Threat Detection Engineer

WorkdayReston, VA
Hybrid

About The Position

Workday is using the latest software development, cloud and AI technologies to build platforms and application services to support our growth while also ensuring the protection of Workday data and infrastructure. Our Active Defense team is a group of highly skilled and dedicated professionals who are passionate about protecting our organization from cyber threats. We work together to proactively counter advanced security threats. Our team members have a strong background in cybersecurity, data analysis, AI and machine learning, and detection engineering. We use innovative tools and technologies to analyze and visualize data, including Splunk, Spark, Python, and AI-assisted analysis and automation tools. We value teamwork and collaborate closely with other security teams to ensure that our organization stays ahead of emerging cyber threats. We are committed to continuous learning and professional development, and regularly attend industry conferences and training sessions to stay up to date on the latest trends and best practices in security analytics. This role is focused on advanced threat detection. As a member of the Active Defense team, you will get an opportunity to collaborate with a large cross-section of teams across Workday to understand the threat landscape, participate in various threat hunting and offensive security exercises to discover potential vulnerabilities and test detection coverage, perform data and detection gap analysis and then use this information to develop and refine alerting logic while applying innovative techniques on large volumes of real-time data. You will also help develop adaptive and AI-assisted detection capabilities that use behavioral baselines, entity-level context, and automation to support detection development, detection validation, threat hunting, and pre-production alert baselining. You will have the flexibility of a hybrid schedule.

Requirements

  • 2+ years of experience analyzing security logs, building or maintaining detection logic, and translating threat intelligence, attacker behavior, or incident learnings into practical detections.
  • 2+ years of experience in a general-purpose programming language like Python, Java, Kotlin, Scala, or JavaScript to build effective detection tools.
  • Experience developing, securing, and monitoring applications in public cloud environments.
  • BS or MS degree in Computer Science, Engineering, or equivalent practical experience.

Nice To Haves

  • Leverage the MITRE ATT&CK framework to identify and hunt for threats based on IOCs and IOAs.
  • Experience developing or applying agents, automation, or workflow orchestration to improve detection engineering, detection validation, threat hunting, or pre-production alert baselining outcomes.
  • Experience using AI-based discovery and exploit creation tools to mimic adversary capabilities.
  • Experience with networking and Linux operating systems.
  • Understanding of containerized applications and associated security challenges.
  • Familiarity with behavior anomaly detection, entity-level baselines, outlier detection, clustering, and forecasting techniques.
  • Experience with SIEM platforms such as Splunk and Elasticsearch.
  • Familiarity with CI/CD pipelines and the Software Development Lifecycle (SDLC).

Responsibilities

  • Collaborate with a large cross-section of teams across Workday to understand the threat landscape.
  • Participate in various threat hunting and offensive security exercises to discover potential vulnerabilities and test detection coverage.
  • Perform data and detection gap analysis.
  • Develop and refine alerting logic while applying innovative techniques on large volumes of real-time data.
  • Develop adaptive and AI-assisted detection capabilities that use behavioral baselines, entity-level context, and automation to support detection development, detection validation, threat hunting, and pre-production alert baselining.

Benefits

  • Workday Bonus Plan or a role-specific commission/bonus
  • Annual refresh stock grants
  • Comprehensive benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service