Threat Hunting & Detection Engineer (us Federal)

Workday

McLean, VA, USA
Primary location base pyy range: $159,600 usd - $2...
Fully remote
Splunk detection logic
Aws security services telemetry
Mitre att&ck adversary behaviors
Our work supports U.S. federal agencies as they modernize and transform the full employee lifecycle experience and finance operations

Job Summary

  • Our work supports U.S. federal agencies as they modernize and transform the full employee lifecycle experience and finance operations.
  • This role develops high-fidelity detection logic leveraging Splunk, cloud-native telemetry, identity and access telemetry, endpoint and container telemetry, and vulnerability intelligence sources.
  • The work isn’t theoretical. It’s operational. It’s high-impact. And it demands rigor, integrity, and long-term thinking.

Matching Summary

Our work supports U.S. federal agencies as they modernize and transform the full employee lifecycle experience and finance operations.

Salary

Primary Location Base Pay Range: $159,600 USD - $239,400 USD; Additional US Location(s) Base Pay Range: $144,400 USD - $258,000 USD; Bonus/Equity: May be eligible for Workday Bonus Plan or role-specific commission/bonus, as well as annual refresh stock grants

Skills & Requirements

Must-have

  • Splunk detection logic
  • AWS security services telemetry
  • MITRE ATT&CK adversary behaviors
  • FedRAMP High and IL5 environments
  • Air-gapped environment detection strategies

Nice-to-have

  • Hypothesis-driven threat hunting
  • Identity-based attack vectors
  • Container and workload attack detection
  • SOAR platform integration

Key Requirements

  • 6+ years cybersecurity operations, detection engineering, or threat hunting
  • Hands-on Splunk detection building experience
  • Experience in FedRAMP, DoD IL4/IL5, or regulated cloud
  • Experience with AWS security services
  • Familiarity with NIST SP 800-61r3
  • Bachelor’s degree or equivalent experience

Work Rights

Must have US citizenship

Tailored Resume

Cover Letter