Staff Threat Detection Engineer: Adversary Emulation & SIEM

CVS Health

Olympia (WA)

On-site

USD 120,000 - 260,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical coverage
Dental coverage
Vision coverage
Retirement plan
Paid time off

Job summary

CVS Health is seeking a Staff Threat Detection Engineer to join our security organization in the United States. You will lead threat hunting, detection engineering, and adversary emulation to strengthen our security posture and reduce risk to patients, colleagues, and business operations.

You will collaborate with Security Operations, Incident Response, and blue/red teams to develop detections across SIEMs like Microsoft Sentinel and Splunk, and to implement automation using KQL/SPL and

Qualifications

  • 7+ years of experience in threat detection, hunting, penetration testing, and/or offensive security.
  • 5+ years of experience in Microsoft Security tools (Defender for Endpoint, Sentinel), CrowdStrike, and Splunk.
  • 3+ years of experience with KQL, SPL, Python, PowerShell, or Bash scripting for automation and detection logic.

Responsibilities

  • Develop, deploy, and optimize detection rules across SIEM platforms such as Microsoft Sentinel and Splunk
  • Conduct threat hunting activities using Microsoft Defender, CrowdStrike, and other SOC tools to identify and respond to advanced threats.
  • Leverage KQL and SPL (Search Processing Language) to create custom detections and automate responses.
  • Continuously refine detection capabilities based on emerging threats and intelligence.
  • Assist with internal and external penetration tests to identify vulnerabilities.
  • Design and execute adversary emulation scenarios to assess detection and response effectiveness.
  • Utilize penetration testing tools and custom scripts to simulate real-world attack scenarios.
  • Produce detailed reports with findings and actionable recommendations.
  • Work closely with blue teams to conduct purple team exercises, bridging offensive and defensive security efforts.
  • Provide actionable insights to improve monitoring, alerting, and incident response based on adversary tactics.
  • Facilitate knowledge-sharing sessions to upskill internal teams on TTPs.

Skills

Threat detection
Threat hunting
Offensive security
Security analytics
Communication

Education

Bachelor's degree or equivalent experience

Tools

Microsoft Defender for Endpoint
Microsoft Defender Sentinel
CrowdStrike
Splunk
KQL
SPL
Python
PowerShell
Bash

Job description

CVS Health is seeking a Staff Threat Detection Engineer to join our security organization in the United States. You will lead threat hunting, detection engineering, and adversary emulation to strengthen our security posture and reduce risk to patients, colleagues, and business operations.

You will collaborate with Security Operations, Incident Response, and blue/red teams to develop detections across SIEMs like Microsoft Sentinel and Splunk, and to implement automation using KQL/SPL and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Detection & Adversary Emulation Engineer
Senior Threat Detection & Adversary Emulation Engineer

CVS Health • Charleston (WV)

On-site
USD 107,000 - 284,000
Senior Threat Detection Engineer & Adversary Emulation
Senior Threat Detection Engineer & Adversary Emulation

CVS Health • Salem (OR)

On-site
USD 107,000 - 284,000
Medical, dental, vision coverage
Bonus and equity awards
Comprehensive benefits
Senior Threat Detection Engineer & Adversary Emulation
Senior Threat Detection Engineer & Adversary Emulation

Koitecc Solutions • Cheyenne (WY)

On-site
USD 107,000 - 284,000
Medical benefits
Dental coverage
Vision coverage
+3
Lead Threat Detection Engineer & Adversary Emulation
Lead Threat Detection Engineer & Adversary Emulation

CVS Health • Annapolis (MD)

On-site
USD 107,000 - 284,000
Senior Threat Detection Engineer: Hunt, Emulation & SIEM
Senior Threat Detection Engineer: Hunt, Emulation & SIEM

CVS Health • Jefferson City (MO)

On-site
USD 107,000 - 284,000
Senior Threat Detection & Hunting Engineer
Senior Threat Detection & Hunting Engineer

Koitecc Solutions • Pierre (SD), Northern (KY)

On-site
USD 107,000 - 284,000
Competitive compensation
Comprehensive benefits
Career growth
Senior Threat Detection Engineer - Threat Hunting
Senior Threat Detection Engineer - Threat Hunting

Idaho Society of Professional Engineers • Boise (ID), Northern (KY)

Hybrid
USD 107,000 - 284,000
Senior Threat Detection Engineer | Threat Hunting & SIEM
Senior Threat Detection Engineer | Threat Hunting & SIEM

Koitecc Solutions • Atlanta (GA)

Hybrid
USD 107,000 - 284,000
Medical, dental, vision
Senior Threat Detection Engineer
Senior Threat Detection Engineer

Koitecc Solutions • Bismarck (ND)

On-site
USD 107,000 - 284,000
Senior Threat Detection & Purple Team Engineer
Senior Threat Detection & Purple Team Engineer

CVS Health • Frankfort (KY)

On-site
USD 107,000 - 284,000