Staff Threat Detection Engineer

CVS HealthNew York, NY
$106,605 - $284,280

About The Position

The Staff Threat Detection Engineer plays a key role in helping the organization stay ahead of evolving cyber threats. This position combines threat hunting, detection engineering, and offensive security expertise to identify suspicious activity, uncover emerging risks, and strengthen the organization's overall security posture. By leveraging security telemetry, threat intelligence, and adversary-focused analysis, this role helps ensure threats are identified and addressed before they can impact the business. Working closely with Security Operations, Incident Response, and other cybersecurity teams, this role develops and improves detections, supports investigations, and helps validate security controls through purple team exercises and adversary emulation activities. The position also contributes to the adoption of new tools, techniques, and automation capabilities that improve visibility and response effectiveness. Success in this role requires curiosity, strong analytical skills, and a passion for continuously improving how the organization detects and defends against cyber threats.

Requirements

  • 7+ years of experience in threat detection, hunting, penetration testing, and/or offensive security.
  • 5+ years of experience in Microsoft Security tools (Defender for Endpoint, Sentinel), CrowdStrike, and Splunk.
  • 3+ years of experience with KQL, SPL, Python, PowerShell, or Bash scripting for automation and detection logic.
  • Bachelor’s degree or equivalent experience (High School Diploma and 4 years relevant experience)

Nice To Haves

  • Relevant certifications such as OSCP, GCIH, GCIA, CISSP, CEH, or Microsoft Azure Certification.
  • Experience in managing or participating in purple team exercises.
  • Familiarity with compliance standards like PCI-DSS, HIPAA, or ISO 27001.
  • Strong understanding of the MITRE ATT&CK framework and security standards (NIST, CIS).
  • Strong communication skills to convey complex security issues to non-technical stakeholders.

Responsibilities

  • Develop, deploy, and optimize detection rules across SIEM platforms such as Microsoft Sentinel and Splunk
  • Conduct threat hunting activities using Microsoft Defender, CrowdStrike, and other SOC tools to identify and respond to advanced threats.
  • Leverage KQL and SPL (Search Processing Language) to create custom detections and automate responses.
  • Continuously refine detection capabilities based on emerging threats and intelligence.
  • Assist with internal and external penetration tests to identify vulnerabilities.
  • Design and execute adversary emulation scenarios to assess detection and response effectiveness.
  • Utilize penetration testing tools and custom scripts to simulate real-world attack scenarios.
  • Produce detailed reports with findings and actionable recommendations.
  • Work closely with blue teams to conduct purple team exercises, bridging offensive and defensive security efforts.
  • Provide actionable insights to improve monitoring, alerting, and incident response based on adversary tactics.
  • Facilitate knowledge-sharing sessions to upskill internal teams on TTPs (Tactics, Techniques, and Procedures).
  • Integrate threat intelligence into detection strategies to prioritize threats and adapt detection rules.
  • Analyze threat intelligence feeds and translate them into actionable detection and response measures.
  • Collaborate with the incident response team during investigations by providing adversary tactics insights.
  • Assist in developing threat-hunting use cases and refining detection capabilities.
  • Contribute to the development of a comprehensive detection strategy aligned with risk management goals.
  • Provide leadership with reports on security gaps, risks, and detection effectiveness.

Benefits

  • medical
  • dental
  • vision coverage
  • paid time off
  • retirement savings options
  • wellness programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service