Threat Detection Engineer
Listed on 2026-09-24
-
IT/Tech
Cybersecurity, Security Management & Operations
We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health®, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time.
PositionSummary
The Staff Threat Detection Engineer plays a key role in helping the organization stay ahead of evolving cyber threats. This position combines threat hunting, detection engineering, and offensive security expertise to identify suspicious activity, uncover emerging risks, and strengthen the organization's overall security posture. By leveraging security telemetry, threat intelligence, and adversary-focused analysis, this role helps ensure threats are identified and addressed before they can impact the business.
Working closely with Security Operations, Incident Response, and other cybersecurity teams, this role develops and improves detections, supports investigations, and helps validate security controls through purple team exercises and adversary emulation activities. The position also contributes to the adoption of new tools, techniques, and automation capabilities that improve visibility and response effectiveness. Success in this role requires curiosity, strong analytical skills, and a passion for continuously improving how the organization detects and defends against cyber threats.
RoleResponsibilities
Detection Engineering & Threat Hunting
- Develop, deploy, and optimize detection rules across SIEM platforms such as Microsoft Sentinel and Splunk
- Conduct threat hunting activities using Microsoft Defender, Crowd Strike, and other SOC tools to identify and respond to advanced threats.
- Leverage KQL and SPL (Search Processing Language) to create custom detections and automate responses.
- Continuously refine detection capabilities based on emerging threats and intelligence.
Penetration Testing & Adversary Emulation
- Assist with internal and external penetration tests to identify vulnerabilities.
- Design and execute adversary emulation scenarios to assess detection and response effectiveness.
- Utilize penetration testing tools and custom scripts to simulate real-world attack scenarios.
- Produce detailed reports with findings and actionable recommendations.
Purple Team Operations
- Work closely with blue teams to conduct purple team exercises, bridging offensive and defensive security efforts.
- Provide actionable insights to improve monitoring, alerting, and incident response based on adversary tactics.
- Facilitate knowledge-sharing sessions to upskill internal teams on TTPs (Tactics, Techniques, and Procedures).
Threat Intelligence Integration
- Integrate threat intelligence into detection strategies to prioritize threats and adapt detection rules.
- Analyze threat intelligence feeds and translate them into actionable detection and response measures.
Incident Response Support
- Collaborate with the incident response team during investigations by providing adversary tactics insights.
- Assist in developing threat-hunting use cases and refining detection capabilities.
Security Strategy & Risk Management
- Contribute to the development of a comprehensive detection strategy aligned with risk management goals.
- Provide leadership with reports on security gaps, risks, and detection effectiveness.
- 7+ years of experience in threat detection, hunting, penetration testing, and/or offensive security.
- 5+ years of experience in Microsoft Security tools (Defender for Endpoint, Sentinel), Crowd Strike, and Splunk.
- 3+ years of experience with KQL, SPL, Python, Power Shell,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).