Staff Threat Detection Engineer

CVS Health

Confirmed live today High trust
Closes in 4 days

Quick summary

Work type
On-site
Location
New York, NY
Salary
$106,605–$284,280 / yr
Posted
3 days ago
Freshness
Confirmed live today
Closes
Sep 24, 2026 (soon)

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $193k
This role $195k
$85k most similar roles pay here $306k

This role pays more than 53% of similar roles. Most pay $163,800–$222,226 — the shaded band above. At the midpoint, this role pays about $195k versus about $193k for comparable roles.

Based on 240 similar postings.

Employer

About CVS Health

CVS Health is a leading American healthcare company operating retail pharmacies, pharmacy benefit management services, and a health insurance segment through Aetna, one of the nation''s largest health insurers. Industry: Healthcare & Pharmacy

CVS Health currently has 85 open roles on FindRole.

Listed pay typically runs $124,372–$284,280 across 84 roles with salary data.

Most-posted roles

View all roles at CVS Health

At a glance

TL;DR · Staff Threat Detection Engineer

Staff Threat Detection Engineer The Staff Threat Detection Engineer joins the cybersecurity team to proactively identify emerging risks and strengthen the organization's security posture through threat hunting, detection engineering, and offensive security expertise. This role involves developing and optimizing detection rules across SIEM platforms like Microsoft Sentinel and Splunk while conducting threat hunting using Microsoft Defender and CrowdStrike. The engineer will perform adversary emulation, conduct purple team exercises to bridge offensive and defensive efforts, and integrate threat intelligence into detection strategies. Key technical requirements include proficiency in KQL, SPL, Python, PowerShell, or Bash for automation and detection logic. The role focuses on the critical problem of identifying and mitigating cyber threats before they impact business operations by utilizing the MITRE ATT&CK framework and translating complex security data into actionable insights to improve monitoring and response effectiveness.

What you'll do

  • Develop, deploy, and optimize detection rules across Microsoft Sentinel and Splunk platforms.
  • Conduct threat hunting activities using Microsoft Defender, CrowdStrike, and other SOC tools.
  • Create custom detections and automate responses using KQL, SPL, Python, PowerShell, or Bash.
  • Design and execute adversary emulation scenarios to assess detection and response effectiveness.
  • Perform purple team exercises to bridge offensive and defensive security efforts.
  • Integrate threat intelligence into detection strategies to prioritize threats and adapt rules.
  • Provide technical insights and adversary tactics during incident response investigations.
  • Report on security gaps, risks, and detection effectiveness to leadership.

What we're looking for

  • 7+ years of experience in threat detection, hunting, penetration testing, and/or offensive security.
  • 5+ years of experience with Microsoft Security tools (Defender for Endpoint, Sentinel), CrowdStrike, and Splunk.
  • 3+ years of experience with KQL, SPL, Python, PowerShell, or Bash scripting for automation and detection logic.
  • Bachelor’s degree or equivalent experience (High School Diploma and 4 years relevant experience).
  • Relevant certifications such as OSCP, GCIH, GCIA, CISSP, CEH, or Microsoft Azure Certification (preferred).
  • Experience in managing or participating in purple team exercises (preferred).
  • Familiarity with compliance standards like PCI-DSS, HIPAA, or ISO 27001 (preferred).
  • Strong understanding of the MITRE ATT&CK framework and security standards such as NIST or CIS (preferred).

More like this

Similar roles

Threat Detection Security Engineer

CoStar Group

Arlington, VA +1 81 days ago $90,000$154,000
Incident Response Sentinel Defender Azure Kubernetes Python Mitre Att&ck Automation Detection Engineering
4+ yrs exp

Staff Threat Hunting & Intelligence Engineer

Cisco

Seattle, WA +4 24 days ago $160,700$203,500
Splunk SPL Threat Intelligence Threat Hunting API Integration CI/CD DevOps infrastructure-as-code AWS GCP Azure Linux Host-based Logs DNS DHCP Firewall VPN AI
8+ yrs exp Hybrid

Engineering Manager I, Threat Detection

Datadog

109 days ago $192,000$240,000
Python AI Detection Engineering SIEM CI/CD Security Operations Incident Response Cloud Infrastructure SaaS Automation Observability Threat Intelligence Detection-as-Code
Hybrid

Principal Threat Detection Operations Engineer

Target

Brooklyn Park, MN 3 days ago $168,000$303,000
Python SIEM SOAR EDR CI/CD Detection-as-Code DevSecOps Kubernetes REST APIs SQL NoSQL Git PowerShell Bash Cloud Security Threat Intelligence
10+ yrs exp Hybrid

Senior Security Engineer, Cloud Threat Detection

The Hartford

Hartford, CT +3 32 days ago $128,400$192,600
AWS GCP Splunk SIEM Python PowerShell Bash MITRE ATT&CK SOAR CloudTrail GuardDuty CrowdStrike Wiz Orca SentinelOne Microsoft Defender XDR Identity and Access Management (IAM)
5+ yrs exp Hybrid

Senior Insider Threat Engineer

Humana

Remote (Louisville, KY) +4 6 days ago $97,900$133,500
Microsoft Purview Proofpoint ITM KQL PowerShell Microsoft Graph API Splunk Defender XDR UEBA EDR DLP eDiscovery HIPAA HITRUST PCI-DSS SOC2
5+ yrs exp Remote