Threat Hunting & Detection Engineer (us Federal)

Workday

McLean, VA, USA
Primary location base pyy range: $159,600 usd - $2...
Fully remote
Splunk detection logic development
Cloud-native telemetry analysis
Mitre att&ck mapping
This role develops high-fidelity detection logic leveraging Splunk, cloud-native telemetry, identity and access telemetry, endpoint and container telemetry, and vulnerability intelligence sources

Job Summary

  • This role develops high-fidelity detection logic leveraging Splunk, cloud-native telemetry, identity and access telemetry, endpoint and container telemetry, and vulnerability intelligence sources.
  • You will translate adversary behaviors into actionable detection analytics aligned to MITRE ATT&CK and NIST SP 800-61r3 incident response lifecycle principles.
  • This role supports one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens.

Matching Summary

This role develops high-fidelity detection logic leveraging Splunk, cloud-native telemetry, identity and access telemetry, endpoint and container telemetry, and vulnerability intelligence sources.

Salary

Primary Location Base Pay Range: $159,600 USD - $239,400 USD; Additional US Location(s) Base Pay Range: $144,400 USD - $258,000 USD; Bonus/Equity: Role may be eligible for bonus plan or commission/bonus and annual refresh stock grants; Benefits: Comprehensive benefits package

Skills & Requirements

Must-have

  • Splunk detection logic development
  • Cloud-native telemetry analysis
  • MITRE ATT&CK mapping
  • NIST SP 800-61r3 incident response
  • FedRAMP High and IL5 environments
  • Air-gapped environment detection strategies

Nice-to-have

  • Curious minds and courageous collaborators
  • Sun-drenched optimism and drive
  • Empathy and shared enthusiasm
  • Hypothesis-driven threat hunting
  • SOAR platform experience

Key Requirements

  • 6+ years cybersecurity operations, detection engineering, or threat hunting
  • Hands-on Splunk experience
  • FedRAMP, DoD IL4/IL5, or regulated cloud environments
  • AWS security services experience
  • Bachelor’s degree or equivalent experience
  • Ability to obtain TS/SCI w/CI Poly security clearance

Work Rights

Must have US citizenship

Tailored Resume

Cover Letter