Detection & Automation Engineer III

Northwestern Mutual•Milwaukee, WI
•$108,160 - $186,600•Hybrid

About The Position

At Northwestern Mutual, our cybersecurity team is focused on protecting our clients, advisors, and business platforms through innovative detection and automation capabilities. As a Detection & Automation Engineer III, you will play a key role in enhancing our ability to identify, investigate, and respond to cybersecurity threats across cloud, identity, endpoint, database, and application environments. This position blends DevOps, detection engineering, SIEM administration, telemetry engineering, and data integration to improve security visibility and strengthen our threat detection program. You'll work closely with cybersecurity, infrastructure, cloud, and application teams to build scalable detection capabilities, onboard critical security telemetry, and drive continuous improvements across our security operations ecosystem.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent professional experience.
  • 2+ years of experience in cybersecurity, detection engineering, security operations, SIEM engineering, or related disciplines.
  • Hands-on experience developing and maintaining threat detections within Splunk Enterprise Security or comparable SIEM platforms.
  • Strong understanding of security monitoring, log management, telemetry engineering, and threat detection methodologies.
  • Experience working with cloud platforms, identity systems, endpoint security technologies, applications, databases, and enterprise infrastructure.
  • Knowledge of security frameworks, including MITRE ATT&CK, and their application to threat detection strategies.
  • Experience onboarding, normalizing, and validating security data from multiple sources.
  • Familiarity with scripting or automation technologies such as Python, PowerShell, or similar languages.
  • Experience with source control platforms, automated testing, and CI/CD pipelines.
  • Strong troubleshooting, analytical, and problem-solving skills with the ability to identify complex security issues and implement scalable solutions.
  • Excellent communication and collaboration skills with the ability to work effectively across technical and business teams.

Nice To Haves

  • Experience with Splunk Enterprise and/or Cribl Stream.
  • Experience supporting cybersecurity monitoring and logging requirements within regulated environments.
  • Background in database administration, enterprise data engineering, or large-scale telemetry architectures.
  • Experience implementing Detection-as-Code methodologies and security automation solutions.
  • Knowledge of audit logging standards, security monitoring controls, and modern security observability practices.
  • Relevant industry certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Administrator, GIAC, CISSP, GCIA, GCIH, or equivalent.

Responsibilities

  • Design, develop, test, and maintain advanced threat detections across a variety of security platforms and data sources.
  • Enhance detection coverage by identifying telemetry gaps and partnering with stakeholders to improve visibility across the environment.
  • Administer and optimize Splunk Enterprise Security, including ES frameworks, data models, reporting, dashboards, and search performance.
  • Troubleshoot and resolve security data ingestion, field extraction, parsing, normalization, and performance issues.
  • Partner with technology teams to onboard new security data sources and validate telemetry quality.
  • Develop and maintain security logging standards, monitoring controls, and data quality processes.
  • Design monitoring capabilities for enterprise databases and business-critical applications, focusing on privileged access, authentication activity, anomalous behavior, and sensitive data access.
  • Contribute to Detection-as-Code initiatives through version control, automated testing, CI/CD pipelines, and reusable detection frameworks.
  • Track and improve key metrics including detection coverage, alert fidelity, telemetry health, and operational effectiveness.
  • Drive continuous improvement efforts that reduce false positives, improve detection accuracy, and streamline security operations.
  • Provide technical leadership, mentor junior engineers, and contribute to architectural and engineering best practices.

Benefits

  • Geographic specific pay structures, compensation and benefits could be applicable
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service