> Markdown version of [/jobs/ext/2834983-senior-threat-engineer-ai-powered-detection-response-continuous-ai-red-teaming](https://www.wearedevelopers.com/jobs/ext/2834983-senior-threat-engineer-ai-powered-detection-response-continuous-ai-red-teaming). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Threat Engineer - AI-Powered Detection, Response & Continuous AI Red Teaming - **Company:** CDW - **Location:** United States - **Experience:** Expert - **Salary:** $137,000.0 - $190,600.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Automation of Tests, Microsoft Azure, Software as a Service, Cyber Security, Continuous Integration, Emulators, Intrusion Detection and Prevention, Python (Programming Language), Red Team (Cyber Security), Security Information and Event Management, Systems Integration, Large Language Models, Mitre Att&ck, Cyber Threat Analysis, Core Api, Cybercrime, Microsoft Sentinel, Cyber Warfare, Splunk, Security Orchestration, Automation & Response - **Published:** September 10, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18238582?backUrl=%2Fcareer%2F18238582%2FSenior-Threat-Engineer-Ai-Powered-Detection-Response-Continuous-Ai-Red-Teaming ## About the Role * Bachelor's degree and 7+ years of experience in threat detection engineering, threat hunting, incident response, or offensive security, or 11+ years of equivalent experience. * Handson experience building and tuning detections in SIEM platforms and cloudscale security tooling. * Practical working knowledge of the MITRE ATT&CK framework, including mapping detections and automated responses to techniques. * Experience with adversary emulation, purple teaming, breach and attack simulation, or penetration testing against production controls. * Proficiency in Python for productiongrade automation and tooling. * Experience applying AI/ML or LLMbased capabilities to security problems, and designing secure, observable, and maintainable AIenabled solutions. * Working experience with security automation, orchestration, or SOAR platforms. * Built detection and response capability for large, diverse enterprise environments, a plus. * Familiarity with platforms such as Microsoft Defender, Microsoft Sentinel, CrowdStrike, Tines, Entra ID, and Splunk, a plus. * Familiarity with emulation and offensive tooling such as Atomic Red Team, Caldera, Cobalt Strike, or commercial breach and attack simulation platforms, a plus * Detectionascode practice: CI/CD pipelines, infrastructureascode, policyascode, and automated testing of detection content, a plus. * Experience securing or red teaming AI systems, including prompt injection, model evasion, and agent safety testing, a plus * Relevant certifications (GCIH, GCFA, GCTI, GPEN, OSCP, Azure Security, or cloud and automation certifications), a plus., We're looking for people who bring curiosity, a learner's mindset, and a willingness to engage with ever-evolving technology and tools. We value adopting AI as a partner, openness to experimentation, and a shared interest in learning together on AI. Our goal is to create a culture where AI enhances-not replaces-human creativity and decision-making. You don't need to be an expert today; what matters is your readiness to explore, adapt, and grow with us as we integrate AI responsibly and effectively into our work. ## Description The Senior Threat Engineer is a handson, highimpact role within the Enterprise Defense & Automation (EDA) team. You will engineer AIpowered detection and response capabilities that compress attacker dwell time from days to minutes, and you will continuously red team those same defenses at attacker speed so that gaps are found by us long before they are found by an adversary. The role sits at the intersection of threat detection engineering, adversary emulation, and applied AI. On the defensive side you will build detections and AIassisted response paths that triage, decide, and act autonomously within policy, moving security operations from "alert and investigate" to detect, decide, and act. On the offensive side you will run continuous, automated adversary emulation against production controls, generating a constant stream of evidence about what our defenses actually stop. This is a builder and problemsolver role. You will write detection logic, adversary emulation content, and automated response playbooks; instrument them with measurable outcomes such as mean time to detect, mean time to contain, and detection coverage against MITRE ATT&CK; and use AI to raise signal fidelity rather than alert volume. Every detection you ship is expected to be tested by an emulation you also ship. Success requires strong threat fundamentals, fluency across modern detection and response platforms, and the discipline to deliver productiongrade capability that holds up in realworld, adversarial conditions. Guardrails matter as much as speed: confidence thresholds, blastradius limits, and rollback paths are part of the design, not an afterthought. If you are energized by hunting real adversaries, teaching machines to respond faster than they can, and attacking your own work before anyone else gets the chance, this role puts you at the forefront of modern cyber defense. What you will do AI-Powered Detection & Response - catch attackers in minutes, not days (Primary) * Engineer highfidelity detections across identity, endpoint, network, cloud, and SaaS, and pair each one with an automated response path so the outcome is containment, not another alert. * Apply AI and machine learning to triage, correlate, and enrich alerts at machine speed - clustering related signals into a single incident narrative and surfacing the attacker story instead of a queue of fragments. * Build autonomous and semiautonomous response playbooks that isolate hosts, revoke sessions and tokens, disable credentials, block infrastructure, and quarantine content within minutes of first signal. * Implement the guardrails that make autonomy safe: confidence thresholds, blastradius controls, humanintheloop escalation for highimpact actions, and tested rollback for every automated action. * Instrument detection and response for measurable outcomes - mean time to detect, mean time to contain, falsepositive rate, and ATT&CK coverage - and drive those numbers down release over release. * Use LLMs and agentic tooling where they earn their place: summarizing investigations, drafting containment recommendations, extracting indicators from unstructured reporting, and generating detection logic that a human reviews before it ships. Continuous AI Red Teaming - test our own defenses at attacker speed (Primary) * Stand up and operate continuous, automated adversary emulation against production controls, so defensive coverage is proven by evidence on a recurring cadence rather than assumed between annual assessments. * Use AI to generate and mutate attack behavior - varying tradecraft, tooling, and sequencing across ATT&CK techniques - so detections are tested against variants rather than a single static signature. * Close the loop from emulation to engineering: every miss becomes a detection backlog item, every noisy hit becomes a tuning task, and every fix is retested automatically. * Red team our AI itself - test detection models, agents, and prompts for evasion, prompt injection, data poisoning, and unsafe autonomous action, and remediate what you find. * Operate emulation safely in production: scoped targets, rate limits, clear abort criteria, deconfliction with the response team, and full audit trails for every executed technique. * Report coverage as a living metric - which techniques are prevented, which are detected, which are only logged, and which are invisible - and use it to prioritize the detection roadmap. Threat Research & Hunting * Track adversary tradecraft relevant to CDW and our customers, and translate intelligence into emulation plans, detections, and response actions rather than reading material. * Run hypothesisdriven threat hunts across SIEM, XDR, identity, and cloud telemetry, and convert every confirmed hunt technique into an automated detection so the same hunt never has to be run by hand twice. * Map techniques to controls and automated responses once, then reuse the mapping globally across the estate. * Lead technical deep dives on significant incidents and emulation findings, and feed the lessons back into detection content, response playbooks, and platform hardening. Detection Engineering as Code * Treat detection content as software: version controlled, peer reviewed, unit tested against emulation data and promoted through CI/CD with security gates that block lowquality logic before it reaches production. * Develop integrations and tooling in Python against platform APIs and eventdriven architectures, favoring reusable services over oneoff scripts. * Build detection and response capability that selfheals - identifying telemetry gaps, sensor degradation, and control drift, then correcting them or rolling back to a knowngood state without waiting for a human. * Eliminate repeat findings through native autoremediation patterns rather than recurring manual cleanup. Collaboration & Influence * Partner closely with the Threat Response team, Cyber Defense Engineering, security platform owners, and business unit owners so that detections, emulations, and automated actions land with clear ownership boundaries. * Contribute to shared backlogs and design reviews, and mentor engineers and analysts on detection quality, adversary tradecraft, and the safe use of AI in the defensive stack. * Document detection logic, emulation plans, automation patterns, and engineering decisions so the capability survives any single person. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Insights from building the Canva Developers Platform to empower 185 million designers](https://www.wearedevelopers.com/videos/942-insights-from-building-the-canva-developers-platform-to-empower-185-million-designers) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [WWC24 - Chris Wysopal, Helmut Reisinger and Johannes Steger - Fighting Digital Threats in the Age of AI](https://www.wearedevelopers.com/videos/926-wwc24-chris-wysopal-helmut-reisinger-and-johannes-steger-fighting-digital-threats-in-the-age-of-ai) - [WeAreDevelopers LIVE – Web Scraping, Agents, Actors and more](https://www.wearedevelopers.com/videos/1764-wearedevelopers-live-web-scraping-agents-actors-and-more) - [Why make use of an integration platform in today's software developments and infrastructure?](https://www.wearedevelopers.com/videos/758-why-make-use-of-an-integration-platform-in-today-s-software-developments-and-infrastructure) ## Related Articles - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)