Threat Detection & Automation Engineer

Fiserv

Quick summary

Work type
On-site
Location
Berkeley Heights, NJAlpharetta, GA
Salary
$146,000–$244,800 / yr
Posted
2 days ago

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $173k
This role $195k
$117k most similar roles pay here $259k

This role pays more than 70% of similar roles. Most pay $142,437–$204,462 — the shaded band above. At the midpoint, this role pays about $195k versus about $173k for comparable roles.

Based on 240 similar postings.

Employer

About Fiserv

Fiserv is a global leader in financial services technology, providing core banking platforms, payment processing, digital banking, and merchant acquiring solutions to financial institutions and businesses. Industry: Financial Technology & Payments

Fiserv currently has 83 open roles on FindRole.

Listed pay typically runs $110,500–$186,600 across 60 roles with salary data.

Most-posted roles

View all roles at Fiserv

At a glance

TL;DR · Threat Detection & Automation Engineer

As a Threat Detection & Automation Engineer at Fiserv, you will join the Cyber Security Operations team as an experienced professional with 8+ years in cybersecurity engineering and detection development. Your role involves researching adversarial techniques and translating them into high-fidelity detections for complex use cases, while designing and operating production-grade security infrastructure using Google SecOps and internal automation tools. You will lead telemetry lifecycles, develop custom integrations, and create dashboards to enhance threat visibility and operational reporting. Key technologies include Python, SQL, PowerShell, Bash, SIEM platforms, SOAR solutions, and MITRE ATT&CK frameworks. Additionally, you will collaborate with various security teams to improve detection coverage and defensive capabilities in a hybrid environment, leveraging AI and machine learning for advanced analytics and automation.

What you'll do

  • Research adversarial techniques and develop high-fidelity detections for complex cybersecurity use cases.
  • Design and operate production-grade security detection infrastructure supporting enrichment and response workflows.
  • Lead telemetry lifecycles, including onboarding, parsing, normalization, testing, deployment, tuning, and maintenance.
  • Develop custom integrations using APIs, webhooks, and event-driven patterns to improve signal fidelity and reduce MTTD/MTTR.
  • Create dashboards and reports using BI tools, SQL, statistical analysis, and AI techniques for improved threat visibility.
  • Apply Python, prompt-driven workflows, and agent-to-agent orchestration patterns to support detection engineering and enrichment.

What we're looking for

  • 8+ years of experience in cybersecurity engineering or detection engineering for enterprise security environments.
  • Extensive experience developing and tuning detections with SIEM technologies and SOAR platforms.
  • Proficient in scripting and automation development using Python, SQL, PowerShell, Bash, or similar languages.
  • Deep knowledge of various cybersecurity technologies including EDR, IDS/NDR, UEBA, DLP, WAF, proxy techs, and cloud security services.
  • Experience designing API integrations with REST, JSON, webhooks, OAuth, service accounts, and event-driven messaging patterns.
  • Applied expertise in MITRE ATT&CK framework for detection coverage analysis and threat reporting.
  • Bachelor's degree in cybersecurity, computer science, or related field.

More like this

Similar roles

Security Automation Engineer

S&P Global

New York, NY +2 5 days ago
Python SOAR Splunk Phantom Terraform AWS MITRE ATT&CK Docker Git Jenkins CI/CD Agentic AI Large Language Models Okta Mimecast CrowdStrike CloudFormation Google SecOps Azure DevOps

Senior Threat Detection Engineer

JLL (Jones Lang LaSalle)

Remote (Austin, TX) 12 days ago $190,000$210,000
SIEM EDR/XDR SOAR CI/CD Terraform Python Go AWS Azure Kubernetes MITRE ATT&CK GitHub Actions Splunk SOAR CloudFormation Docker Grafana Prometheus SQL KQL SPL
Remote

Security Engineer, Threat Intelligence

Snap Inc.

NSW, Australia +1 7 days ago
Python Go Kubernetes AWS Google Cloud Platform CI/CD Threat Intelligence Incident Response Malware Analysis Digital Forensics Linux macOS Windows Terraform Prometheus Grafana

Security Engineer - Threat Intelligence

Snap Inc.

Sydney, Australia 11 days ago
Python Go Kubernetes AWS Google Cloud Platform CI/CD Threat Intelligence Incident Response Malware Analysis Digital Forensics Linux macOS Windows Terraform Prometheus Grafana

Threat Detection Security Engineer

CoStar Group

Arlington, VA +1 45 days ago
Python Azure Kubernetes Mitre Att&ck CI/CD Microsoft Defender Microsoft Sentinel Elasticsearch Logstash Kibana Prometheus Grafana Terraform Ansible JSON YAML REST APIs Linux Windows
Hybrid

Senior Security Automation Engineer

P&G

Cincinnati, OH 33 days ago $110,000$165,300
Python SOAR SOC SIEM API development Incident Response Playbooks Log Integration Workflow Automation CI/CD AWS
Hybrid