Threat Detection Engineer

WorkdayReston, VA
Hybrid

About The Position

Workday is using the latest software development, cloud and AI technologies to build platforms and application services to support our growth while also ensuring the protection of Workday data and infrastructure. Our security analytics team is a group of highly skilled and dedicated professionals who are passionate about protecting our organization from cyber threats. We work together to analyze large volumes of security data to mitigate security threats. Our team members have a strong background in cybersecurity, data analysis, and machine learning. We use innovative tools and technologies to analyze and visualize data, including Splunk, Spark, and Python. We value teamwork and collaborate closely with other security teams, including threat intelligence and SIRT to ensure that our organization stays ahead of emerging cyber threats. We are committed to continuous learning and professional development, and regularly attend industry conferences and training sessions to stay up to date on the latest trends and best practices in security analytics. As a member of the Security Analytics team, you will get an opportunity to collaborate with a large cross section of teams across Workday to understand the threat landscape, participate in various threat hunting exercises to discover potential vulnerabilities and test detective coverage, perform data and detection gap analysis and then use this information to develop and refine alerting logic while applying innovative techniques on large volumes of real time data. You will have the flexibility of a hybrid schedule.

Requirements

  • Experience with analyzing security logs and turning them into effective alert logic, baselines, and investigation context.
  • Experience building and maintaining detections as durable production content.
  • Experience translating threat intelligence, attacker behavior, and incident learnings into practical detections.
  • 2+ years of experience in a general-purpose programming language like Python, Java, Kotlin, Scala, or JavaScript to build effective detection tools.
  • Experience developing, securing, and monitoring applications in public cloud environments.
  • BS or MS degree in Computer Science, Engineering, or equivalent practical experience.
  • Leverage the MITRE ATT&CK framework to identify and hunt for threats based on IOCs and IOAs.
  • Experience with networking and Linux operating systems.
  • Understanding of containerized applications and associated security challenges.
  • Familiarity with outlier detection, clustering, and forecasting techniques.
  • Experience with SIEM platforms such as Splunk and Elasticsearch.
  • Familiarity with CI/CD pipelines and the Software Development Lifecycle (SDLC).

Responsibilities

  • Collaborate with a large cross section of teams across Workday to understand the threat landscape.
  • Participate in various threat hunting exercises to discover potential vulnerabilities and test detective coverage.
  • Perform data and detection gap analysis.
  • Develop and refine alerting logic.
  • Apply innovative techniques on large volumes of real-time data.

Benefits

  • Workday Bonus Plan
  • Role-specific commission/bonus
  • Annual refresh stock grants
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service