Threat Detection & Automation Engineer

Fiserv

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Berkeley Heights, NJ
Salary
$146,000–$244,800 / yr
Posted
5 days ago
Freshness
Confirmed live today

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $177k
This role $195k
$116k most similar roles pay here $259k

This role pays more than 67% of similar roles. Most pay $145,000–$209,850 — the shaded band above. At the midpoint, this role pays about $195k versus about $177k for comparable roles.

Based on 240 similar postings.

Employer

About Fiserv

Fiserv is a global leader in financial services technology, providing core banking platforms, payment processing, digital banking, and merchant acquiring solutions to financial institutions and businesses. Industry: Financial Technology & Payments

Fiserv currently has 106 open roles on FindRole.

Listed pay typically runs $123,750–$201,000 across 74 roles with salary data.

Most-posted roles

View all roles at Fiserv

At a glance

TL;DR · Threat Detection & Automation Engineer

The Threat Detection & Automation Engineer joins the Cyber Security Operations team to enable end-to-end detection engineering across telemetry onboarding, content development, and response automation. This role involves researching adversarial techniques to create high-fidelity detections, building production-grade security infrastructure within Google SecOps, and managing full telemetry lifecycles including parsing and normalization. The engineer will develop custom integrations using APIs, webhooks, and event-driven patterns while creating dashboards and reports utilizing SQL, statistical analysis, and machine learning. Key technical requirements include proficiency in Python, PowerShell, Bash, and tools like EDR, IDS/NDR, and WAF. The role focuses on solving complex cybersecurity use cases by improving detection fidelity and reducing response times through automated workflows and infrastructure as code. Collaboration with threat intelligence and red teams ensures robust defense across hybrid environments using Agile methodologies.

What you'll do

  • Translate adversarial techniques into high-fidelity detections aligned with complex cybersecurity use cases.
  • Build and operate production-grade security detection infrastructure using Google SecOps and internal automation tools.
  • Manage the full telemetry lifecycle including source onboarding, parsing, normalization, enrichment, and tuning.
  • Develop custom integrations and automated workflows using APIs, webhooks, and event-driven patterns to improve response times.
  • Create dashboards and reports using SQL, statistical analysis, and AI/ML techniques to enhance threat visibility.
  • Apply Python and agent-to-agent orchestration patterns to support detection engineering and analytic decision support.
  • Identify and close detection coverage gaps by collaborating with threat intelligence and incident response teams.
  • Manage project lifecycles through Agile practices while maintaining reliable platform operations across hybrid environments.

What we're looking for

  • Bachelor's degree in cybersecurity, computer science, information technology, engineering, or a related field, or equivalent experience.
  • 8+ years of experience in cybersecurity engineering, security operations, or detection engineering for enterprise environments.
  • 8+ years of experience developing and tuning detections using SIEM and SOAR platforms.
  • 8+ years of experience scripting and automation development using Python, SQL, PowerShell, Bash, or similar languages.
  • 8+ years of experience working with cybersecurity technologies including EDR, IDS/NDR, UEBA, DLP, WAF, and cloud security services.
  • Experience designing and supporting API integrations using REST, JSON, webhooks, OAuth, and event-driven messaging patterns.
  • Experience applying MITRE ATT&CK, detection coverage analysis, telemetry mapping, and threat reporting to improve cyber detection.
  • Work authorization to be considered for this role.

More like this

Similar roles

Principal Threat Detection Operations Engineer

Target

Brooklyn Park, MN 3 days ago $168,000$303,000
Python SIEM SOAR EDR CI/CD Detection-as-Code DevSecOps Kubernetes REST APIs SQL NoSQL Git PowerShell Bash Cloud Security Threat Intelligence
10+ yrs exp Hybrid

Engineering Manager I, Threat Detection

Datadog

109 days ago $192,000$240,000
Python AI Detection Engineering SIEM CI/CD Security Operations Incident Response Cloud Infrastructure SaaS Automation Observability Threat Intelligence Detection-as-Code
Hybrid

Senior Security Engineer, Cloud Threat Detection

The Hartford

Hartford, CT +3 32 days ago $128,400$192,600
AWS GCP Splunk SIEM Python PowerShell Bash MITRE ATT&CK SOAR CloudTrail GuardDuty CrowdStrike Wiz Orca SentinelOne Microsoft Defender XDR Identity and Access Management (IAM)
5+ yrs exp Hybrid

Cyber Threat Hunter

Fiserv

Berkeley Heights, NJ 4 days ago $128,000$216,000
Python Machine Learning Detection-as-Code CI/CD Git Google SecOps Chronicle Digital Forensics Incident Response Malware Analysis Reverse Engineering MITRE ATT&CK Cloud Security Data Science
8+ yrs exp

Threat Detection Security Engineer

CoStar Group

Arlington, VA +1 81 days ago $90,000$154,000
Incident Response Sentinel Defender Azure Kubernetes Python Mitre Att&ck Automation Detection Engineering
4+ yrs exp

Staff Threat Detection Engineer

CVS Health

New York, NY 3 days ago $106,605$284,280
Microsoft Sentinel Splunk Microsoft Defender CrowdStrike KQL SPL Python PowerShell Bash Purple Team Penetration Testing NIST CIS PCI-DSS HIPAA ISO 27001
7+ yrs exp