1

Threat Detection Engineer Jobs (NOW HIRING)

The Detection Engineer will leverage telemetry generated through malware analysis, vulnerability ... Working closely with Threat Analysts and Security Researchers, this individual will develop high ...

We are hiring a Staff Security Engineer, Threat Detection for our Security team. This is a fully remote role open to candidates across the United States. As Snowflake scales globally, we are ...

Showing results 41-60

Threat Detection Engineer information

What are the key skills and qualifications needed to thrive as a threat detection engineer?

To thrive as a Threat Detection Engineer, you need a solid understanding of network security, cybersecurity frameworks, threat analysis, and incident response, often backed by a degree in computer science or a related field. Hands-on experience with SIEM tools (such as Splunk or QRadar), intrusion detection/prevention systems, malware analysis platforms, and certifications like CISSP or GIAC are highly valued. Strong analytical thinking, effective communication skills, and a proactive mindset make someone stand out in this role. These skills are crucial for accurately identifying and responding to cyber threats in a timely manner while collaborating with security teams.

What does a typical workday look like for a threat detection engineer?

A typical day for a Threat Detection Engineer involves monitoring security alerts, analyzing network and endpoint data, performing threat hunting activities, and triaging incidents for further investigation. You’ll regularly collaborate with other cybersecurity team members to develop detection rules, improve automated response processes, and stay up-to-date with emerging threat trends. Expect to participate in incident response drills and contribute to documentation and knowledge sharing within your organization. The environment is often fast-paced and requires a mix of independent analysis and teamwork to protect critical assets effectively.

What does a threat detection engineer do?

A Threat Detection Engineer is responsible for identifying, analyzing, and mitigating potential security threats within an organization’s systems and networks. They develop and implement detection strategies, create alerts for suspicious activities, and fine-tune security tools to improve threat visibility. Additionally, they collaborate with security teams to investigate incidents and enhance overall cybersecurity defenses. Their goal is to ensure early detection and response to cyber threats, minimizing potential damage.

More about Threat Detection Engineer jobs
What cities are hiring for Threat Detection Engineer jobs? Cities with the most Threat Detection Engineer job openings:
What are the most commonly searched types of Threat Detection Engineer jobs? The most popular types of Threat Detection Engineer jobs are:
What states have the most Threat Detection Engineer jobs? States with the most job openings for Threat Detection Engineer jobs include:
Infographic showing various Threat Detection Engineer job openings in the United States as of August 2026, with employment types broken down into 92% Full Time, 2% Part Time, and 6% Contract. Highlights an 86% Physical, 5% Hybrid, and 9% Remote job distribution.

AI Threat Detection Engineer, Senior Specialist

Vanguard Group, Inc.

Malvern, PA • On-site

$112K - $154K/yr

Full-time

Re-posted 8 days ago


Vanguard rating

8.7

Company rating: 8.7 out of 10

Based on 64 frontline employees who took The Breakroom Quiz

15th of 150 rated financial services


Job description

The AI Threat Detection Engineer, Senior Specialist is responsible for developing and implementing AI-driven capabilities that enhance Security Operations Center (SOC) effectiveness. This role focuses on building automation and intelligent solutions to improve threat detection, streamline workflows, and reduce manual effort. Working closely with senior engineers and cross-functional teams, this individual contributes to the delivery of secure, scalable solutions that support SOC modernization.
Core Responsibilities
  • Leads and responds to escalated cyber security alerts, cyber incidents, or related security investigations. Identifies real-time complex attack patterns and suggests mitigation strategies.
  • Leads the processes, tools and measures to monitor and detect compromises, risks, vulnerabilities, network security threats, tools and tactics used by modern and emerging threat actors. Facilitates security operations and incident response technologies and methodologies.
  • Develops, manages, maintains and enhances security controls (alerts, rules, policies, and signatures) for the security platforms.
  • Develop and enhance AI agents to streamline SOC operations and improve efficiency
  • Design and optimize prompts and workflows to support LLM-based security use cases
  • Evaluate emerging AI technologies and contribute to innovation within the SOC
  • Implement safeguards and controls to ensure secure and responsible AI usage
  • Build APIs, integrations, and automation workflows to support AI-driven capabilities
  • Write clean, maintainable, and production-ready code aligned with engineering best practices
  • Collaborate with security, engineering, and platform teams to deliver AI-enabled solutions
  • Support AI agent development and deployment across SOC use cases
  • Stay current on AI advancements and apply best practices to ongoing work
  • Mentors junior team members to improve their technical acumen
  • Participates in special projects and performs other duties as assigned.

Qualifications
  • 4+ years of hands-on programming or scripting experience (e.g., Python, Java, Shell)
  • 5+ years of experience with cloud platforms such as AWS or Microsoft Azure
  • 4+ year of experience building or supporting automation solutions (e.g., SOAR, GitHub, or similar tools)
  • 4+ years of experience working with security technologies or supporting SOC/security operations
  • Exposure to AI, GenAI, or LLM-based solutions, with hands-on development experience preferred
  • Familiarity with security telemetry (logs, alerts, endpoint, network, and cloud data)
  • 5+ years of exposure to SIEM platforms or detection engineering concepts

Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.
About Vanguard
At Vanguard, we don't just have a mission-we're on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

What Vanguard employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom