CDW Corporation

Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming

CDW Corporation$137K — $190K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree and 7+ years of experience in threat detection engineering, threat hunting, incident response, or offensive security, or 11+ years of equivalent experience.
  • Hands-on experience building and tuning detections in SIEM platforms and cloud-scale security tooling.
  • Practical working knowledge of the MITRE ATT&CK framework.
  • Experience with adversary emulation, purple teaming, or penetration testing against production controls.
  • Proficiency in Python for automation and tooling.
  • Experience applying AI/ML or LLM capabilities to security problems.
  • Working experience with security automation and orchestration platforms.

Responsibilities

  • Engineer high-fidelity detections across various environments with automated response paths.
  • Apply AI to enhance alert triage and incident narratives.
  • Develop autonomous response playbooks for swift action on security threats.
  • Implement guardrails to ensure safe automation practices.
  • Measure detection and response efficiency metrics and work to improve them continuously.
  • Conduct continuous adversary emulation to validate defensive coverage.
  • Lead threat hunting efforts and translate findings into automated detections.

Benefits

  • Comprehensive health insurance packages.
  • Retirement savings plan with employer match.
  • Professional development and education assistance.
  • Generous paid time off policies.
  • Flexible work arrangements, including remote work options.
Full Job Description

Job Summary

Catch attackers in minutes, not days. Test our own defenses at attacker speed, continuously.

The Senior Threat Engineer is a hands‑on, high‑impact role within the Enterprise Defense & Automation (EDA) team. You will engineer AI‑powered detection and response capabilities that compress attacker dwell time from days to minutes, and you will continuously red team those same defenses at attacker speed so that gaps are found by us long before they are found by an adversary.

The role sits at the intersection of threat detection engineering, adversary emulation, and applied AI. On the defensive side you will build detections and AI‑assisted response paths that triage, decide, and act autonomously within policy, moving security operations from “alert and investigate” to detect, decide, and act. On the offensive side you will run continuous, automated adversary emulation against production controls, generating a constant stream of evidence about what our defenses actually stop.

This is a builder and problem‑solver role. You will write detection logic, adversary emulation content, and automated response playbooks; instrument them with measurable outcomes such as mean time to detect, mean time to contain, and detection coverage against MITRE ATT&CK; and use AI to raise signal fidelity rather than alert volume. Every detection you ship is expected to be tested by an emulation you also ship.

Success requires strong threat fundamentals, fluency across modern detection and response platforms, and the discipline to deliver production‑grade capability that holds up in real‑world, adversarial conditions. Guardrails matter as much as speed: confidence thresholds, blast‑radius limits, and rollback paths are part of the design, not an afterthought.

If you are energized by hunting real adversaries, teaching machines to respond faster than they can, and attacking your own work before anyone else gets the chance, this role puts you at the forefront of modern cyber defense.

What you will do

AI-Powered Detection & Response — catch attackers in minutes, not days (Primary)

  • Engineer high‑fidelity detections across identity, endpoint, network, cloud, and SaaS, and pair each one with an automated response path so the outcome is containment, not another alert.
  • Apply AI and machine learning to triage, correlate, and enrich alerts at machine speed — clustering related signals into a single incident narrative and surfacing the attacker story instead of a queue of fragments.
  • Build autonomous and semi‑autonomous response playbooks that isolate hosts, revoke sessions and tokens, disable credentials, block infrastructure, and quarantine content within minutes of first signal.
  • Implement the guardrails that make autonomy safe: confidence thresholds, blast‑radius controls, human‑in‑the‑loop escalation for high‑impact actions, and tested rollback for every automated action.
  • Instrument detection and response for measurable outcomes — mean time to detect, mean time to contain, false‑positive rate, and ATT&CK coverage — and drive those numbers down release over release.
  • Use LLMs and agentic tooling where they earn their place: summarizing investigations, drafting containment recommendations, extracting indicators from unstructured reporting, and generating detection logic that a human reviews before it ships.

Continuous AI Red Teaming — test our own defenses at attacker speed (Primary)

  • Stand up and operate continuous, automated adversary emulation against production controls, so defensive coverage is proven by evidence on a recurring cadence rather than assumed between annual assessments.
  • Use AI to generate and mutate attack behavior — varying tradecraft, tooling, and sequencing across ATT&CK techniques — so detections are tested against variants rather than a single static signature.
  • Close the loop from emulation to engineering: every miss becomes a detection backlog item, every noisy hit becomes a tuning task, and every fix is re‑tested automatically.
  • Red team our AI itself — test detection models, agents, and prompts for evasion, prompt injection, data poisoning, and unsafe autonomous action, and remediate what you find.
  • Operate emulation safely in production: scoped targets, rate limits, clear abort criteria, deconfliction with the response team, and full audit trails for every executed technique.
  • Report coverage as a living metric — which techniques are prevented, which are detected, which are only logged, and which are invisible — and use it to prioritize the detection roadmap.

Threat Research & Hunting

  • Track adversary tradecraft relevant to CDW and our customers, and translate intelligence into emulation plans, detections, and response actions rather than reading material.
  • Run hypothesis‑driven threat hunts across SIEM, XDR, identity, and cloud telemetry, and convert every confirmed hunt technique into an automated detection so the same hunt never has to be run by hand twice.
  • Map techniques to controls and automated responses once, then reuse the mapping globally across the estate.
  • Lead technical deep dives on significant incidents and emulation findings, and feed the lessons back into detection content, response playbooks, and platform hardening.

Detection Engineering as Code

  • Treat detection content as software: version controlled, peer reviewed, unit tested against emulation data and promoted through CI/CD with security gates that block low‑quality logic before it reaches production.
  • Develop integrations and tooling in Python against platform APIs and event‑driven architectures, favoring reusable services over one‑off scripts.
  • Build detection and response capability that self‑heals — identifying telemetry gaps, sensor degradation, and control drift, then correcting them or rolling back to a known‑good state without waiting for a human.
  • Eliminate repeat findings through native auto‑remediation patterns rather than recurring manual cleanup.

Collaboration & Influence

  • Partner closely with the Threat Response team, Cyber Defense Engineering, security platform owners, and business unit owners so that detections, emulations, and automated actions land with clear ownership boundaries.
  • Contribute to shared backlogs and design reviews, and mentor engineers and analysts on detection quality, adversary tradecraft, and the safe use of AI in the defensive stack.
  • Document detection logic, emulation plans, automation patterns, and engineering decisions so the capability survives any single person.

What we expect of you

  • Bachelor’s degree and 7+ years of experience in threat detection engineering, threat hunting, incident response, or offensive security, or 11+ years of equivalent experience.
  • Hands‑on experience building and tuning detections in SIEM platforms and cloud‑scale security tooling.
  • Practical working knowledge of the MITRE ATT&CK framework, including mapping detections and automated responses to techniques.
  • Experience with adversary emulation, purple teaming, breach and attack simulation, or penetration testing against production controls.
  • Proficiency in Python for production‑grade automation and tooling.
  • Experience applying AI/ML or LLM‑based capabilities to security problems, and designing secure, observable, and maintainable AI‑enabled solutions.
  • Working experience with security automation, orchestration, or SOAR platforms.
  • Built detection and response capability for large, diverse enterprise environments, a plus.
  • Familiarity with platforms such as Microsoft Defender, Microsoft Sentinel, CrowdStrike, Tines, Entra ID, and Splunk, a plus.
  • Familiarity with emulation and offensive tooling such as Atomic Red Team, Caldera, Cobalt Strike, or commercial breach and attack simulation platforms, a plus
  • Detection‑as‑code practice: CI/CD pipelines, infrastructure‑as‑code, policy‑as‑code, and automated testing of detection content, a plus.
  • Experience securing or red teaming AI systems, including prompt injection, model evasion, and agent safety testing, a plus
  • Relevant certifications (GCIH, GCFA, GCTI, GPEN, OSCP, Azure Security, or cloud and automation certifications), a plus.

Pay range: $137,000 – 190,600 depending on experience and skill set.
Annual bonus target 10% subject to terms and conditions of plan.
Benefits overview: https://cdw.benefit-info.com/
Salary ranges may be subject to geographic differentials.

About CDW Corporation

CDW is a provider of IT solutions for business, government, education, and healthcare. It features dedicated account managers who help customers choose the right technology products and services to meet their needs. The company’s solution architects offer expertise in designing customized solutions, while its advanced technology engineers assist customers with the implementation and long-term management of those solutions. Headquartered in Vernon Hills, Illinois, With a balanced portfolio of 250,000 small-, medium- and large-sized customers, CDW generated net sales of $10.1 billion in 2012, and employs more than 6,800 coworkers in 25 locations across the U.S. and Canada. Founded in 1984 by entrepreneur Michael Krasny, CDW pioneered the business model that melds personalized business-to-business technology distribution with advanced technology services. Today, CDW is ranked No. 31 on Forbes’ list of America’s Largest Private Companies and No. 267 on the FORTUNE 500 list of America’s top companies.

CDW Corporation Careers

Join the vibrant team at CDW Corporation, a leading provider of technology solutions and services, where innovation, leadership, and growth are at the heart of what we do. As a powerhouse in the tech industry, CDW Corporation offers unparalleled job opportunities to both seasoned professionals and those at the start of their careers.

Work You’ll Do

At CDW Corporation, you’ll be part of a culture that cherishes diversity, innovation, and leadership. Our team is composed of over 10,000 strong, dedicated professionals who lead the way in technology and consulting services. We are committed to helping some of the world’s most well-known companies navigate their digital transformation journeys.

Explore Professional Growth and Development

CDW Corporation is not just a company; it's a place where you can shape your future. With a variety of career paths available, your professional growth is supported by robust training programs, diversity training, and opportunities for leadership development. We believe in fostering a culture where innovation thrives and where our employees are encouraged to develop new skills and gain valuable experiences.

Internship Programs

Kickstart your career with CDW Corporation’s dynamic internship programs. These opportunities allow you to apply your skills in real-world scenarios, ensuring you gain the experience and insights needed to excel. Our internships are designed to transform students into professionals by involving them in projects that promote problem-solving, networking, and professional growth.

Join Our Team

Discover the wide range of job opportunities at CDW Corporation, from technology to business management. Each position offers a chance to work on transformative technology solutions while building a career that aligns with your passions and skills.

Benefits of Working at CDW Corporation

Choosing to work at CDW Corporation means opting for a career that comes with competitive benefits designed to support you and your family. These include health, dental, and vision insurance, employee wellness programs, and generous retirement plans. Our commitment to employee well-being is reflected in every aspect of our corporate structure.

Inclusive Hiring Process

Our hiring process is designed to be transparent and inclusive, ensuring that all candidates, regardless of background, feel valued from the initial interview through to potential employment. We look for passionate, curious, and innovative team players who are ready to drive change. Prepare your resume, sharpen your interview skills, and get ready to join a team that’s at the forefront of the technology sector.

Stay Connected

Keep up to date with the latest at CDW Corporation by following our careers blog. Gain insider perspectives, industry-leading insights, and career tips that you can put to use today—all from the people who work here.

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at CDW Corporation.

Explore Jobs at CDW Corporation

Search open positions that match your skills and interests on our careers page. Whether you’re looking to contribute your experience or start fresh, CDW Corporation offers a path for you. [SEARCH CDW JOBS] Join CDW Corporation and be part of a team that values professionalism, opportunity, and innovation. Let’s shape the future together!
Learn more about CDW Corporation
Size
13,900 employees
Market Cap
$24.1 billion
Industry
Net Income
$788.4 million
Founded
1984
5 Year Trend
+8.8%
Revenue
$18.4 billion
NASDAQ

Similar Jobs

More Jobs at CDW Corporation

More Information Technology Jobs

Find similar Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming jobs: