Threat Hunting & Detection Engineer (us Federal)

Workday

McLean, VA, USA
Primary location base pyy range: $159,600 usd - $2...
**
Splunk detection logic
Aws cloud-native telemetry
Mitre att&ck alignment
** Workday is seeking a Threat Hunting & Detection Engineer for its McLean, VA office to enhance cybersecurity measures for U.S. Federal Government clients. The role focuses on developing and validating detection capabilities in high-security cloud environments, requiring extensive experience in cybersecurity and regulatory frameworks. **

Job Summary

  • The Threat Hunting & Detection Engineer is responsible for engineering, validating, and continuously improving detection capabilities across FedRAMP High and IL5 cloud-native SaaS environments, including air-gapped regions.
  • This role develops high-fidelity detection logic leveraging Splunk, cloud-native telemetry, identity and access telemetry, endpoint and container telemetry, and vulnerability intelligence sources.
  • You will collaborate closely with SOC Analysts, Security Engineers, Red/Purple Teams, Threat Intelligence, and Compliance stakeholders to ensure continuous validation of detection coverage and operational readiness.

Matching Summary

Match Score: 75

** Workday is seeking a Threat Hunting & Detection Engineer for its McLean, VA office to enhance cybersecurity measures for U.S. Federal Government clients. The role focuses on developing and validating detection capabilities in high-security cloud environments, requiring extensive experience in cybersecurity and regulatory frameworks. **

Salary

Primary Location Base Pay Range: $159,600 USD - $239,400 USD; Additional US Location(s) Base Pay Range: $144,400 USD - $258,000 USD; Bonus/Equity: Not specified; Benefits: Not specified

Skills & Requirements

Must-have

  • Splunk detection logic
  • AWS cloud-native telemetry
  • MITRE ATT&CK alignment
  • NIST SP 800-61r3 principles
  • FedRAMP High and IL5 environments

Nice-to-have

  • hypothesis-driven threat hunting
  • identity-based attack vectors
  • container and workload attacks
  • secure logging in air-gapped environments

Key Requirements

  • 6+ years of experience
  • Hands-on Splunk experience
  • FedRAMP, DoD IL4/IL5 experience
  • AWS security services experience
  • Bachelor's degree or equivalent experience

Work Rights

Must have US citizenship

Tailored Resume

Cover Letter