
Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in United States.
• Develop high-fidelity detections across identity, endpoint, network, cloud, and SaaS, integrating each with automated response mechanisms.
• Utilize AI and machine learning to triage, correlate, and enhance alerts into comprehensive incident narratives.
• Create autonomous and semi-autonomous playbooks to isolate hosts, revoke sessions and tokens, disable credentials, block infrastructure, and quarantine content.
• Establish confidence thresholds, blast-radius controls, human-in-the-loop escalation, and verified rollback procedures.
• Assess mean time to detect, mean time to contain, false-positive rates, and MITRE ATT&CK coverage.
• Employ LLMs and agentic tools for investigation summaries, containment recommendations, indicator extraction, and human-reviewed detection logic generation.
• Conduct continuous automated adversary emulation on production controls.
• Generate and adapt attack behaviors across ATT&CK techniques using AI.
• Transform emulation misses into detection backlog items and noisy hits into tuning tasks, followed by automatic re-testing of fixes.
• Test AI systems through red teaming for evasion, prompt injection, data poisoning, and unsafe autonomous actions.
• Execute safe production emulation with defined targets, rate limits, abort criteria, deconfliction, and audit trails.
• Report on living coverage metrics and prioritize the detection roadmap.
• Monitor adversary tradecraft and convert intelligence into emulation strategies, detections, and response actions.
• Conduct hypothesis-driven hunts across SIEM, XDR, identity, and cloud telemetry.
• Lead technical deep dives into incidents and emulation findings.
• Develop Python integrations and tools against platform APIs and event-driven architectures.
• Create self-healing detection and response capabilities that identify and rectify telemetry gaps, sensor degradation, and control drift.
• Collaborate with Threat Response, Cyber Defense Engineering, security platform owners, and business unit leaders.
• Contribute to backlogs and design reviews, mentor engineers and analysts, and document decisions related to detection and automation.
• Bachelor’s degree and 7+ years of experience in threat detection engineering, threat hunting, incident response, or offensive security, or 11+ years of equivalent experience.
• Practical experience in building and fine-tuning detections within SIEM platforms and cloud-scale security tools.
• In-depth working knowledge of the MITRE ATT&CK framework.
• Experience with adversary emulation, purple teaming, breach and attack simulation, or penetration testing against production controls.
• Proficient in Python for production-level automation and tooling.
• Experience applying AI/ML or LLM-based solutions to security challenges.
• Ability to design secure, observable, and maintainable AI-enabled solutions.
• Hands-on experience with security automation, orchestration, or SOAR platforms.
• Experience in developing detection and response capabilities for large, diverse enterprise environments is an advantage.
• Familiarity with Microsoft Defender, Microsoft Sentinel, CrowdStrike, Tines, Entra ID, and Splunk is beneficial.
• Knowledge of Atomic Red Team, Caldera, Cobalt Strike, or commercial breach and attack simulation platforms is a plus.
• Detection-as-code practices, including CI/CD pipelines, infrastructure-as-code, policy-as-code, and automated testing, are advantageous.
• Experience securing or red teaming AI systems, including prompt injection, model evasion, and agent safety testing, is beneficial.
• Relevant certifications such as GCIH, GCFA, GCTI, GPEN, OSCP, Azure Security, or other cloud and automation certifications are a plus.
• Annual bonus target of 10% subject to the terms and conditions of the plan.
• Benefits provided; more details are available at https://cdw.benefit-info.com/.
• A culture of AI-fluent, curiosity-driven learning and experimentation.
• An equitable, transparent, and respectful hiring process.
• Support for professional growth and contributions within a collaborative environment.
Vericast
Protective Life
Get handpicked remote jobs straight to your inbox weekly.