1

Senior Threat Detection Engineer Jobs (NOW HIRING)

Senior Threat Detection Engineer

Bellevue, WA · On-site

$128K - $176K/yr

As a Senior Threat Detection Engineer, you will take ownership of technical areas, leading initiatives to enhance threat detection and collaborate across teams to ensure security for Salesforce ...

We are looking for a savvy, high-performing Threat Detection Engineer who will be responsible for the day-to-day management of company-wide information security toolsets and the protection of ...

Senior Threat Detection Engineer

SC · On-site

$101K - $132K/yr

We are looking for a savvy, high-performing Threat Detection Engineer who will be responsible for the day-to-day management of company-wide information security toolsets and the protection of ...

Tenex is seeking a highly motivated and skilled Threat Detection Engineer to join our growing Security Operations team. In this critical role, you will be responsible for proactively identifying and ...

Lead Threat Detection Engineer

Irving, TX · On-site +1

$139K - $231K/yr

McKesson's Lead Threat Detection Engineer will be a member of our global cyber threat intelligence, incident response, analytics, and engineering team responsible for advancing our detection ...

Lead Threat Detection Engineer

Irving, TX · On-site +1

$139K - $231K/yr

McKesson's Lead Threat Detection Engineer will be a member of our global cyber threat intelligence, incident response, analytics, and engineering team responsible for advancing our detection ...

WV

$94K - $129K/yr

About the role A Senior Threat Engineer builds and improves systems, logic, and workflows that ... Own complex threat detection and workflow problem spaces from investigation concept through ...

next page

Showing results 1-20

Senior Threat Detection Engineer information

See salary details

$59.5K

$126.6K

$183.5K

How much do senior threat detection engineer jobs pay per year?

As of Aug 4, 2026, the average yearly pay for senior threat detection engineer in the United States is $126,557.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,500.00 and $143,500.00 per year, depending on experience, location, and employer.

What does a senior threat detection engineer do?

A Senior Threat Detection Engineer is responsible for designing, implementing, and maintaining systems that identify and respond to cybersecurity threats within an organization's network. They analyze security alerts, develop detection logic, and work closely with incident response teams to mitigate risks. Their role often includes researching emerging threats, improving detection capabilities, and mentoring junior engineers. By proactively identifying potential security breaches, they help safeguard sensitive information and ensure the organization’s cyber resilience.

What are the key skills and qualifications needed to thrive as a senior threat detection engineer, and why are they important?

A Senior Threat Detection Engineer requires deep expertise in cybersecurity, threat analysis, and incident response, often backed by a degree in computer science or a related field and industry certifications like CISSP or GIAC. Proficiency with SIEM platforms (such as Splunk or QRadar), EDR solutions, scripting languages, and threat intelligence tools is crucial. Strong analytical thinking, problem-solving abilities, and effective communication skills distinguish top performers in this role. These competencies ensure accurate threat identification, swift mitigation, and robust organizational security in an ever-evolving threat landscape.

What is the difference between Senior Threat Detection Engineer vs Security Analyst?

AspectSenior Threat Detection EngineerSecurity Analyst
CertificationsGICSP, CISSP, GIAC certificationsCompTIA Security+, GIAC certifications
Work EnvironmentAdvanced threat detection, incident response, security architectureMonitoring, analyzing security alerts, reporting
Industry UsageUsed in cybersecurity teams focusing on threat detection and responseUsed across organizations for security monitoring and analysis

While both roles focus on cybersecurity, the Senior Threat Detection Engineer primarily develops and implements advanced detection strategies and handles complex incident responses. The Security Analyst monitors security alerts and performs initial analysis. The Senior Threat Detection Engineer typically requires more technical expertise and experience in threat hunting, whereas Security Analysts focus on alert management and reporting.

How does a senior threat detection engineer typically collaborate with other teams to enhance organizational security?

A Senior Threat Detection Engineer works closely with security operations, incident response, IT, and development teams to identify and mitigate threats. This often involves sharing intelligence, developing detection rules, and coordinating responses to security incidents. Regular collaboration ensures that detection strategies align with evolving threats and organizational priorities, fostering a proactive security posture. Effective communication and teamwork are essential, as these engineers often lead efforts to improve detection capabilities and mentor junior staff.
More about Senior Threat Detection Engineer jobs
What cities are hiring for Senior Threat Detection Engineer jobs? Cities with the most Senior Threat Detection Engineer job openings:
What are the most commonly searched types of Threat Detection Engineer jobs? The most popular types of Threat Detection Engineer jobs are:
What states have the most Senior Threat Detection Engineer jobs? States with the most job openings for Senior Threat Detection Engineer jobs include:
Infographic showing various Senior Threat Detection Engineer job openings in the United States as of July 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $126,557 per year, or $60.8 per hour.

Senior Threat Detection Engineer

Salesforce

Bellevue, WA • On-site

$128K - $176K/yr

Full-time

Re-posted 3 days ago


Salesforce rating

8.1

Company rating: 8.1 out of 10

Based on 58 frontline employees who took The Breakroom Quiz

120th of 241 rated software companies


Job description

Job Summary:
Salesforce is the #1 AI CRM, where innovation and customer success are at the forefront. As a Senior Threat Detection Engineer, you will take ownership of technical areas, leading initiatives to enhance threat detection and collaborate across teams to ensure security for Salesforce's infrastructure and customers.
Responsibilities:
• The Threat Detection team is responsible for detecting attacks against Salesforce's infrastructure, products, employees, and customers.
• The team collaborates with CSIRT and engineering teams to enhance detection effectiveness.
• The role involves writing logic on security platforms to detect malicious activity, building attack simulation scenarios, and testing logic effectiveness.
• Collaboration with the incident response team is essential to improve alert reliability and quality.
• As a Senior Threat Detection Engineer,, you will be responsible to lead a project end to end owning a technical area, and delivering research and features.
• In this role you will be working security organization wide initiatives and cross-team collaboration are expected working with multiple engineering teams is required.
Qualifications:
Required:
• 6 to 8 years of experience in relevant areas like in Threat Detection, Threat Hunting, Security Incident Response, and managing significant security incidents and breaches.
• Experience and expertise in developing and refining threat detection methodologies is a prerequisite.
• Proficiency in leveraging security logs from multiple log source types which includes network infrastructure, endpoint devices, public and private cloud substrates and SaaS.
• A comprehensive grasp of log structure, data normalization techniques, and the capacity to isolate critical security incidents is imperative.
• Strong proficiency and experience in log correlation techniques to identify patterns and anomalies indicative of malicious activity.
• Demonstrate expertise in constructing complex search queries using languages such as SPL, YARAL and other query languages to analyze large volumes of data.
• Possess strong data analysis skills to interpret query results, identify false positives, and fine-tune detection rules for optimal efficacy.
• Demonstrate in-depth knowledge of fundamental security principles, common attack vectors employed by threat actors, Tactics, Techniques, and Procedures (TTPs) used throughout the cyber kill chain, and relevant security frameworks such as the MITRE ATT&CK framework.
• Possess practical experience in working with a variety of security tools and technologies, including Security Information and Event Management (SIEM) systems for centralized log analysis and alerting, Endpoint Detection and Response (EDR) solutions for endpoint visibility and threat mitigation, Network Detection and Response (NDR) tools for network traffic analysis and anomaly detection, and Security Orchestration, Automation and Response (SOAR) platforms for automating incident response workflows.
• Demonstrate the ability to effectively handle and analyze large and complex datasets, identifying meaningful security insights and trends from vast amounts of information.
• Knowledge of writing detections based on network, host, OS, and other logs.
• Experience with correlation and complex log analytic queries.
• Coding experience with Python or other languages for automation.
• Ability to correlate multiple log sources for effective adversary detection.
• Demonstrated experience collaborating across global, cross-functional teams with members in multiple time zones, with the ability to communicate and coordinate effectively across geographically distributed environments.
• A related technical degree required.
Preferred:
• Hands on experience with any log aggregation/SIEM tool such as and not limited to Splunk, Elastic (ELK), FLINK, Chronicle etc
• Hands on Experience with public cloud, such as AWS or Azure or GCP, especially Public cloud security.
• Undergraduate degree in cyber security, computer science, information technology, or similar subjects.
• Experience working in a globally distributed team leveraging documentation and async communications as needed
• Prior experience or basic knowledge on DS algorithms and methodologies
• Experience on automation platform such as SOAR
Company:
Salesforce is a cloud-based software company that provides customer relationship management software and applications. Founded in 1999, the company is headquartered in San Francisco, USA, with a team of 10001+ employees. The company is currently Late Stage.

What Salesforce employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom