Threat Detection Engineer - Purple Team & Threat Hunting

CVS Health

Lincoln (NE)

On-site

USD 107,000 - 284,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CVS Health is hiring a Staff Threat Detection Engineer to help stay ahead of evolving cyber threats. The role combines threat hunting, detection engineering, and offensive security to identify suspicious activity and strengthen our security posture using telemetry, threat intel, and adversary-focused analysis.

You'll work with Security Operations, Incident Response, and other cybersecurity teams to develop detections, support investigations, and validate controls through purple team exercises

Qualifications

  • 7+ years of experience in threat detection, hunting, penetration testing, and/or offensive security.
  • 5+ years of experience in Microsoft Security tools (Defender for Endpoint, Sentinel), CrowdStrike, and Splunk.
  • 3+ years of experience with KQL, SPL, Python, PowerShell, or Bash scripting for automation and detection logic.

Responsibilities

  • Develop, deploy, and optimize detection rules across SIEM platforms such as Microsoft Sentinel and Splunk.
  • Conduct threat hunting activities using Microsoft Defender, CrowdStrike, and other SOC tools to identify and respond to advanced threats.
  • Leverage KQL and SPL (Search Processing Language) to create custom detections and automate responses.
  • Continuously refine detection capabilities based on emerging threats and intelligence.
  • Assist with internal and external penetration tests to identify vulnerabilities.
  • Design and execute adversary emulation scenarios to assess detection and response effectiveness.
  • Utilize penetration testing tools and custom scripts to simulate real-world attack scenarios.
  • Produce detailed reports with findings and actionable recommendations.
  • Work closely with blue teams to conduct purple team exercises, bridging offensive and defensive security efforts.
  • Provide actionable insights to improve monitoring, alerting, and incident response based on adversary tactics.
  • Facilitate knowledge-sharing sessions to upskill internal teams on TTPs (Tactics, Techniques, and Procedures).
  • Integrate threat intelligence into detection strategies to prioritize threats and adapt detection rules.
  • Analyze threat intelligence feeds and translate them into actionable detection and response measures.
  • Collaborate with the incident response team during investigations by providing adversary tactics insights.
  • Assist in developing threat-hunting use cases and refining detection capabilities.
  • Contribute to the development of a comprehensive detection strategy aligned with risk management goals.
  • Provide leadership with reports on security gaps, risks, and detection effectiveness.

Skills

Threat detection
Threat hunting
Penetration testing
Offensive security
Microsoft Defender
Splunk
CrowdStrike
KQL
SPL
Python
PowerShell
Bash scripting

Education

Bachelor's degree

Tools

Microsoft Sentinel
Splunk
Penetration testing tools

Job description

CVS Health is hiring a Staff Threat Detection Engineer to help stay ahead of evolving cyber threats. The role combines threat hunting, detection engineering, and offensive security to identify suspicious activity and strengthen our security posture using telemetry, threat intel, and adversary-focused analysis.

You'll work with Security Operations, Incident Response, and other cybersecurity teams to develop detections, support investigations, and validate controls through purple team exercises

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Detection Engineer - Purple Team & Threat Hunting
Threat Detection Engineer - Purple Team & Threat Hunting

CVS Health • Denver (CO)

On-site
USD 107,000 - 284,000
Bonus eligibility
Equity award program
Comprehensive benefits
Threat Detection Engineer: Purple Team & Threat Hunting
Threat Detection Engineer: Purple Team & Threat Hunting

CVS Health • Indianapolis (IN)

On-site
USD 107,000 - 284,000
Bonus eligibility
Comprehensive benefits
Threat Detection Engineer — Threat Hunting & Purple Team
Threat Detection Engineer — Threat Hunting & Purple Team

CVS Health • Nashville (TN)

On-site
USD 107,000 - 284,000
Bonus program
Comprehensive benefits
Equity award target
Threat Detection Engineer: Purple Team & Hunting
Threat Detection Engineer: Purple Team & Hunting

CVS Health • Tallahassee (FL)

On-site
USD 107,000 - 284,000
Senior Threat Detection Engineer - Purple Team Leader
Senior Threat Detection Engineer - Purple Team Leader

Koitecc Solutions • Annapolis (MD)

On-site
USD 107,000 - 284,000
Senior Threat Detection Engineer — Purple Team
Senior Threat Detection Engineer — Purple Team

CVS Health • Jackson (MS)

On-site
USD 96,000 - 117,000
Threat Detection Engineer | Threat Hunting & Purple Team
Threat Detection Engineer | Threat Hunting & Purple Team

CVS Health • Sacramento (CA)

On-site
USD 107,000 - 284,000
Medical, dental, and vision coverage
Retirement savings options
Paid time off and wellness programs
Senior Threat Detection Engineer — Purple Team & Hunting
Senior Threat Detection Engineer — Purple Team & Hunting

CVS Health • Washington

On-site
USD 107,000 - 284,000
Bonus program
Equity awards
Comprehensive benefits
Threat Detection Engineer — Purple Team Lead
Threat Detection Engineer — Purple Team Lead

CVS Health • Juneau (AK)

On-site
USD 107,000 - 284,000
Bonus eligibility
Comprehensive benefits
Equity awards
Senior Threat Detection Engineer — Purple Team & Hunting
Senior Threat Detection Engineer — Purple Team & Hunting

Koitecc Solutions • Dover (DE)

On-site
USD 107,000 - 284,000
Comprehensive benefits package
Bonus eligible
Equity award program