated Emulation
Tech Stack
Tools & technologiesAzureCloudPythonSplunk
About the role
Key responsibilities & impact- Engineer high-fidelity detections across identity, endpoint, network, cloud, and SaaS, pairing each with automated response paths
- Apply AI and machine learning to triage, correlate, and enrich alerts into incident narratives
- Build autonomous and semi-autonomous playbooks to isolate hosts, revoke sessions and tokens, disable credentials, block infrastructure, and quarantine content
- Implement confidence thresholds, blast-radius controls, human-in-the-loop escalation, and tested rollback paths
- Measure mean time to detect, mean time to contain, false-positive rate, and MITRE ATT&CK coverage
- Use LLMs and agentic tooling for investigation summaries, containment recommendations, indicator extraction, and human-reviewed detection logic generation
- Operate continuous automated adversary emulation against production controls
- Generate and mutate attack behavior across ATT&CK techniques using AI
- Convert emulation misses into detection backlog items and noisy hits into tuning tasks, then automatically re-test fixes
- Red team AI systems for evasion, prompt injection, data poisoning, and unsafe autonomous action
- Operate safe production emulation with scoped targets, rate limits, abort criteria, deconfliction, and audit trails
- Report living coverage metrics and prioritize the detection roadmap
- Track adversary tradecraft and translate intelligence into emulation plans, detections, and response actions
- Run hypothesis-driven hunts across SIEM, XDR, identity, and cloud telemetry
- Lead technical deep dives on incidents and emulation findings
- Develop Python integrations and tooling against platform APIs and event-driven architectures
- Build self-healing detection and response capabilities that identify and correct telemetry gaps, sensor degradation, and control drift
- Partner with Threat Response, Cyber Defense Engineering, security platform owners, and business unit owners
- Contribute to backlogs and design reviews, mentor engineers and analysts, and document detection and automation decisions
Requirements
What you’ll need- Bachelor’s degree and 7+ years of experience in threat detection engineering, threat hunting, incident response, or offensive security, or 11+ years of equivalent experience
- Hands-on experience building and tuning detections in SIEM platforms and cloud-scale security tooling
- Practical working knowledge of the MITRE ATT&CK framework
- Experience with adversary emulation, purple teaming, breach and attack simulation, or penetration testing against production controls
- Proficiency in Python for production-grade automation and tooling
- Experience applying AI/ML or LLM-based capabilities to security problems
- Experience designing secure, observable, and maintainable AI-enabled solutions
- Working experience with security automation, orchestration, or SOAR platforms
- Experience building detection and response capability for large, diverse enterprise environments is a plus
- Familiarity with Microsoft Defender, Microsoft Sentinel, CrowdStrike, Tines, Entra ID, and Splunk is a plus
- Familiarity with Atomic Red Team, Caldera, Cobalt Strike, or commercial breach and attack simulation platforms is a plus
- Detection-as-code practice, including CI/CD pipelines, infrastructure-as-code, policy-as-code, and automated testing, is a plus
- Experience securing or red teaming AI systems, including prompt injection, model evasion, and agent safety testing, is a plus
- Relevant certifications such as GCIH, GCFA, GCTI, GPEN, OSCP, Azure Security, or cloud and automation certifications are a plus
Benefits
Comp & perks- Annual bonus target 10% subject to terms and conditions of plan
- Benefits provided; details available at https://cdw.benefit-info.com/
- AI-fluent, curiosity-driven learning and experimentation culture
- Equitable, transparent, and respectful hiring process
- Support for professional growth and contributions in a collaborative environment