Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Team
Job Summary
Catch attackers in minutes, not days. Test our own defenses at attacker speed, continuously.
The Senior Threat Engineer is a hands‑on, high‑impact role within the Enterprise Defense & Automation (EDA) team. You will engineer AI‑powered detection and response capabilities that compress attacker dwell time from days to minutes, and you will continuously red team those same defenses at attacker speed so that gaps are found by us long before they are found by an adversary.
The role sits at the intersection of threat detection engineering, adversary emulation, and applied AI. On the defensive side you will build detections and AI‑assisted response paths that triage, decide, and act autonomously within policy, moving security operations from “alert and investigate” to detect, decide, and act. On the offensive side you will run continuous, automated adversary emulation against production controls, generating a constant stream of evidence about what our defenses actually stop.
This is a builder and problem‑solver role. You will write detection logic, adversary emulation content, and automated response playbooks; instrument them with measurable outcomes such as mean time to detect, mean time to contain, and detection coverage against MITRE ATT and use AI to raise signal fidelity rather than alert volume. Every detection you ship is expected to be tested by an emulation you also ship.
Success requires strong threat fundamentals, fluency across modern detection and response platforms, and the discipline to deliver production‑grade capability that holds up in real‑world, adversarial conditions. Guardrails matter as much as speed: confidence thresholds, blast‑radius limits, and rollback paths are part of the design, not an afterthought.
If you are energized by hunting real adversaries, teaching machines to respond faster than they can, and attacking your own work before anyone else gets the chance, this role puts you at the forefront of modern cyber defense.
What you will do
AI-Powered Detection & Response — catch attackers in minutes, not days (Primary)
- Engineer high‑fidelity detections across identity, endpoint, network, cloud, and SaaS, and pair each one with an automated response path so the outcome is containment, not another alert.
- Apply AI and machine learning to triage, correlate, and enrich alerts at machine speed — clustering related signals into a single incident narrative and surfacing the attacker story instead of a queue of fragments.
- Build autonomous and semi‑autonomous response playbooks that isolate hosts, revoke sessions and tokens, disable credentials, block infrastructure, and quarantine content within minutes of first signal.
- Implement the guardrails that make autonomy safe: confidence thresholds, blast‑radius controls, human‑in‑the‑loop escalation for high‑impact actions, and tested rollback for every automated action.
- Instrument detection and response for measurable outcomes — mean time to detect, mean time to contain, false‑positive rate, and ATT&CK coverage — and drive those numbers down release over release.
- Use LLMs and agentic tooling where they earn their place: summarizing investigations, drafting containment recommendations, extracting indicators from unstructured reporting, and generating detection logic that a human reviews before it ships.
Continuous AI Red Teaming — test our own defenses at attacker speed (Primary)
- Stand up and operate continuous, automated adversary emulation against production controls, so defensive coverage is proven by evidence on a recurring cadence rather than assumed between annual assessments.
- Use AI to generate and mutate attack behavior — varying tradecraft, tooling, and sequencing across ATT&CK techniques — so detections are tested against variants rather than a single static signature.
- Close the loop from emulation to engineering: every miss becomes a detection backlog item, every noisy hit becomes a tuning task, and every fix
Get remote jobs like this by email
One weekly digest. No spam, unsubscribe anytime.