More jobs:
Senior Threat Detection Engineer
Job in
Bellevue, King County, Washington, 98009, USA
Listed on 2026-07-09
Listing for:
Salesforce
Full Time
position Listed on 2026-07-09
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Senior Threat Detection Engineer Overview
As a Senior Threat Detection Engineer, you will take on complete ownership of a technical area, responsible for delivering all necessary research and features to achieve our team’s goals in that area. You will work across teams in multiple geographies to deliver on initiatives with many moving parts. You will also have the opportunity to lead broad initiatives that go beyond our own work.
We value innovation and expect everyone to innovate and come up with creative ways to solve the problems that we and our customers face.
- The Threat Detection team is responsible for detecting attacks against Salesforce’s infrastructure, products, employees, and customers.
- The team collaborates with CSIRT and engineering teams to enhance detection effectiveness.
- The role involves writing logic on security platforms to detect malicious activity, building attack simulation scenarios, and testing logic effectiveness.
- Collaboration with the incident response team is essential to improve alert reliability and quality.
- As a Senior Threat Detection Engineer, you will be responsible to lead a project end to end owning a technical area, and delivering research and features.
- In this role you will be working security organization wide initiatives and cross-team collaboration are expected working with multiple engineering teams is required.
- 6 to 8 years of experience in relevant areas like in Threat Detection, Threat Hunting, Security Incident Response, and managing significant security incidents and breaches.
- Experience and expertise in developing and refining threat detection methodologies is a prerequisite. This proficiency in leveraging security logs from multiple log source types which includes network infrastructure, endpoint devices, public and private cloud substrates and SaaS A comprehensive grasp of log structure, data normalization techniques, and the capacity to isolate critical security incidents is imperative.
- Strong proficiency and experience in log correlation techniques to identify patterns and anomalies indicative of malicious activity. Demonstrate expertise in constructing complex search queries using languages such as SPL, YARAL and other query languages to analyze large volumes of data. Possess strong data analysis skills to interpret query results, identify false positives, and fine‑tune detection rules for optimal efficacy.
- Demonstrate in-depth knowledge of fundamental security principles, common attack vectors employed by threat actors, Tactics, Techniques, and Procedures (TTPs) used throughout the cyber kill chain, and relevant security frameworks such as the MITRE ATT&CK framework. This understanding is crucial for developing context‑aware and effective detection strategies.
- Possess practical experience in working with a variety of security tools and technologies, including Security Information and Event Management (SIEM) systems for centralized log analysis and alerting, Endpoint Detection and Response (EDR) solutions for endpoint visibility and threat mitigation, Network Detection and Response (NDR) tools for network traffic analysis and anomaly detection, and Security Orchestration, Automation and Response (SOAR) platforms for automating incident response workflows.
- Demonstrate the ability to effectively handle and analyze large and complex datasets, identifying meaningful security insights and trends from vast amounts of information. This includes understanding data processing pipelines, performance considerations when querying large datasets, and the ability to synthesize findings into actionable intelligence.
- Knowledge of writing detections based on network, host, OS, and other logs.
- Experience with correlation and complex log analytic queries.
- Coding experience with Python or other languages for automation.
- Ability to correlate multiple log sources for effective adversary detection.
- Demonstrated experience collaborating across global, cross-functional teams with members in multiple time zones, with the ability to communicate and coordinate effectively across geographically distributed environments.
- A…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×