Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming

CDW

United States

Remote

USD 137,000 - 191,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

CDW is seeking a Senior Threat Engineer to build AI-powered detection and autonomous response capabilities across identity, endpoint, network, and cloud. You will run automated adversary emulation against production controls and translate findings into measurable improvements in detection and containment.

You will also lead threat hunting, research, and risk reduction through detection-as-code, CI/CD, and collaboration with security teams. Strong Python, MITRE ATT&CK expertise welcomed.

Qualifications

  • Bachelor’s degree and 7+ years of experience in threat detection engineering, threat hunting, incident response, or offensive security, or 11+ years of equivalent experience.
  • Hands-on experience building and tuning detections in SIEM platforms and cloud-scale security tooling.
  • Knowledge of MITRE ATT&CK framework and mapping detections to techniques.
  • Experience with adversary emulation, purple teaming, breach and attack simulation, or penetration testing against production controls.
  • Proficiency in Python for production-grade automation and tooling.
  • Experience applying AI/ML or LLM-based capabilities to security problems and designing secure AI-enabled solutions.
  • Working experience with security automation, orchestration, or SOAR platforms.
  • Desirable: large, diverse enterprise environment detection/response capability.
  • Familiarity with Defender, Sentinel, CrowdStrike, Tines, Entra ID, Splunk.
  • Familiarity with emulation tools like Atomic Red Team, Caldera, Cobalt Strike, or similar.
  • Detection-as-code practices: CI/CD, IaC, policy-as-code, automated testing.
  • Experience securing or red teaming AI systems (prompt injection, model evasion, agent safety).
  • Certifications such as GCIH, GCFA, GCTI, GPEN, OSCP, Azure Security are a plus.

Responsibilities

  • Engineer high-fidelity detections across identity, endpoint, network, cloud, and SaaS with automated response paths.
  • Apply AI to triage, correlate, and enrich alerts, surfacing attacker narratives rather than fragmented data.
  • Build autonomous response playbooks for containment and controlled actions.
  • Run continuous automated adversary emulation against production controls and iterate on detections from emulation results.
  • Track adversary tradecraft and translate findings into detections and response actions.
  • Treat detection content as code: versioned, peer‑reviewed, and CI/CD promoted.
  • Collaborate with Threat Response, security platform owners, and business units for clear ownership.

Skills

Threat detection engineering
Threat hunting
Incident response
Offensive security
Python
AI/ML security
Security automation
Adversary emulation
MITRE ATT&CK
Penetration testing
Cloud security tooling
CI/CD for detection
Emulation tooling
Certifications (GCIH/GCFA/GCTI/GPEN/OS

Education

Bachelor’s degree

Tools

Microsoft Defender
Microsoft Sentinel
CrowdStrike
Tines
Entra ID
Splunk
Atomic Red Team
Caldera
Cobalt Strike
CI/CD tooling

Job description

Job Summary

Catch attackers in minutes, not days. Test our own defenses at attacker speed, continuously. The Senior Threat Engineer is a hands‑on, high‑impact role within the Enterprise Defense & Automation (EDA) team. You will engineer AI‑powered detection and response capabilities that compress attacker dwell time from days to minutes, and you will continuously red team those same defenses at attacker speed so that gaps are found by us long before they are found by an adversary. The role sits at the intersection of threat detection engineering, adversary emulation, and applied AI. On the defensive side you will build detections and AI‑assisted response paths that triage, decide, and act autonomously within policy, moving security operations from “alert and investigate” to detect, decide, and act. On the offensive side you will run continuous, automated adversary emulation against production controls, generating a constant stream of evidence about what our defenses actually stop. This is a builder and problem‑solver role. You will write detection logic, adversary emulation content, and automated response playbooks; instrument them with measurable outcomes such as mean time to detect, mean time to contain, and detection coverage against MITRE ATT&CK; and use AI to raise signal fidelity rather than alert volume. Every detection you ship is expected to be tested by an emulation you also ship. Success requires strong threat fundamentals, fluency across modern detection and response platforms, and the discipline to deliver production‑grade capability that holds up in real‑world, adversarial conditions. Guardrails matter as much as speed: confidence thresholds, blast‑radius limits, and rollback paths are part of the design, not an afterthought. If you are energized by hunting real adversaries, teaching machines to respond faster than they can, and attacking your own work before anyone else gets the chance, this role puts you at the forefront of modern cyber defense.

What you will do
AI-Powered Detection & Response — catch attackers in minutes, not days (Primary)

Engineer high‑fidelity detections across identity, endpoint, network, cloud, and SaaS, and pair each one with an automated response path so the outcome is containment, not another alert. Apply AI and machine learning to triage, correlate, and enrich alerts at machine speed — clustering related signals into a single incident narrative and surfacing the attacker story instead of a queue of fragments. Build autonomous and semi‑autonomous response playbooks that isolate hosts, revoke sessions and tokens, disable credentials, block infrastructure, and quarantine content within minutes of first signal. Implement the guardrails that make autonomy safe: confidence thresholds, blast‑radius controls, human‑in‑the‑loop escalation for high‑impact actions, and tested rollback for every automated action. Instrument detection and response for measurable outcomes — mean time to detect, mean time to contain, false‑positive rate, and ATT&CK coverage — and drive those numbers down release over release. Use LLMs and agentic tooling where they earn their place: summarizing investigations, drafting containment recommendations, extracting indicators from unstructured reporting, and generating detection logic that a human reviews before it ships.

Continuous AI Red Teaming — test our own defenses at attacker speed (Primary)

Stand up and operate continuous, automated adversary emulation against production controls, so defensive coverage is proven by evidence on a recurring cadence rather than assumed between annual assessments. Use AI to generate and mutate attack behavior — varying tradecraft, tooling, and sequencing across ATT&CK techniques — so detections are tested against variants rather than a single static signature. Close the loop from emulation to engineering: every miss becomes a detection backlog item, every noisy hit becomes a tuning task, and every fix is re‑tested automatically. Red team our AI itself — test detection models, agents, and prompts for evasion, prompt injection, data poisoning, and unsafe autonomous action, and remediate what you find. Operate emulation safely in production: scoped targets, rate limits, clear abort criteria, deconfliction with the response team, and full audit trails for every executed technique. Report coverage as a living metric — which techniques are prevented, which are detected, which are only logged, and which are invisible — and use it to prioritize the detection roadmap.

Threat Research & Hunting

Track adversary tradecraft relevant to CDW and our customers, and translate intelligence into emulation plans, detections, and response actions rather than reading material. Run hypothesis‑driven threat hunts across SIEM, XDR, identity, and cloud telemetry, and convert every confirmed hunt technique into an automated detection so the same hunt never has to be run by hand twice. Map techniques to controls and automated responses once, then reuse the mapping globally across the estate. Lead technical deep dives on significant incidents and emulation findings, and feed the lessons back into detection content, response playbooks, and platform hardening.

Detection Engineering as Code

Treat detection content as software: version controlled, peer reviewed, unit tested against emulation data and promoted through CI/CD with security gates that block low‑quality logic before it reaches production. Develop integrations and tooling in Python against platform APIs and event‑driven architectures, favoring reusable services over one‑off scripts. Build detection and response capability that self‑heals — identifying telemetry gaps, sensor degradation, and control drift, then correcting them or rolling back to a known‑good state without waiting for a human. Eliminate repeat findings through native auto‑remediation patterns rather than recurring manual cleanup.

Collaboration & Influence

Partner closely with the Threat Response team, Cyber Defense Engineering, security platform owners, and business unit owners so that detections, emulations, and automated actions land with clear ownership boundaries. Contribute to shared backlogs and design reviews, and mentor engineers and analysts on detection quality, adversary tradecraft, and the safe use of AI in the defensive stack. Document detection logic, emulation plans, automation patterns, and engineering decisions so the capability survives any single person.

What we expect of you
  • Bachelor’s degree and 7+ years of experience in threat detection engineering, threat hunting, incident response, or offensive security, or 11+ years of equivalent experience.
  • Hands‑on experience building and tuning detections in SIEM platforms and cloud‑scale security tooling.
  • Practical working knowledge of the MITRE ATT&CK framework, including mapping detections and automated responses to techniques.
  • Experience with adversary emulation, purple teaming, breach and attack simulation, or penetration testing against production controls.
  • Proficiency in Python for production‑grade automation and tooling.
  • Experience applying AI/ML or LLM‑based capabilities to security problems, and designing secure, observable, and maintainable AI‑enabled solutions.
  • Working experience with security automation, orchestration, or SOAR platforms.
  • Built detection and response capability for large, diverse enterprise environments, a plus.
  • Familiarity with platforms such as Microsoft Defender, Microsoft Sentinel, CrowdStrike, Tines, Entra ID, and Splunk, a plus.
  • Familiarity with emulation and offensive tooling such as Atomic Red Team, Caldera, Cobalt Strike, or commercial breach and attack simulation platforms, a plus.
  • Detection‑as‑code practice: CI/CD pipelines, infrastructure‑as‑code, policy‑as‑code, and automated testing of detection content, a plus.
  • Experience securing or red teaming AI systems, including prompt injection, model evasion, and agent safety testing, a plus.
  • Relevant certifications (GCIH, GCFA, GCTI, GPEN, OSCP, Azure Security, or cloud and automation certifications), a plus.
Pay range

Pay range: $137,000 – 190,600 depending on experience and skill set. Annual bonus target 10% subject to terms and conditions of plan.

Benefits overview

Benefits overview: https://cdw.benefit-info.com/ Salary ranges may be subject to geographic differentials.

CDW is committed to being an AI‑fluent organization

CDW is an equal opportunity employer

CDW is an equal opportunity employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status or any other basis prohibited by state and local law. At CDW, we make technology work so people can do great things.

We’re looking for people who bring curiosity, a learner’s mindset, and a willingness to engage with ever‑evolving technology and tools.

We’re looking for people who bring curiosity, a learner’s mindset, and a willingness to engage with ever‑evolving technology and tools. We value adopting AI as a partner, openness to experimentation, and a shared interest in learning together on AI. Our goal is to create a culture where AI enhances—not replaces—human creativity and decision‑making. You don’t need to be an expert today; what matters is your readiness to explore, adapt, and grow with us as we integrate AI responsibly and effectively into our work. Additionally, CDW is committed to fostering an equitable, transparent, and respectful hiring process for all applicants. During our application process, our goal is to understand your experience, strengths, skills, and qualifications. As an AI forward company, we see AI not just as a tool, but as a catalyst for new ways of thinking, creating, and communicating. We encourage candidates to embrace an AI mindset, one that’s curious, adaptive, and ready to explore what’s possible. We welcome thoughtful use of AI to expand your perspective and elevate how you share your story, while ensuring your application remains rooted in your own background, judgment, and voice.

About Us

CDW is a Fortune 500 technology solutions provider that helps businesses, government, education, and healthcare organizations achieve what’s possible through technology. What makes CDW different isn’t just what we do—it’s how we do it. At CDW we act as one—building trust, speaking candidly, and working together to achieve more. We play to win—focusing on what matters most and delivering for our customers. And we think forward—staying curious, moving fast, and continuously learning. We believe meaningful work happens when people feel supported, heard, and empowered to contribute. That’s why we think of ourselves as coworkers, not just employees—working together to solve complex challenges and deliver real impact for our customers and communities. As a full‑stack, full‑lifecycle technology partner, CDW brings deep expertise, strong relationships, and broad industry knowledge to help turn ideas into outcomes. When you join CDW, you become part of a collaborative environment where your work matters, your growth is supported, and your contributions help shape what’s next. Together, we deliver the full promise of what technology can do. Together, we Make Amazing Happen. CDW is an equal opportunity employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status or any other basis prohibited by state and local law. At CDW, we make technology work so people can do great things.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming
Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming

CO1000 CDW, LLC • Illinois

Hybrid
USD 137,000 - 191,000
Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Team
Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Team

United States Digital Space LLC • United States

Remote
USD 137,000 - 191,000
Senior Network Engineer - TS/SCI Clearance
Senior Network Engineer - TS/SCI Clearance

CDW group • Town of Florida (NY)

On-site
USD 160,000 - 220,000
Presales Manager - Security
Presales Manager - Security

CO1001 CDW Direct, LLC • United States

On-site
USD 132,000 - 186,000
Benefits overview
Senior Manager, AI Enablement
Senior Manager, AI Enablement

CO1000 CDW, LLC • Chicago (IL)

On-site
USD 143,000 - 200,000
Presales Manager - Security
Presales Manager - Security

CDW • Town of Texas (WI)

On-site
USD 132,000 - 186,000
Annual bonus 25%
Benefits overview
Senior Manager, AI Enablement
Senior Manager, AI Enablement

CDW group • Chicago (IL)

On-site
USD 143,000 - 200,000
Principal Strategist - Healthcare
Principal Strategist - Healthcare

CO1002 CDW Government, LLC • Illinois

Hybrid
USD 158,000 - 214,000
Senior Manager, AI Enablement
Senior Manager, AI Enablement

CDW • Vernon Hills (IL)

On-site
USD 143,000 - 200,000
Senior Manager, AI Enablement
Senior Manager, AI Enablement

CDW group • Vernon Hills (IL)

On-site
USD 143,000 - 200,000
Annual bonus 15%
Benefits overview