Senior Threat Engineer - AI-Powered Detection, Response & Continuous AI Red Teaming

CDW

United States

On-site

USD 140,000 - 210,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

CDW is seeking a Senior Threat Engineer to design AI-powered detection and autonomous response capabilities. You will compress attacker dwell time with high‑fidelity detections across identity, endpoints, cloud, and SaaS, paired with automated containment actions.

You will lead continuous AI red teaming, emulation against production controls, and translate intelligence into detections and responses while using AI to improve signal fidelity and reduce alert volume.

Qualifications

  • Strong threat fundamentals and modern detection/response platform knowledge.
  • Experience building detections and automated responses across identity, endpoint, network, cloud, and SaaS.
  • Hands-on adversary emulation and red-teaming at attacker speed.

Responsibilities

  • Engineer high‑fidelity detections with automated response paths for containment.
  • Apply AI/ML to triage, correlate, and enrich alerts at machine speed.
  • Build autonomous response playbooks to isolate hosts, revoke sessions, and quarantine content.
  • Implement guardrails: confidence thresholds, blast-radius controls, and safe rollback for automations.
  • Instrument detection/response for metrics like mean time to detect and ATT&CK coverage.
  • Use LLMs and agentic tooling to summarize investigations and draft containment plans.

Skills

Threat fundamentals
Detection engineering
Adversary emulation
Applied AI
MITRE ATT&CK
AI tooling

Tools

AI/ML tooling
LLMs
Agentic tooling

Job description

Job Summary

Catch attackers in minutes, not days. Test our own defenses at attacker speed, continuously.

The Senior Threat Engineer is a hands‑on, high‑impact role within the Enterprise Defense & Automation (EDA) team. You will engineer AI‑powered detection and response capabilities that compress attacker dwell time from days to minutes, and you will continuously red team those same defenses at attacker speed so that gaps are found by us long before they are found by an adversary.

The role sits at the intersection of threat detection engineering, adversary emulation, and applied AI. On the defensive side you will build detections and AI‑assisted response paths that triage, decide, and act autonomously within policy, moving security operations from "alert and investigate" to detect, decide, and act. On the offensive side you will run continuous, automated adversary emulation against production controls, generating a constant stream of evidence about what our defenses actually stop.

This is a builder and problem‑solver role. You will write detection logic, adversary emulation content, and automated response playbooks; instrument them with measurable outcomes such as mean time to detect, mean time to contain, and detection coverage against MITRE ATT&CK; and use AI to raise signal fidelity rather than alert volume. Every detection you ship is expected to be tested by an emulation you also ship.

Success requires strong threat fundamentals, fluency across modern detection and response platforms, and the discipline to deliver production‑grade capability that holds up in real‑world, adversarial conditions. Guardrails matter as much as speed: confidence thresholds, blast‑radius limits, and rollback paths are part of the design, not an afterthought.

If you are energized by hunting real adversaries, teaching machines to respond faster than they can, and attacking your own work before anyone else gets the chance, this role puts you at the forefront of modern cyber defense.

What you will do
AI-Powered Detection & Response - catch attackers in minutes, not days (Primary)

Engineer high‑fidelity detections across identity, endpoint, network, cloud, and SaaS, and pair each one with an automated response path so the outcome is containment, not another alert.

Apply AI and machine learning to triage, correlate, and enrich alerts at machine speed - clustering related signals into a single incident narrative and surfacing the attacker story instead of a queue of fragments.

Build autonomous and semi‑autonomous response playbooks that isolate hosts, revoke sessions and tokens, disable credentials, block infrastructure, and quarantine content within minutes of first signal.

Implement the guardrails that make autonomy safe: confidence thresholds, blast‑radius controls, human‑in‑the‑loop escalation for high‑impact actions, and tested rollback for every automated action.

Instrument detection and response for measurable outcomes - mean time to detect, mean time to contain, false‑positive rate, and ATT&CK coverage - and drive those numbers down release over release.

Use LLMs and agentic tooling where they earn their place: summarizing investigations, drafting containment recommendations, extracting indicators from unstructured reporting, and generating detection logic that a human reviews before it ships.

Continuous AI Red Teaming - test our own defenses at attacker speed (Primary)

Stand up and operate continuous, automated adversary emulation against production controls, so defensive coverage is proven by evidence on a recurring cadence rather than assumed between annual assessments.

Use AI to generate and mutate attack behavior - varying tradecraft, tooling, and sequencing across ATT&CK techniques - so detections are tested against variants rather than a single static signature.

Close the loop from emulation to engineering: every miss becomes a detection backlog item, every noisy hit becomes a tuning task, and every fix is re‑tested automatically.

Red team our AI itself - test detection models, agents, and prompts for evasion, prompt injection, data poisoning, and unsafe autonomous action, and remediate what you find.

Operate emulation safely in production: scoped targets, rate limits, clear abort criteria, deconfliction with the response team, and full audit trails for every executed technique.

Report coverage as a living metric - which techniques are prevented, which are detected, which are only logged, and which are invisible - and use it to prioritize the detection roadmap.

Threat Research & Hunting

Track adversary tradecraft relevant to CDW and our customers, and translate intelligence into emulation plans, detections, and response actions rather than reading material.

Run hypothesis‑driven threat hunts across SIEM, XDR, identity, and cloud telemetry, and convert every confirmed hunt technique into an automated detection so the same hunt never has to be run by hand twice.

Map techniques to controls and automated responses once, t

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI-Driven Threat Detection & Red Team Engineer
Senior AI-Driven Threat Detection & Red Team Engineer

CO1000 CDW, LLC • Illinois

Hybrid
USD 137,000 - 191,000
AI-Driven Threat Engineer: Rapid Detection & Red Teaming
AI-Driven Threat Engineer: Rapid Detection & Red Teaming

CDW • United States

On-site
USD 140,000 - 210,000
Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming
Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming

CO1000 CDW, LLC • Illinois

Hybrid
USD 137,000 - 191,000
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Detection Engineer
Detection Engineer

Aegis AI Security • New York (NY)

On-site
USD 180,000 - 240,000
Detection Engineer
Detection Engineer

Cerebras • San Francisco (CA)

On-site
USD 150,000 - 200,000
Cybersecurity Threat Detection & Automation Manager
Cybersecurity Threat Detection & Automation Manager

Cummins Inc. • Troy (MI)

On-site
USD 150,000 - 190,000
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Lead Detection Architect: AI-Driven Cyber Defense
Lead Detection Architect: AI-Driven Cyber Defense

Cerebras • San Francisco (CA)

On-site
Sr. IT Security Engineer (Hybrid)
Sr. IT Security Engineer (Hybrid)

Belk • Town of Charlotte (NY)

Hybrid
CAD 207,000 - 276,000